ci(security): give pip-audit the same registry-outage retry as npm
pip-audit queries PyPI's advisory API and exits non-zero when it cannot reach it, exactly as `npm audit` does — the same class of outage that reddened #409 would have failed the Python half too. Both now go through .github/scripts/audit-with-retry.sh, which retries only when the output names a transport or availability failure and lets a real finding fail on the first attempt, unretried. The npm loop added in the previous commit is folded into it. ha-relevant: no
This commit is contained in:
committed by
Pouzor - Rémy Jardient
parent
37a3aee9cc
commit
03e5ae939e
Executable
+38
@@ -0,0 +1,38 @@
|
||||
#!/usr/bin/env bash
|
||||
#
|
||||
# Run a dependency audit, retrying only when the registry could not be reached.
|
||||
#
|
||||
# Both `npm audit` and `pip-audit` exit non-zero for two very different reasons:
|
||||
# a real advisory, and a registry that would not answer. Only the second is
|
||||
# worth a retry — the audit endpoints 503 often enough to redden PRs that
|
||||
# changed no dependency at all. An advisory fails on the first attempt, so a
|
||||
# vulnerability can never be retried into a pass.
|
||||
#
|
||||
# Usage: audit-with-retry.sh <command> [args...]
|
||||
|
||||
set -uo pipefail
|
||||
|
||||
ATTEMPTS=${AUDIT_ATTEMPTS:-3}
|
||||
DELAY=${AUDIT_RETRY_DELAY:-30}
|
||||
|
||||
# Transport and availability failures, from both npm and pip-audit/urllib3.
|
||||
NETWORK_FAILURE='audit endpoint returned an error|service unavailable|max retries exceeded|connectionerror|readtimeout|read timed out|temporary failure in name resolution|50[234] server error|etimedout|econnreset|enotfound|socket hang up|connection reset|remotedisconnected|urlopen error|timeouterror'
|
||||
|
||||
for attempt in $(seq 1 "$ATTEMPTS"); do
|
||||
if out=$("$@" 2>&1); then
|
||||
echo "$out"
|
||||
exit 0
|
||||
fi
|
||||
echo "$out"
|
||||
|
||||
if ! grep -qiE "$NETWORK_FAILURE" <<<"$out"; then
|
||||
echo "::error::$1 reported findings — see the output above"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "::warning::$1 could not reach its registry (attempt $attempt/$ATTEMPTS)"
|
||||
if [ "$attempt" -lt "$ATTEMPTS" ]; then sleep "$DELAY"; fi
|
||||
done
|
||||
|
||||
echo "::error::$1 could not reach its registry after $ATTEMPTS attempts"
|
||||
exit 1
|
||||
Reference in New Issue
Block a user