ci(semgrep): install with --ignore-installed (apt-managed PyJWT can't be uninstalled)
The runner's semgrep install failed trying to replace Debian's apt-managed PyJWT
("Cannot uninstall PyJWT ... RECORD file not found"). --ignore-installed installs
semgrep's deps fresh without uninstalling the apt copies, staying within the
runner's constraints (no setup-python, no container job).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -115,14 +115,17 @@ jobs:
|
|||||||
# Installed via the runner's preinstalled python3/pip — NOT `setup-python` (its Python
|
# Installed via the runner's preinstalled python3/pip — NOT `setup-python` (its Python
|
||||||
# download failed on this runner) and NOT a job `container:` (this act_runner times out
|
# download failed on this runner) and NOT a job `container:` (this act_runner times out
|
||||||
# pulling the base runner image for container jobs). `--break-system-packages` survives
|
# pulling the base runner image for container jobs). `--break-system-packages` survives
|
||||||
# PEP-668; pip drops `semgrep` on PATH. Verified locally: install + scan run clean.
|
# PEP-668; pip drops `semgrep` on PATH. `--ignore-installed` is required because some of
|
||||||
|
# semgrep's deps (e.g. PyJWT) are already present as apt-managed packages, which pip cannot
|
||||||
|
# uninstall ("RECORD file not found") — this flag installs fresh without uninstalling, so it
|
||||||
|
# never touches the Debian copies. Don't drop it.
|
||||||
# ponytail: report-only for now (no `--error`, so the job stays green while the initial
|
# ponytail: report-only for now (no `--error`, so the job stays green while the initial
|
||||||
# findings are triaged); flip to `--error` to make it a blocking gate. See WP-30.
|
# findings are triaged); flip to `--error` to make it a blocking gate. See WP-30.
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
timeout-minutes: 15
|
timeout-minutes: 15
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
- run: python3 -m pip install --break-system-packages semgrep
|
- run: python3 -m pip install --break-system-packages --ignore-installed semgrep
|
||||||
# p/default = curated cross-language security (covers JS/TS); p/csharp = the backend.
|
# p/default = curated cross-language security (covers JS/TS); p/csharp = the backend.
|
||||||
# Anonymous registry fetch; --metrics=off disables telemetry (not `auto`, which uploads
|
# Anonymous registry fetch; --metrics=off disables telemetry (not `auto`, which uploads
|
||||||
# project metadata).
|
# project metadata).
|
||||||
|
|||||||
Reference in New Issue
Block a user