File tree Expand file tree Collapse file tree 10 files changed +515
-499
lines changed
Expand file tree Collapse file tree 10 files changed +515
-499
lines changed Original file line number Diff line number Diff line change 2828 echo "TAG_FORMAT=$TAG_FORMAT" >> "$GITHUB_OUTPUT"
2929
3030 quality_checks :
31- uses : NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml@2b3ddfd1e59daf9905522d0140c6cd08e2547432
31+ uses : NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml@2fe6bc6cd974efb4d55a2a7b665385f7a2d28950
3232 needs : [get_asdf_version]
3333 with :
3434 asdfVersion : ${{ needs.get_asdf_version.outputs.asdf_version }}
Original file line number Diff line number Diff line change 3333 echo "TAG_FORMAT=$TAG_FORMAT" >> "$GITHUB_OUTPUT"
3434
3535 quality_checks :
36- uses : NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml@2b3ddfd1e59daf9905522d0140c6cd08e2547432
36+ uses : NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml@2fe6bc6cd974efb4d55a2a7b665385f7a2d28950
3737 needs : [get_asdf_version]
3838 with :
3939 asdfVersion : ${{ needs.get_asdf_version.outputs.asdf_version }}
Original file line number Diff line number Diff line change 2727 echo "TAG_FORMAT=$TAG_FORMAT" >> "$GITHUB_OUTPUT"
2828
2929 quality_checks :
30- uses : NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml@2b3ddfd1e59daf9905522d0140c6cd08e2547432
30+ uses : NHSDigital/eps-common-workflows/.github/workflows/quality-checks.yml@2fe6bc6cd974efb4d55a2a7b665385f7a2d28950
3131 needs : [get_asdf_version]
3232 with :
3333 asdfVersion : ${{ needs.get_asdf_version.outputs.asdf_version }}
Original file line number Diff line number Diff line change @@ -34,3 +34,4 @@ cdk.out
3434.requirements_syncKnowledgeBaseFunction
3535.local_config /
3636.dependencies /
37+ .poetry /
Original file line number Diff line number Diff line change 1+ vulnerabilities :
2+ - id : CVE-2025-66418
3+ paths :
4+ - " node_modules/@cdklabs/generative-ai-cdk-constructs/lambda/aws-bedrock-batch-stepfn/uv.lock"
5+ - " node_modules/@cdklabs/generative-ai-cdk-constructs/lambda/opensearch-serverless-custom-resources/poetry.lock"
6+ statement : downstream dependency just used in build stage
7+ - id : CVE-2025-66471
8+ paths :
9+ - " node_modules/@cdklabs/generative-ai-cdk-constructs/lambda/aws-bedrock-batch-stepfn/uv.lock"
10+ - " node_modules/@cdklabs/generative-ai-cdk-constructs/lambda/opensearch-serverless-custom-resources/poetry.lock"
11+ statement : downstream dependency just used in build stage
12+ - id : CVE-2026-21441
13+ paths :
14+ - " node_modules/@cdklabs/generative-ai-cdk-constructs/lambda/aws-bedrock-batch-stepfn/uv.lock"
15+ - " node_modules/@cdklabs/generative-ai-cdk-constructs/lambda/opensearch-serverless-custom-resources/poetry.lock"
16+ statement : downstream dependency just used in build stage
Original file line number Diff line number Diff line change 6565
6666deep-clean : clean
6767 rm -rf .venv
68+ rm -rf .poetry
6869 find . -name ' node_modules' -type d -prune -exec rm -rf ' {}' +
6970
7071check-licenses : check-licenses-node check-licenses-python
Original file line number Diff line number Diff line change @@ -47,10 +47,3 @@ aws-lambda-powertools = "^3.23.0"
4747
4848[tool .black ]
4949line-length = 120
50-
51- [build-system ]
52- requires = [" poetry>=0.12" ]
53- build-backend = " poetry.masonry.api"
54-
55- [tool .poetry .requires-plugins ]
56- poetry-plugin-export = " >=1.8"
Original file line number Diff line number Diff line change @@ -64,8 +64,8 @@ echo "Generating config for ${EPSAM_CONFIG}"
6464
6565echo " Installing dependencies locally"
6666mkdir -p .dependencies
67- poetry export --without-hashes --format=requirements.txt --with slackBotFunction > .dependencies/requirements_slackBotFunction
68- poetry export --without-hashes --format=requirements.txt --with syncKnowledgeBaseFunction > .dependencies/requirements_syncKnowledgeBaseFunction
67+ poetry show --only=slackBotFunction | grep -E " ^[a-zA-Z] " | awk ' {print $1"=="$2} ' > .dependencies/requirements_slackBotFunction
68+ poetry show --only=syncKnowledgeBaseFunction | grep -E " ^[a-zA-Z] " | awk ' {print $1"=="$2} ' > .dependencies/requirements_syncKnowledgeBaseFunction
6969pip3 install -r .dependencies/requirements_slackBotFunction -t .dependencies/slackBotFunction/python
7070pip3 install -r .dependencies/requirements_syncKnowledgeBaseFunction -t .dependencies/syncKnowledgeBaseFunction/python
7171
Original file line number Diff line number Diff line change 1+ ignorefile : " .trivyignore.yaml"
You can’t perform that action at this time.
0 commit comments