Compare commits

...

2 commits

Author SHA1 Message Date
Bukely_
a51d97f63c
Add security CI workflows (#248)
Some checks are pending
CodeQL / Analyze (actions) (push) Waiting to run
* Add security CI workflows

* Remove duplicate Python CodeQL workflow
2026-04-25 00:46:01 +08:00
dependabot[bot]
40073375ff
Bump the pip group across 1 directory with 2 updates (#247)
Bumps the pip group with 2 updates in the / directory: [litellm](https://github.com/BerriAI/litellm) and [python-dotenv](https://github.com/theskumar/python-dotenv).


Updates `litellm` from 1.83.0 to 1.83.7
- [Release notes](https://github.com/BerriAI/litellm/releases)
- [Commits](https://github.com/BerriAI/litellm/commits)

Updates `python-dotenv` from 1.1.0 to 1.2.2
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.1.0...v1.2.2)

---
updated-dependencies:
- dependency-name: litellm
  dependency-version: 1.83.7
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: python-dotenv
  dependency-version: 1.2.2
  dependency-type: direct:production
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-25 00:19:47 +08:00
3 changed files with 58 additions and 2 deletions

34
.github/workflows/codeql.yml vendored Normal file
View file

@ -0,0 +1,34 @@
name: CodeQL
on:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
- cron: '37 9 * * 1'
permissions:
security-events: write
contents: read
actions: read
jobs:
analyze:
name: Analyze (actions)
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Initialize CodeQL
uses: github/codeql-action/init@v4
with:
languages: actions
build-mode: none
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4
with:
category: /language:actions

22
.github/workflows/dependency-review.yml vendored Normal file
View file

@ -0,0 +1,22 @@
name: Dependency Review
on:
pull_request:
branches: [main]
permissions:
contents: read
jobs:
dependency-review:
name: Dependency Review
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Dependency Review
uses: actions/dependency-review-action@v4
with:
fail-on-severity: moderate

View file

@ -1,6 +1,6 @@
litellm==1.83.0
litellm==1.83.7
# openai-agents # optional: required for examples/agentic_vectorless_rag_demo.py
pymupdf==1.26.4
PyPDF2==3.0.1
python-dotenv==1.1.0
python-dotenv==1.2.2
pyyaml==6.0.2