Fix quality black wrap and PyPI upload with the existing token. #21
CI.yml
on: push
Matrix: codeql
Matrix: rust-test
Matrix: test-unit
Matrix: test-windows
Static analysis and formatting
44s
Composite action dogfood
1m 30s
Rust format, check, clippy, coverage, audit
27s
Windows executable smoke tests
1m 24s
sdist and wheel
26s
Dependency Graph
25s
Publish wheels to PyPI
23s
Annotations
3 errors, 3 warnings, and 2 notices
|
Dependency Graph
HttpError: The Dependency graph is disabled for this repository. Please enable it before submitting snapshots. - https://docs.github.com/code-security/supply-chain-security/understanding-your-software-supply-chain/configuring-the-dependency-graph
at file:///home/runner/work/_actions/advanced-security/component-detection-dependency-submission-action/v0.1.4/node_modules/@octokit/request/dist-node/index.js:125:1
at processTicksAndRejections (node:internal/process/task_queues:104:5)
at L (file:///home/runner/work/_actions/advanced-security/component-detection-dependency-submission-action/v0.1.4/node_modules/@github/dependency-submission-toolkit/dist/index.js:1:1)
|
|
Dependency Graph
The Dependency graph is disabled for this repository. Please enable it before submitting snapshots. - https://docs.github.com/code-security/supply-chain-security/understanding-your-software-supply-chain/configuring-the-dependency-graph
|
|
Composite action dogfood
Process completed with exit code 1.
|
|
Create a Trusted Publisher
A new Trusted Publisher for the currently running publishing workflow can be created by accessing the following link(s) while logged-in as an owner of the package(s):
|
|
Upgrade to Trusted Publishing
Trusted Publishers allows publishing packages to PyPI from automated environments like GitHub Actions without needing to use username/password combinations or API tokens to authenticate with PyPI. Read more: https://docs.pypi.org/trusted-publishers
|
|
attestations input ignored
The workflow was run with the 'attestations: true' input, but an explicit password was also set, disabling Trusted Publishing. As a result, the attestations input is ignored.
|
|
Dependency Graph
{
"manifests": {
"requirements.txt": {
"resolved": {
"pkg:pypi/pyyaml@6.0.3": {
"package_url": "pkg:pypi/pyyaml@6.0.3",
"relationship": "direct",
"scope": "runtime",
"dependencies": []
},
"pkg:pypi/typing-extensions@4.16.0": {
"package_url": "pkg:pypi/typing-extensions@4.16.0",
"relationship": "indirect",
"scope": "runtime",
"dependencies": []
},
"pkg:pypi/typing-inspection@0.4.4": {
"package_url": "pkg:pypi/typing-inspection@0.4.4",
"relationship": "indirect",
"scope": "runtime",
"dependencies": []
},
"pkg:pypi/charset-normalizer@3.5.1": {
"package_url": "pkg:pypi/charset-normalizer@3.5.1",
"relationship": "direct",
"scope": "runtime",
"dependencies": []
},
"pkg:pypi/pydantic@2.13.4": {
"package_url": "pkg:pypi/pydantic@2.13.4",
"relationship": "direct",
"scope": "runtime",
"dependencies": [
"pkg:pypi/typing-extensions@4.16.0",
"pkg:pypi/typing-inspection@0.4.4",
"pkg:pypi/pydantic-core@2.46.4",
"pkg:pypi/annotated-types@0.8.0"
]
},
"pkg:pypi/pydantic-core@2.46.4": {
"package_url": "pkg:pypi/pydantic-core@2.46.4",
"relationship": "indirect",
"scope": "runtime",
"dependencies": []
},
"pkg:pypi/annotated-types@0.8.0": {
"package_url": "pkg:pypi/annotated-types@0.8.0",
"relationship": "indirect",
"scope": "runtime",
"dependencies": []
},
"pkg:pypi/pydantic@2.14.0b1": {
"package_url": "pkg:pypi/pydantic@2.14.0b1",
"relationship": "direct",
"scope": "runtime",
"dependencies": [
"pkg:pypi/pydantic-core@2.48.0"
]
},
"pkg:pypi/pydantic-core@2.48.0": {
"package_url": "pkg:pypi/pydantic-core@2.48.0",
"relationship": "indirect",
"scope": "runtime",
"dependencies": []
}
},
"name": "requirements.txt",
"file": {
"source_location": "requirements.txt"
}
}
},
"version": 0,
"job": {
"correlator": "dependency-graph",
"id": "32286106765"
},
"sha": "c3426a7b0953ac0cb80eafad13d47d8313756554",
"ref": "refs/heads/main",
"scanned": "2026-08-19T18:13:48.027Z",
"detector": {
"name": "Component Detection",
"version": "0.0.1",
"url": "https://github.com/advanced-security/component-detection-dependency-submission-action"
}
}
|
|
Dependency Graph
Submitting snapshot...
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
python-dist
|
484 KB |
sha256:7f8af3d6379de77279b3639844626bb2cad01e37df65ef4ee528f3ab67c74428
|
|
|
windows-build
|
15.2 MB |
sha256:4b1a95936a6f76b4d96b242b6936bafeae801db8d3568108efebc93a7d648f43
|
|