Skip to content

chore: create a new release#1385

Merged
behnazh-w merged 12 commits intoreleasefrom
main
Apr 24, 2026
Merged

chore: create a new release#1385
behnazh-w merged 12 commits intoreleasefrom
main

Conversation

@behnazh-w
Copy link
Copy Markdown
Member

No description provided.

behnazh-w and others added 12 commits April 7, 2026 10:39
This PR updates the Macaron Action version in docs and the test workflow.

Signed-off-by: behnazh-w <[email protected]>
…ing to the issues (#1352)

Updated all Flake8 plugins and add flake8-logging, then fixed code according to the issues.

Signed-off-by: Jens Troeger <[email protected]>
…n, and improve and update package metadata (#1357)

Signed-off-by: Jens Troeger <[email protected]>
…ribution artifacts and then creates a PEP-503 compatible Simple Index in the dist/ folder (#1358)

Add a new Makefile target simple-index which builds all distribution artifacts and then creates a PEP-503 compatible Simple Index in the dist/ folder.

Signed-off-by: Jens Troeger <[email protected]>
This PR improves build tool detection and buildspec generation across ecosystems, with stronger support for multi-module Java projects and richer build command metadata. There are breaking changes in the schema of macaron.buildspec and build_tool_check table.

Signed-off-by: behnazh-w <[email protected]>
…tion (#1378)

Improved Semgrep rules for obfuscation using insights gained on malicious datasets.

Signed-off-by: Carl Flottmann <[email protected]>
… pinned and hashed requirements.txt (#1377)

Following up on comment #1358 (comment), this change makes the Docker image building reproducible by using Macaron’s pinned and hashed requirements.txt.

Signed-off-by: Jens Troeger <[email protected]>
This PR adds support for detecting uv as a Python build tool and improves Python build-tool reporting reliability.

Signed-off-by: behnazh-w <[email protected]>
Suppress GHSA-vfmq-68hx-4jfw for now until semgrep/semgrep#11630 is resolved and we can upgrade our dependencies to use the latest version of lxml.

Signed-off-by: behnazh-w <[email protected]>
Implements license filtering for Macaron. Adds a new check that detects a repository's license via the GitHub API and validates it against a user-configured SPDX allow-list.

Signed-off-by: ruchitagrawal <[email protected]>
Improves the usability and transparency of Macaron’s GitHub Actions reports by enhancing failure visibility and documentation.

Signed-off-by: behnazh-w <[email protected]>
@github-advanced-security
Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@oracle-contributor-agreement oracle-contributor-agreement Bot added the OCA Verified All contributors have signed the Oracle Contributor Agreement. label Apr 24, 2026
@behnazh-w behnazh-w requested a review from nicallen April 24, 2026 05:19
@behnazh-w behnazh-w merged commit 0574478 into release Apr 24, 2026
46 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

OCA Verified All contributors have signed the Oracle Contributor Agreement.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants