Skip to content

Conversation

art1f1c3R
Copy link
Member

@art1f1c3R art1f1c3R commented Jul 21, 2025

Summary

Semgrep version 1.113.0 has been approved for installing using pip. This is an easier and more streamlined way to install the dependency and is easier to maintain. This PR updates Macaron's release artifacts to use this method of installation instead of the previously developed build from source method.

Description of changes

The final docker file now uses Semgrep from the requirements file instead of using the dependency artifact.

Checklist

  • I have reviewed the contribution guide.
  • My PR title and commits follow the Conventional Commits convention.
  • My commits include the "Signed-off-by" line.
  • I have signed my commits following the instructions provided by GitHub. Note that we run GitHub's commit verification tool to check the commit signatures. A green verified label should appear next to all of your commits on GitHub.
  • I have updated the relevant documentation, if applicable.
  • I have tested my changes and verified they work as expected.

@oracle-contributor-agreement oracle-contributor-agreement bot added the OCA Verified All contributors have signed the Oracle Contributor Agreement. label Jul 21, 2025
@art1f1c3R art1f1c3R merged commit fab7158 into main Jul 21, 2025
11 checks passed
@art1f1c3R art1f1c3R deleted the art1f1c3R/semgrep_pypi_revert branch August 1, 2025 04:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
OCA Verified All contributors have signed the Oracle Contributor Agreement.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants