Skip to content

Migrate package to hatch - #79

Merged
jkanche merged 4 commits into
masterfrom
update-hatchit
Sep 16, 2026
Merged

jkanche merged 4 commits into
masterfrom
update-hatchit

Merge branch 'update-hatchit' of https://github.com/biocpy/singlecell…

9aea86c
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL succeeded Sep 16, 2026 in 3s

6 new alerts including 6 medium severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 6 medium

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 16 in .github/workflows/pre-commit.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Check warning on line 16 in .github/workflows/pre-commit.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action or reusable workflow Medium

Unpinned 3rd party Action 'pre-commit' step
Uses Step
uses 'pre-commit/action' with ref 'v3.0.1', not a pinned commit hash

Check warning on line 34 in .github/workflows/publish-pypi.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Check warning on line 59 in .github/workflows/publish-pypi.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Check warning on line 76 in .github/workflows/publish-pypi.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action or reusable workflow Medium

Unpinned 3rd party Action 'Publish to PyPI and GitHub Pages' step
Uses Step
uses 'pypa/gh-action-pypi-publish' with ref 'release/v1', not a pinned commit hash

Check warning on line 65 in .github/workflows/run-tests.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action or reusable workflow Medium

Unpinned 3rd party Action 'Test the library' step
Uses Step
uses 'codecov/codecov-action' with ref 'v7', not a pinned commit hash