Copilot commented on code in PR #838:
URL: https://github.com/apache/iceberg-cpp/pull/838#discussion_r3636953503


##########
.github/workflows/cpp-linter.yml:
##########
@@ -91,24 +96,40 @@ jobs:
         with:
           path: ${{ github.workspace }}/.sccache
           key: sccache-cpp-linter-ubuntu-${{ github.run_id }}
-      - uses: 
cpp-linter/cpp-linter-action@0f6d1b8d7e38b584cbee606eb23d850c217d54f8 # v2.15.1
+      - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # 
v6.3.0
+        if: github.event_name == 'pull_request'
+        with:
+          python-version: '3.13'
+      - name: Install cpp-linter and clang tools
+        if: github.event_name == 'pull_request'
+        run: |
+          python -m pip install --upgrade pip
+          python -m pip install "cpp-linter==${CPP_LINTER_VERSION}" 
"clang-format==${CLANG_FORMAT_VERSION}" "clang-tidy==${CLANG_TIDY_VERSION}"

Review Comment:
   This introduces new runtime supply-chain dependencies via PyPI downloads in 
CI. If your project’s security posture requires tighter controls, consider 
adding a constraints/lock approach (e.g., a `requirements.txt`/constraints file 
with hashes and `--require-hashes`) so CI installs are reproducible and 
resistant to dependency substitution.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to