Stirling-PDF/.github/scripts
Ludy f5f011f1e0
deps: Pin Python dev dependencies and lock hashes to remediate security alert 302 (#4173)
## Description of Changes

- **What was changed**
- Added `.github/scripts/requirements_dev.in` and an autogenerated,
hash-locked `.github/scripts/requirements_dev.txt` to control Python dev
dependencies via `pip-compile`.
- **Why the change was made**
- To remediate a GitHub code scanning alert by removing vulnerable
transitive ranges and ensuring reproducible installs with vetted
versions and hashes.
- **Any challenges encountered**
- Reconciling version constraints among image/PDF tooling (e.g., Pillow,
pdf2image, OpenCV, WeasyPrint) while keeping wheels available across CI
platforms.
- Ensuring the generated lockfile remains maintainable and can be
refreshed with `pip-compile` when needed.



Closes
#https://github.com/Stirling-Tools/Stirling-PDF/security/code-scanning/302

---

## Checklist

### General

- [x] I have read the [Contribution
Guidelines](https://github.com/Stirling-Tools/Stirling-PDF/blob/main/CONTRIBUTING.md)
- [x] I have read the [Stirling-PDF Developer
Guide](https://github.com/Stirling-Tools/Stirling-PDF/blob/main/devGuide/DeveloperGuide.md)
(if applicable)
- [ ] I have read the [How to add new languages to
Stirling-PDF](https://github.com/Stirling-Tools/Stirling-PDF/blob/main/devGuide/HowToAddNewLanguage.md)
(if applicable)
- [ ] I have performed a self-review of my own code
- [ ] My changes generate no new warnings

### Documentation

- [ ] I have updated relevant docs on [Stirling-PDF's doc
repo](https://github.com/Stirling-Tools/Stirling-Tools.github.io/blob/main/docs/)
(if functionality has heavily changed)
- [ ] I have read the section [Add New Translation
Tags](https://github.com/Stirling-Tools/Stirling-PDF/blob/main/devGuide/HowToAddNewLanguage.md#add-new-translation-tags)
(for new translation tags only)

### UI Changes (if applicable)

- [ ] Screenshots or videos demonstrating the UI changes are attached
(e.g., as comments or direct attachments in the PR)

### Testing (if applicable)

- [ ] I have tested my changes locally. Refer to the [Testing
Guide](https://github.com/Stirling-Tools/Stirling-PDF/blob/main/devGuide/DeveloperGuide.md#6-testing)
for more details.
2025-08-24 22:03:12 +01:00
..
check_language_properties.py refactor: move modules under app/ directory and update file paths (#3938) 2025-07-14 20:53:11 +01:00
requirements_dev.in deps: Pin Python dev dependencies and lock hashes to remediate security alert 302 (#4173) 2025-08-24 22:03:12 +01:00
requirements_dev.txt deps: Pin Python dev dependencies and lock hashes to remediate security alert 302 (#4173) 2025-08-24 22:03:12 +01:00
requirements_pre_commit.in Add: require-hashes pre-commit (#2684) 2025-01-13 18:27:27 +00:00
requirements_pre_commit.txt chore(ci): include testing/** in file change detection for docker-compose-tests workflow (#4206) 2025-08-21 10:31:25 +01:00
requirements_sync_readme.in Fix: Pinned-Dependencies sync_files.yml (#2660) 2025-01-10 11:25:23 +00:00
requirements_sync_readme.txt deps: update Python requirements and add --strip-extras flag (#3887) 2025-07-07 10:05:23 +01:00