Commit Graph

22 Commits

Author SHA1 Message Date
Jeremy Daer 22b6d4bdaf Bump ruby/setup-ruby to v1.321.0
v1.295.0 predates Ruby 3.4.10 — its baked-in version index stops at
3.4.9, so asking for anything newer fails with "Unknown version 3.4.10
for ruby on ubuntu-24.04". The next commit needs 3.4.10, and pinning
our Ruby to whatever an old action happens to know is backwards.

SHA verified against the v1.321.0 tag.
2026-08-22 12:30:43 -07:00
Jeremy Daer 431aad8b71 Retire the docker ecosystem from Dependabot
The base image tag is a build arg — `ARG RUBY_VERSION` plus
`FROM ruby:$RUBY_VERSION-slim` — and Dependabot's docker updater matches
literal tags, so this entry has never had anything to propose. It ran
green every week and reported nothing, which reads as coverage and
isn't.

No other repo in the fleet configures a docker ecosystem, and none
could: they all either interpolate a variable or pull from the internal
registry. Inlining the tag here to buy coverage would make this
Dockerfile the outlier instead, against Rails-generated boilerplate.
Ruby bumps stay a manual, human-decided step.
2026-08-22 02:21:49 -07:00
Jeremy Daer 9310b002d7 Drop the unsupported semver cooldown keys from the docker ecosystem (#251)
The docker block copied bundler's cooldown wholesale, but Dependabot only
accepts semver-major/minor/patch-days for ecosystems whose versions it
classifies as semver, and container tags aren't. One invalid property
invalidates the entire file rather than the block it sits in, so since
this config landed in #248 the version updater has not run for any
ecosystem at all:

  Your .github/dependabot.yml contained invalid details
  The property '#/updates/2/cooldown/semver-major-days' is not supported
  for the package ecosystem 'docker'. (and -minor-, -patch-)

That is why #249's cooldown exclude for brakeman never took effect, and
why #250 had to bump the workflow linter pins by hand while every other
repo got a Dependabot PR. It also left `bin/brakeman --ensure-latest 15`
armed with nothing to disarm it: the lock pins brakeman 8.0.6, and CI
would have gone red roughly 15 days after 8.0.7 shipped.

Security updates were never affected — those don't read this file, which
is why the only four Dependabot runs here are single-gem security bumps.

docker keeps default-days, which is supported for every ecosystem.
2026-08-21 21:49:40 -07:00
Jeremy Daer dfd2dd2bca Bump actionlint and zizmor-action to current releases (#250)
Dependabot version updates are disabled for this repo, so the weekly
github-actions group never proposed these. The pins had been frozen since
March: zizmor-action v0.5.2 ships zizmor 1.23.1, which flags
secrets-outside-env at the default persona -- that moved to the auditor
persona in zizmor 1.24.0. v0.6.2 ships zizmor 1.29.0.

Both linters pass locally at the new versions.
2026-08-20 03:08:26 -07:00
Jeremy Daer 487125dc4c Bump brakeman to 8.0.6 and stop --ensure-latest reddening CI (#249)
* Bump brakeman to 8.0.6

Brakeman 8.0.6 shipped 2026-08-12: corrected Rails 8.0 EOL date, added
Rails 8.1 and Ruby 4.0 EOL dates, and fixed command-injection false
positives.

brakeman's only runtime dependency is racc and its required ruby is
>= 3.2.0, both unchanged since 7.1.2, so this is a version bump with no
other movement in the graph.

* Give brakeman's --ensure-latest a 15-day grace period

Bare --ensure-latest exits 5 the moment a newer brakeman exists, so a
release turns this build red before anyone has a chance to react. That
is what happened on 2026-08-12 when 8.0.6 shipped.

The flag takes an optional minimum age in days and only complains once
the latest release is at least that old. 15 is the maximum it accepts;
brakeman rejects anything outside 1-15.

* Exempt brakeman from the dependabot cooldown

The grace period on --ensure-latest is only headroom if the bump lands
inside it. A weekly schedule plus a 7-day cooldown can take 14 days to
so much as open the PR, leaving a single day to merge it.

Excluding brakeman from the cooldown caps the delay at the weekly
schedule, comfortably inside the 15 days.
2026-08-19 09:27:49 -07:00
Stanko K.R. d79225ecd1 Fix version number for CI built images 2026-07-30 18:34:54 +02:00
Mike Dalessio 3fada3d997 ci: harden GitHub Actions workflows (#185)
* Add GitHub Actions audit job (actionlint + zizmor) to CI

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Configure dependabot for GitHub Actions, bundler, and Docker

Batches all action updates into a single weekly PR. Adds cooldown
periods to all ecosystems.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Add local GitHub Actions linting (actionlint + zizmor) to bin/setup and bin/ci

Install actionlint, shellcheck, and zizmor in bin/setup. Run both
linters as CI steps in config/ci.rb alongside existing style checks.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Pin all GitHub Actions to SHA hashes

Run pinact to pin action versions to specific commit SHAs,
preventing supply chain attacks from tag mutation.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Fix high severity zizmor findings

- Suppress unpinned-images for redis service containers (digest
  pinning is nontrivial for service containers)
- Move workflow-level permissions to job-level in publish-image.yml
  (build gets full set, manifest gets only what it needs)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Fix medium severity zizmor findings

- Add persist-credentials: false to all checkout steps
- Add permissions: {} at workflow level in ci.yml
- Add job-level permissions (contents: read) to all CI jobs

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Fix informational template-injection findings in publish-image.yml

Move steps.meta.outputs.tags from inline ${{ }} expressions to env
vars in both the manifest creation and cosign signing steps.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Update brakeman to 8.0.4

bin/brakeman uses --ensure-latest which fails if not on the newest version.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-20 19:26:25 -04:00
Stanko K.R. 7b6ce97afd Add contributing guide 2025-09-18 14:51:42 +02:00
Alexander Nicholson 4584443+DragonStuff@users.noreply.github.com cf1ebda01c fix: run on tag and not release 2025-09-10 04:18:08 +09:00
Alexander Nicholson 4584443+DragonStuff@users.noreply.github.com 08cab1679e fix: final tag release 2025-09-10 04:16:00 +09:00
Alexander Nicholson 4584443+DragonStuff@users.noreply.github.com d3d196af1c fix: disable sbom and provenance
Disabled SBOM/provenance embedding and stopped uploading build attestations. Those were creating untagged OCI referrers in GHCR. Still sign with cosign with signatures as referrers.
2025-09-10 04:02:28 +09:00
Alexander Nicholson 4584443+DragonStuff@users.noreply.github.com fc24ab44fc fix: only add tag latest on git version tag 2025-09-10 03:55:02 +09:00
Alexander Nicholson 4584443+DragonStuff@users.noreply.github.com 8608ba2520 chore: use build arg for image description 2025-09-05 09:56:42 +02:00
Alexander Nicholson 4584443+DragonStuff@users.noreply.github.com 99e6e46b04 chore: add static env for opencontainer description 2025-09-05 09:48:52 +02:00
Alexander Nicholson 4584443+DragonStuff@users.noreply.github.com 8ddd9270b3 fix: update Dockerfile to specify MIT license directly and remove unused ARG 2025-09-05 09:39:49 +02:00
Alexander Nicholson 4584443+DragonStuff@users.noreply.github.com 47d8122a7f fix: ensure manifest creation is quoted 2025-09-04 13:08:48 +02:00
Alexander Nicholson 4584443+DragonStuff@users.noreply.github.com a2caf0ae5a fix: correct empty manifest description 2025-09-04 13:04:56 +02:00
Alexander Nicholson 4584443+DragonStuff@users.noreply.github.com 27244295fe feature: add opencontainers annotations 2025-09-04 12:58:43 +02:00
Alexander Nicholson 4584443+DragonStuff@users.noreply.github.com f003b8fcfe fix: use native runners for arm64 and amd64
Should significantly reduce build time as we won't be emulating with QEMU.
2025-09-04 12:48:06 +02:00
Alexander Nicholson 4584443+DragonStuff@users.noreply.github.com 6efb901637 fix: use locked versions on ci to prevent issues in the future 2025-09-04 12:30:59 +02:00
Alexander Nicholson 4584443+DragonStuff@users.noreply.github.com ecb0ecaccf feature(ci): add actions workflow to publish Docker image to GHCR 2025-09-04 12:26:00 +02:00
Kevin McConnell df76a227dc Hello world
First open source release of Campfire 🎉
2025-08-21 09:31:59 +01:00