From 87c1de2fa70331f1d566b80c468c3a7da11e6309 Mon Sep 17 00:00:00 2001 From: Xore Date: Wed, 23 Sep 2026 23:50:24 +0200 Subject: [PATCH] ci: adopt OmniRoute CI hardening for #3194 --- .github/dependabot.yml | 15 +++++++++++++++ .github/workflows/quality.yml | 12 ++++++++---- .github/workflows/security.yml | 8 +++++--- docs/CI-CD.md | 9 +++++++++ 4 files changed, 37 insertions(+), 7 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 19ad14190..853eed2f7 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -49,6 +49,19 @@ updates: update-types: [minor, patch] labels: [dependencies, frontend] + - package-ecosystem: cargo + directory: /arcane/home/honeypot-dashboard/backend-service + schedule: + interval: weekly + day: monday + time: "04:35" + timezone: Europe/Berlin + groups: + backend-compatible: + patterns: ["*"] + update-types: [minor, patch] + labels: [dependencies] + # #154 phase 4: was only these 7 (a leftover of gomod's own directory # list above, never extended past it) -- every other Dockerfile in this # tree got zero automated base-image update coverage at all. Now every @@ -81,6 +94,8 @@ updates: - /arcane/home/honeypot-dns-honeypot/dns-honeypot - /arcane/home/honeypot-endlessh/endlessh-honeypot - /arcane/home/honeypot-http/http-honeypot + - /arcane/home/honeypot-dashboard/frontend-next + - /arcane/home/honeypot-dashboard/backend-service - /llm-worker - /ml-worker - /arcane/home/honeypot-multipot/multipot diff --git a/.github/workflows/quality.yml b/.github/workflows/quality.yml index aaf89a053..c554819e4 100644 --- a/.github/workflows/quality.yml +++ b/.github/workflows/quality.yml @@ -355,8 +355,10 @@ jobs: runs-on: [self-hosted, linux, x64, honeypot-ci] timeout-minutes: 45 steps: - - uses: actions/checkout@v7 - - uses: actions/setup-node@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 with: node-version: "24" cache: npm @@ -483,8 +485,10 @@ jobs: if: needs.ci-target.outputs.homeserver != 'true' runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 - - uses: actions/setup-node@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 with: node-version: "24" cache: npm diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index fdbd15e72..05e0f1f3a 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -45,7 +45,9 @@ jobs: matrix: language: [go, javascript-typescript, python] steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - if: matrix.language == 'go' uses: actions/setup-go@v7 with: @@ -63,10 +65,10 @@ jobs: # unpack, and gets re-uploaded from the post step. Same # reasoning as the quality.yml Go jobs. cache: ${{ needs.ci-target.outputs.homeserver != 'true' }} - - uses: github/codeql-action/init@v4 + - uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 with: languages: ${{ matrix.language }} config-file: .github/codeql/codeql-config.yml - - uses: github/codeql-action/analyze@v4 + - uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 with: category: /language:${{ matrix.language }} diff --git a/docs/CI-CD.md b/docs/CI-CD.md index f1468de53..d16d34d64 100644 --- a/docs/CI-CD.md +++ b/docs/CI-CD.md @@ -18,6 +18,15 @@ Every push to `main` and every pull request runs: Container images are built for pull requests. A push to `main` or a version tag publishes the custom images to the repository's GitHub Container Registry. +### CodeQL setup guardrail + +`security.yml` uses CodeQL's advanced setup. Keep GitHub's **Settings → Code +security → CodeQL** configuration on **Advanced**, not **Default**: the two +setups cannot process the same analysis, and the resulting failure is +reported as `CodeQL analyses from advanced configurations cannot be processed +when the default setup is enabled`. If that error appears, disable the +repository's default CodeQL setup before changing or rerunning this workflow. + ### Trigger, runner, and trust boundary ```mermaid