Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,19 @@ updates:
update-types: [minor, patch]
labels: [dependencies, frontend]

- package-ecosystem: cargo
directory: /arcane/home/honeypot-dashboard/backend-service
schedule:
interval: weekly
day: monday
time: "04:35"
timezone: Europe/Berlin
groups:
backend-compatible:
patterns: ["*"]
update-types: [minor, patch]
labels: [dependencies]

# #154 phase 4: was only these 7 (a leftover of gomod's own directory
# list above, never extended past it) -- every other Dockerfile in this
# tree got zero automated base-image update coverage at all. Now every
Expand Down Expand Up @@ -81,6 +94,8 @@ updates:
- /arcane/home/honeypot-dns-honeypot/dns-honeypot
- /arcane/home/honeypot-endlessh/endlessh-honeypot
- /arcane/home/honeypot-http/http-honeypot
- /arcane/home/honeypot-dashboard/frontend-next
- /arcane/home/honeypot-dashboard/backend-service
- /llm-worker
- /ml-worker
- /arcane/home/honeypot-multipot/multipot
Expand Down
12 changes: 8 additions & 4 deletions .github/workflows/quality.yml
Original file line number Diff line number Diff line change
Expand Up @@ -355,8 +355,10 @@ jobs:
runs-on: [self-hosted, linux, x64, honeypot-ci]
timeout-minutes: 45
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with:
node-version: "24"
cache: npm
Expand Down Expand Up @@ -483,8 +485,10 @@ jobs:
if: needs.ci-target.outputs.homeserver != 'true'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with:
node-version: "24"
cache: npm
Expand Down
8 changes: 5 additions & 3 deletions .github/workflows/security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,9 @@ jobs:
matrix:
language: [go, javascript-typescript, python]
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- if: matrix.language == 'go'
uses: actions/setup-go@v7
with:
Expand All @@ -63,10 +65,10 @@ jobs:
# unpack, and gets re-uploaded from the post step. Same
# reasoning as the quality.yml Go jobs.
cache: ${{ needs.ci-target.outputs.homeserver != 'true' }}
- uses: github/codeql-action/init@v4
- uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
with:
languages: ${{ matrix.language }}
config-file: .github/codeql/codeql-config.yml
- uses: github/codeql-action/analyze@v4
- uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
with:
category: /language:${{ matrix.language }}
9 changes: 9 additions & 0 deletions docs/CI-CD.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,15 @@ Every push to `main` and every pull request runs:
Container images are built for pull requests. A push to `main` or a version tag
publishes the custom images to the repository's GitHub Container Registry.

### CodeQL setup guardrail

`security.yml` uses CodeQL's advanced setup. Keep GitHub's **Settings → Code
security → CodeQL** configuration on **Advanced**, not **Default**: the two
setups cannot process the same analysis, and the resulting failure is
reported as `CodeQL analyses from advanced configurations cannot be processed
when the default setup is enabled`. If that error appears, disable the
repository's default CodeQL setup before changing or rerunning this workflow.

### Trigger, runner, and trust boundary

```mermaid
Expand Down
Loading