diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..2d9c6d0 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,35 @@ +version: 2 +# Weekly, grouped version updates. Security updates are enabled in the repository settings +# and arrive as their own pull requests whenever an advisory matches a locked dependency. +updates: + # Actions are pinned to commit SHAs; Dependabot moves the pins and their version comments. + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly + day: monday + groups: + actions: + patterns: ["*"] + + - package-ecosystem: npm + directory: / + schedule: + interval: weekly + day: monday + groups: + npm-minor-and-patch: + update-types: [minor, patch] + + - package-ecosystem: cargo + directory: /src-tauri + schedule: + interval: weekly + day: monday + groups: + cargo-minor-and-patch: + update-types: [minor, patch] + ignore: + # The Toolbox revision must also match REVISION in src-tauri/src/toolbox.rs; update both with + # scripts/pin-toolbox.mjs after reviewing the Toolbox commit. + - dependency-name: linutil_core diff --git a/.github/workflows/linux-packages.yml b/.github/workflows/linux-packages.yml index d06f9bb..2f2219f 100644 --- a/.github/workflows/linux-packages.yml +++ b/.github/workflows/linux-packages.yml @@ -23,13 +23,14 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 35 steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: "22.23.2" cache: npm - - uses: dtolnay/rust-toolchain@stable + - uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable with: + toolchain: stable components: clippy - name: Install build dependencies run: | @@ -69,15 +70,17 @@ jobs: sleep 30 done exit 1 - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: "22.23.2" - - uses: dtolnay/rust-toolchain@stable + - uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable + with: + toolchain: stable - run: npm ci && npm run check && npm test - run: npm run desktop:package - run: python3 scripts/verify-packages.py - - uses: actions/upload-artifact@v4 + - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 with: name: packages path: artifacts/release/* @@ -96,8 +99,8 @@ jobs: env: DEBIAN_FRONTEND: noninteractive steps: - - uses: actions/checkout@v4 - - uses: actions/download-artifact@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 with: name: packages path: packages @@ -121,8 +124,8 @@ jobs: container: fedora:43 timeout-minutes: 20 steps: - - uses: actions/checkout@v4 - - uses: actions/download-artifact@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 with: name: packages path: packages @@ -143,7 +146,7 @@ jobs: steps: - name: Install build, lint and launch-test tools run: pacman -Syu --noconfirm --needed git nodejs npm rust webkit2gtk-4.1 gtk3 libappindicator-gtk3 namcap xorg-server-xvfb xorg-xauth dbus - - uses: actions/checkout@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: Build package env: RELEASE_BUILD: ${{ github.ref_type == 'tag' || inputs.arch_release }} @@ -170,7 +173,7 @@ jobs: mkdir /arch-release cp /build/command-center-[0-9]*-x86_64.pkg.tar.zst /arch-release/ cd /arch-release && test "$(ls | wc -l)" -eq 1 && sha256sum -- *.pkg.tar.zst > SHA256SUMS && cat SHA256SUMS - - uses: actions/upload-artifact@v4 + - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 with: name: arch-package path: /arch-release/* diff --git a/.github/workflows/security-audit.yml b/.github/workflows/security-audit.yml index d4b99e6..d3b972e 100644 --- a/.github/workflows/security-audit.yml +++ b/.github/workflows/security-audit.yml @@ -19,8 +19,10 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 15 steps: - - uses: actions/checkout@v4 - - uses: dtolnay/rust-toolchain@stable + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable + with: + toolchain: stable - run: cargo install cargo-audit --version 0.22.2 --locked - run: cargo audit --file src-tauri/Cargo.lock @@ -28,8 +30,8 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 10 steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: "22.23.2" - run: npm audit diff --git a/docs/development.md b/docs/development.md index c0975d6..84b2447 100644 --- a/docs/development.md +++ b/docs/development.md @@ -37,6 +37,8 @@ Rust tests exercise temporary Git remotes, fast-forward and divergence behavior, The **Security audit** workflow runs `cargo audit --file src-tauri/Cargo.lock` and `npm audit` on every pull request, every push to main, and weekly, so new advisories against unchanged dependencies are caught too. Run them locally before changing dependencies (`cargo install cargo-audit --locked` once). A known vulnerability fails the check; RustSec "unmaintained" and "unsound" notices are warnings. +Workflow actions are pinned to full commit SHAs, with the version in a trailing comment. Dependabot (`.github/dependabot.yml`) opens grouped weekly updates for Actions, npm, and Cargo; review an Action update's release before merging it. The Commander Toolbox pin is excluded; update it with `scripts/pin-toolbox.mjs`. + Tests do not push real repositories, run personal backups, activate Home Manager, or execute real Toolbox installers. UI changes should also be checked visually in the browser preview and, for native behavior, in the desktop app. ## Updating Commander Toolbox