From 3115b5103bff2b5f5ed0dbc2c091f3d07a62fb32 Mon Sep 17 00:00:00 2001 From: Commanderx-code Date: Fri, 25 Sep 2026 13:23:16 -0400 Subject: [PATCH] Pin workflow actions to commit SHAs and configure Dependabot Actions referenced by a movable tag (actions/checkout@v4) run whatever the tag points to, including in the job that builds release packages. Every action is now pinned to the commit its tag resolves to today, so CI runs the same code, with the version in a trailing comment. rust-toolchain now names its toolchain explicitly so a moved pin cannot change it. dependabot.yml opens grouped weekly updates for Actions, npm and Cargo. The Commander Toolbox pin is excluded because it must match REVISION in toolbox.rs and is updated with scripts/pin-toolbox.mjs. Co-Authored-By: Claude Opus 5.5 --- .github/dependabot.yml | 35 ++++++++++++++++++++++++++++ .github/workflows/linux-packages.yml | 29 ++++++++++++----------- .github/workflows/security-audit.yml | 10 ++++---- docs/development.md | 2 ++ 4 files changed, 59 insertions(+), 17 deletions(-) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..2d9c6d0 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,35 @@ +version: 2 +# Weekly, grouped version updates. Security updates are enabled in the repository settings +# and arrive as their own pull requests whenever an advisory matches a locked dependency. +updates: + # Actions are pinned to commit SHAs; Dependabot moves the pins and their version comments. + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly + day: monday + groups: + actions: + patterns: ["*"] + + - package-ecosystem: npm + directory: / + schedule: + interval: weekly + day: monday + groups: + npm-minor-and-patch: + update-types: [minor, patch] + + - package-ecosystem: cargo + directory: /src-tauri + schedule: + interval: weekly + day: monday + groups: + cargo-minor-and-patch: + update-types: [minor, patch] + ignore: + # The Toolbox revision must also match REVISION in src-tauri/src/toolbox.rs; update both with + # scripts/pin-toolbox.mjs after reviewing the Toolbox commit. + - dependency-name: linutil_core diff --git a/.github/workflows/linux-packages.yml b/.github/workflows/linux-packages.yml index d06f9bb..2f2219f 100644 --- a/.github/workflows/linux-packages.yml +++ b/.github/workflows/linux-packages.yml @@ -23,13 +23,14 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 35 steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: "22.23.2" cache: npm - - uses: dtolnay/rust-toolchain@stable + - uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable with: + toolchain: stable components: clippy - name: Install build dependencies run: | @@ -69,15 +70,17 @@ jobs: sleep 30 done exit 1 - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: "22.23.2" - - uses: dtolnay/rust-toolchain@stable + - uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable + with: + toolchain: stable - run: npm ci && npm run check && npm test - run: npm run desktop:package - run: python3 scripts/verify-packages.py - - uses: actions/upload-artifact@v4 + - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 with: name: packages path: artifacts/release/* @@ -96,8 +99,8 @@ jobs: env: DEBIAN_FRONTEND: noninteractive steps: - - uses: actions/checkout@v4 - - uses: actions/download-artifact@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 with: name: packages path: packages @@ -121,8 +124,8 @@ jobs: container: fedora:43 timeout-minutes: 20 steps: - - uses: actions/checkout@v4 - - uses: actions/download-artifact@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 with: name: packages path: packages @@ -143,7 +146,7 @@ jobs: steps: - name: Install build, lint and launch-test tools run: pacman -Syu --noconfirm --needed git nodejs npm rust webkit2gtk-4.1 gtk3 libappindicator-gtk3 namcap xorg-server-xvfb xorg-xauth dbus - - uses: actions/checkout@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: Build package env: RELEASE_BUILD: ${{ github.ref_type == 'tag' || inputs.arch_release }} @@ -170,7 +173,7 @@ jobs: mkdir /arch-release cp /build/command-center-[0-9]*-x86_64.pkg.tar.zst /arch-release/ cd /arch-release && test "$(ls | wc -l)" -eq 1 && sha256sum -- *.pkg.tar.zst > SHA256SUMS && cat SHA256SUMS - - uses: actions/upload-artifact@v4 + - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 with: name: arch-package path: /arch-release/* diff --git a/.github/workflows/security-audit.yml b/.github/workflows/security-audit.yml index d4b99e6..d3b972e 100644 --- a/.github/workflows/security-audit.yml +++ b/.github/workflows/security-audit.yml @@ -19,8 +19,10 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 15 steps: - - uses: actions/checkout@v4 - - uses: dtolnay/rust-toolchain@stable + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable + with: + toolchain: stable - run: cargo install cargo-audit --version 0.22.2 --locked - run: cargo audit --file src-tauri/Cargo.lock @@ -28,8 +30,8 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 10 steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: "22.23.2" - run: npm audit diff --git a/docs/development.md b/docs/development.md index c0975d6..84b2447 100644 --- a/docs/development.md +++ b/docs/development.md @@ -37,6 +37,8 @@ Rust tests exercise temporary Git remotes, fast-forward and divergence behavior, The **Security audit** workflow runs `cargo audit --file src-tauri/Cargo.lock` and `npm audit` on every pull request, every push to main, and weekly, so new advisories against unchanged dependencies are caught too. Run them locally before changing dependencies (`cargo install cargo-audit --locked` once). A known vulnerability fails the check; RustSec "unmaintained" and "unsound" notices are warnings. +Workflow actions are pinned to full commit SHAs, with the version in a trailing comment. Dependabot (`.github/dependabot.yml`) opens grouped weekly updates for Actions, npm, and Cargo; review an Action update's release before merging it. The Commander Toolbox pin is excluded; update it with `scripts/pin-toolbox.mjs`. + Tests do not push real repositories, run personal backups, activate Home Manager, or execute real Toolbox installers. UI changes should also be checked visually in the browser preview and, for native behavior, in the desktop app. ## Updating Commander Toolbox