Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 35 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
version: 2
# Weekly, grouped version updates. Security updates are enabled in the repository settings
# and arrive as their own pull requests whenever an advisory matches a locked dependency.
updates:
# Actions are pinned to commit SHAs; Dependabot moves the pins and their version comments.
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
day: monday
groups:
actions:
patterns: ["*"]

- package-ecosystem: npm
directory: /
schedule:
interval: weekly
day: monday
groups:
npm-minor-and-patch:
update-types: [minor, patch]

- package-ecosystem: cargo
directory: /src-tauri
schedule:
interval: weekly
day: monday
groups:
cargo-minor-and-patch:
update-types: [minor, patch]
ignore:
# The Toolbox revision must also match REVISION in src-tauri/src/toolbox.rs; update both with
# scripts/pin-toolbox.mjs after reviewing the Toolbox commit.
- dependency-name: linutil_core
29 changes: 16 additions & 13 deletions .github/workflows/linux-packages.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,13 +23,14 @@ jobs:
runs-on: ubuntu-24.04
timeout-minutes: 35
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: "22.23.2"
cache: npm
- uses: dtolnay/rust-toolchain@stable
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
with:
toolchain: stable
components: clippy
- name: Install build dependencies
run: |
Expand Down Expand Up @@ -69,15 +70,17 @@ jobs:
sleep 30
done
exit 1
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: "22.23.2"
- uses: dtolnay/rust-toolchain@stable
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
with:
toolchain: stable
- run: npm ci && npm run check && npm test
- run: npm run desktop:package
- run: python3 scripts/verify-packages.py
- uses: actions/upload-artifact@v4
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: packages
path: artifacts/release/*
Expand All @@ -96,8 +99,8 @@ jobs:
env:
DEBIAN_FRONTEND: noninteractive
steps:
- uses: actions/checkout@v4
- uses: actions/download-artifact@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: packages
path: packages
Expand All @@ -121,8 +124,8 @@ jobs:
container: fedora:43
timeout-minutes: 20
steps:
- uses: actions/checkout@v4
- uses: actions/download-artifact@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: packages
path: packages
Expand All @@ -143,7 +146,7 @@ jobs:
steps:
- name: Install build, lint and launch-test tools
run: pacman -Syu --noconfirm --needed git nodejs npm rust webkit2gtk-4.1 gtk3 libappindicator-gtk3 namcap xorg-server-xvfb xorg-xauth dbus
- uses: actions/checkout@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- name: Build package
env:
RELEASE_BUILD: ${{ github.ref_type == 'tag' || inputs.arch_release }}
Expand All @@ -170,7 +173,7 @@ jobs:
mkdir /arch-release
cp /build/command-center-[0-9]*-x86_64.pkg.tar.zst /arch-release/
cd /arch-release && test "$(ls | wc -l)" -eq 1 && sha256sum -- *.pkg.tar.zst > SHA256SUMS && cat SHA256SUMS
- uses: actions/upload-artifact@v4
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: arch-package
path: /arch-release/*
Expand Down
10 changes: 6 additions & 4 deletions .github/workflows/security-audit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,17 +19,19 @@ jobs:
runs-on: ubuntu-24.04
timeout-minutes: 15
steps:
- uses: actions/checkout@v4
- uses: dtolnay/rust-toolchain@stable
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
with:
toolchain: stable
- run: cargo install cargo-audit --version 0.22.2 --locked
- run: cargo audit --file src-tauri/Cargo.lock

npm-audit:
runs-on: ubuntu-24.04
timeout-minutes: 10
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: "22.23.2"
- run: npm audit
2 changes: 2 additions & 0 deletions docs/development.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,8 @@ Rust tests exercise temporary Git remotes, fast-forward and divergence behavior,

The **Security audit** workflow runs `cargo audit --file src-tauri/Cargo.lock` and `npm audit` on every pull request, every push to main, and weekly, so new advisories against unchanged dependencies are caught too. Run them locally before changing dependencies (`cargo install cargo-audit --locked` once). A known vulnerability fails the check; RustSec "unmaintained" and "unsound" notices are warnings.

Workflow actions are pinned to full commit SHAs, with the version in a trailing comment. Dependabot (`.github/dependabot.yml`) opens grouped weekly updates for Actions, npm, and Cargo; review an Action update's release before merging it. The Commander Toolbox pin is excluded; update it with `scripts/pin-toolbox.mjs`.

Tests do not push real repositories, run personal backups, activate Home Manager, or execute real Toolbox installers. UI changes should also be checked visually in the browser preview and, for native behavior, in the desktop app.

## Updating Commander Toolbox
Expand Down
Loading