Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/renovate.json
Original file line number Diff line number Diff line change
Expand Up @@ -324,7 +324,7 @@
"/^\\.github/skills/security-scan-docker-image-scripts/run\\.sh$/"
],
"matchStrings": [
"anchore/grype/main/install\\.sh \\| sh -s -- -b /usr/local/bin v(?<currentValue>[0-9]+\\.[0-9]+\\.[0-9]+)",
"anchore/grype/(?:main|[0-9a-f]{40})/install\\.sh \\| sh -s -- -b /usr/local/bin v(?<currentValue>[0-9]+\\.[0-9]+\\.[0-9]+)",
"set_default_env \\\"GRYPE_VERSION\\\" \\\"v(?<currentValue>[^\\\"]+)\\\""
],
"depNameTemplate": "anchore/grype",
Expand Down
4 changes: 3 additions & 1 deletion .github/workflows/container-prune.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,7 @@ permissions:
jobs:
prune-ghcr:
runs-on: ubuntu-latest
if: github.event_name != 'workflow_dispatch' || github.ref == format('refs/heads/{0}', github.event.repository.default_branch)
strategy:
fail-fast: false
matrix:
Expand Down Expand Up @@ -108,6 +109,7 @@ jobs:

prune-dockerhub:
runs-on: ubuntu-latest
if: github.event_name != 'workflow_dispatch' || github.ref == format('refs/heads/{0}', github.event.repository.default_branch)
strategy:
fail-fast: false
matrix:
Expand Down Expand Up @@ -191,7 +193,7 @@ jobs:
summarize:
runs-on: ubuntu-latest
needs: [prune-ghcr, prune-dockerhub]
if: always()
if: always() && (github.event_name != 'workflow_dispatch' || github.ref == format('refs/heads/{0}', github.event.repository.default_branch))
steps:
- name: Download all artifacts
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
Expand Down
30 changes: 20 additions & 10 deletions .github/workflows/docs-to-issues.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,12 @@ jobs:
convert-docs:
name: Convert Markdown to Issues
runs-on: ubuntu-latest
if: github.actor != 'github-actions[bot]' && (github.event_name != 'workflow_run' || github.event.workflow_run.conclusion == 'success')
if: >-
github.actor != 'github-actions[bot]' &&
(github.event_name != 'workflow_run' ||
(github.event.workflow_run.conclusion == 'success' &&
github.event.workflow_run.event == 'push' &&
github.event.workflow_run.head_repository.full_name == github.repository))

steps:
- name: Checkout repository
Expand All @@ -49,21 +54,22 @@ jobs:
node-version: ${{ env.NODE_VERSION }}

- name: Install dependencies
run: npm install gray-matter
run: npm install --ignore-scripts --no-save gray-matter@4.0.3

- name: Detect changed files
id: changes
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9
env:
COMMIT_SHA: ${{ github.event.workflow_run.head_sha || github.sha }}
MANUAL_FILE: ${{ github.event.inputs.file_path }}
with:
script: |
const fs = require('fs');
const path = require('path');
const commitSha = process.env.COMMIT_SHA || context.sha;

// Manual file specification
const manualFile = '${{ github.event.inputs.file_path }}';
const manualFile = process.env.MANUAL_FILE;
if (manualFile) {
if (fs.existsSync(manualFile)) {
core.setOutput('files', JSON.stringify([manualFile]));
Expand Down Expand Up @@ -98,13 +104,14 @@ jobs:
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9
env:
DRY_RUN: ${{ github.event.inputs.dry_run || 'false' }}
FILES_JSON: ${{ steps.changes.outputs.files }}
with:
script: |
const fs = require('fs');
const path = require('path');
const matter = require('gray-matter');

const files = JSON.parse('${{ steps.changes.outputs.files }}');
const files = JSON.parse(process.env.FILES_JSON);
const isDryRun = process.env.DRY_RUN === 'true';
const createdIssues = [];
const errors = [];
Expand Down Expand Up @@ -322,9 +329,10 @@ jobs:

- name: Move processed files
if: steps.process.outputs.created_count != '0' && github.event.inputs.dry_run != 'true'
env:
CREATED_ISSUES: ${{ steps.process.outputs.created_issues }}
run: |
mkdir -p docs/issues/created
CREATED_ISSUES='${{ steps.process.outputs.created_issues }}'
echo "$CREATED_ISSUES" | jq -r '.[].file' | while IFS= read -r file; do
if [ -f "$file" ] && [ -n "$file" ]; then
filename=$(basename "$file")
Expand All @@ -336,22 +344,24 @@ jobs:

- name: Commit moved files
if: steps.process.outputs.created_count != '0' && github.event.inputs.dry_run != 'true'
env:
BRANCH_NAME: ${{ github.event.workflow_run.head_branch || github.ref_name }}
run: |
git config --local user.email "github-actions[bot]@users.noreply.github.com"
git config --local user.name "github-actions[bot]"
git add docs/issues/
# Removed [skip ci] to allow CI checks to run on PRs
# Infinite loop protection: path filter excludes docs/issues/created/** AND github.actor guard prevents bot loops
git diff --staged --quiet || git commit -m "chore: move processed issue files to created/"
BRANCH="${{ github.event.workflow_run.head_branch || github.ref_name }}"
git push origin HEAD:refs/heads/${BRANCH}
git push origin "HEAD:refs/heads/${BRANCH_NAME}"

- name: Summary
if: always()
env:
CREATED: ${{ steps.process.outputs.created_issues }}
ERRORS: ${{ steps.process.outputs.errors }}
DRY_RUN: ${{ github.event.inputs.dry_run }}
run: |
CREATED='${{ steps.process.outputs.created_issues }}'
ERRORS='${{ steps.process.outputs.errors }}'
DRY_RUN='${{ github.event.inputs.dry_run }}'

{
echo "## Docs to Issues Summary"
Expand Down
5 changes: 4 additions & 1 deletion .github/workflows/dry-run-history-rewrite.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,10 @@ jobs:
preview-history:
name: Dry-run preview for history rewrite
runs-on: ubuntu-latest
if: ${{ github.event_name != 'workflow_run' || github.event.workflow_run.conclusion == 'success' }}
if: >-
${{ github.event_name != 'workflow_run' ||
(github.event.workflow_run.conclusion == 'success' &&
github.event.workflow_run.head_repository.full_name == github.repository) }}
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
Expand Down
7 changes: 5 additions & 2 deletions .github/workflows/e2e-tests-split.yml
Original file line number Diff line number Diff line change
Expand Up @@ -146,9 +146,12 @@ jobs:
steps:
- name: Resolve image inputs
id: resolve-image
env:
INPUT_IMAGE_REF: ${{ inputs.image_ref }}
INPUT_IMAGE_TAG: ${{ inputs.image_tag || 'charon:e2e-test' }}
run: |
IMAGE_REF="${{ inputs.image_ref }}"
IMAGE_TAG="${{ inputs.image_tag || 'charon:e2e-test' }}"
IMAGE_REF="${INPUT_IMAGE_REF}"
IMAGE_TAG="${INPUT_IMAGE_TAG}"
if [ -n "$IMAGE_REF" ]; then
{
echo "image_source=registry"
Expand Down
5 changes: 4 additions & 1 deletion .github/workflows/history-rewrite-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,10 @@ permissions:
jobs:
test:
runs-on: ubuntu-latest
if: ${{ github.event_name != 'workflow_run' || github.event.workflow_run.conclusion == 'success' }}
if: >-
${{ github.event_name != 'workflow_run' ||
(github.event.workflow_run.conclusion == 'success' &&
github.event.workflow_run.head_repository.full_name == github.repository) }}
steps:
- name: Checkout with full history
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
Expand Down
8 changes: 8 additions & 0 deletions .github/workflows/nightly-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,14 @@ jobs:
agent_changed: ${{ steps.sync.outputs.agent_changed }}

steps:
- name: Restrict manual runs to the nightly branch
if: github.event_name == 'workflow_dispatch' && github.ref != 'refs/heads/nightly'
env:
TRIGGER_REF: ${{ github.ref }}
run: |
echo "::error::Manual runs are only permitted from the nightly branch (got ${TRIGGER_REF})"
exit 1

- name: Checkout nightly branch
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
Expand Down
9 changes: 6 additions & 3 deletions .github/workflows/quality-checks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -468,16 +468,19 @@ jobs:

- name: Check if frontend was modified in PR
id: check-frontend
env:
EVENT_NAME: ${{ github.event_name }}
BASE_REF: ${{ github.event.pull_request.base.ref }}
run: |
if [ "${{ github.event_name }}" = "push" ]; then
if [ "${EVENT_NAME}" = "push" ]; then
echo "frontend_changed=true" >> "$GITHUB_OUTPUT"
exit 0
fi
# Try to fetch the PR base ref. This may fail for forked PRs or other cases.
git fetch origin "${{ github.event.pull_request.base.ref }}" --depth=1 || true
git fetch origin "${BASE_REF}" --depth=1 || true

# Compute changed files against the PR base ref, fallback to origin/main, then fallback to last 10 commits
CHANGED=$(git diff --name-only "origin/${{ github.event.pull_request.base.ref }}...HEAD" 2>/dev/null || echo "")
CHANGED=$(git diff --name-only "origin/${BASE_REF}...HEAD" 2>/dev/null || echo "")
printf "Changed files (base ref):\n%s\n" "$CHANGED"

if [ -z "$CHANGED" ]; then
Expand Down
Loading
Loading