Skip to content

Promote nightly to main (2026-10-05) - #1488

Merged
Wikid82 merged 70 commits into
mainfrom
nightly
Oct 5, 2026
Merged

Wikid82 merged 70 commits into
mainfrom
nightly

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🚀 Nightly to Main Promotion

Date: 2026-10-05
Trigger: Scheduled weekly promotion
Commits: 70 commits to promote
Changes: 171 files changed, 8750 insertions(+), 1287 deletions(-)


Commits Being Promoted

Showing first 50 of 70 commits:

68a8d2f7 chore: remove Aikido API key from tracked Claude settings
4da6d869 docs: scrub example emergency token from archived docs
82cc160b test: use obviously fake token in emergency server redaction test
c1f9bf0d docs: replace example emergency tokens with placeholders
735549c7 docs: add Aikido security audit report badge to README
518526be chore(docs-site): override feed to ^6.0.0 and add update script
4e5c7b51 chore(deps): bump lucide-react from 1.51.0 to 1.52.0
37210e21 chore(docker): update GeoLite2-Country.mmdb checksum (#1487)
b4dac5a7 chore(deps): bump http-cache-semantics override to 4.3.0
4a714509 chore: move serialize-javascript script to docs-site directory
80aab864 chore(ci): drop workflow_run trigger from PR security scan
d77293e9 chore(ci): scope package write permissions to the jobs that publish
3b4f00b4 chore(ci): scope workflow token permissions per job and guard workflow_run against forks
cd644662 Merge branch 'development' into bot/update-geolite2-checksum
bfc19875 chore(ci): push with an explicit token instead of persisted checkout credentials
e4e69479 chore(ci): stop persisting git credentials in build and release workflow checkouts
07a8e68e chore(ci): stop persisting git credentials in test and scan workflow checkouts
c7b284c4 chore: update dependency uuid to v14 (#1485)
78b0026a chore(docker): update GeoLite2-Country.mmdb checksum
66cb560c Merge branch 'development' into renovate/uuid-14.x
2f4d88d5 chore(docker): refresh bundled proxy toolchain image (#1486)
3d88540a chore(docker): refresh bundled proxy toolchain image
937a7199 chore: update dependency uuid to v14
7eb6181c fix(security): pin pgproto3/v2 to v2.3.3 in crowdsec build
c34e060d chore: update dependency anchore/grype to v0.120.0 (#1484)
dc66f2c9 chore(deps): allowlist unpatched braces and http-cache-semantics advisories in docs site
b70837d5 docs: fix broken links to contributor-only pages in the docs site
9353d7e9 chore(deps): override sitemap and uuid in docs site
faea809d chore(deps): bump lucide-react from 1.50.0 to 1.51.0
34653e6c chore(deps): bump eslint-plugin-unicorn to v77
4312d881 chore: update dependency anchore/grype to v0.120.0
08047942 fix(security): harden URL handling in provider integrations (#1476)
16351cbf chore(deps): bump otelhttp to v0.72.0 and add powerdns to updater
11b9792c chore: ignore plugin build leftovers in the powerdns module
13152899 test: handle ignored errors flagged by the full linter set
88440b7f chore(docker): set ownership at copy time instead of recursive chown of /app
b8470470 chore: teach code scanning about the shared outbound request helpers
afcc35bf docs: document stricter address checks for provider integrations
4cfb0820 fix: validate DNS provider endpoint addresses
febd3cd4 fix(security): harden URL handling in provider integrations
f15fd842 refactor: add shared helper for outbound provider requests
328b6f46 chore: build and test the powerdns plugin in the workspace
f6c85c6e chore(docker): refresh bundled proxy toolchain image (#1475)
dba3150d chore(docker): refresh bundled proxy toolchain image
98a872e4 fix: apply dnsimple-go pin via go get instead of xcaddy --with
e69da964 deps: pin dnsimple-go to v8.3.1 in Caddy build
a8e7d5e8 chore: harden workflow triggers and checkout credentials
52d63f03 chore: add Aikido API key env to Claude settings
9e72b821 fix(security): harden request validation in the API layer (#1471)
1b1e7038 chore: merge development into fix/security-hardening-3

...and 20 more commits


Pre-Merge Checklist

  • All status checks pass
  • No critical security issues identified
  • Changelog is up-to-date (auto-generated via workflow)
  • Version bump is appropriate (if applicable)

⚠️ Merge Instructions — CRITICAL

You MUST use "Create a merge commit" — NOT squash or rebase.

Squash merging collapses all feat:/fix: commits into a single bullet-list body.
The auto-versioning workflow cannot parse these bullets, so minor version bumps are
silently skipped and release notes only show the weekly PR title instead of real changes.

Once all checks pass:

  1. Review the commit summary above
  2. Approve if changes look correct
  3. Merge → click the dropdown arrow → select "Create a merge commit"

This PR was automatically created by the Weekly Nightly Promotion workflow.

Wikid82 and others added 30 commits October 3, 2026 07:25
Add a small package for per-process secrets and local address checks, and share the management network helper.
Tighten validation in a few API handlers and surface persistence errors.
Add an engine-wide middleware chain constructor and a request context record used by the auth helpers.
Pass request context details between the proxy and the API for routes that target the API itself.
Tighten credential handling and session lifecycle in the authentication service and user handlers, with accompanying tests.
Read caller identity through shared accessors and tighten request validation. Adds guard and regression tests.
Rebuilds the prebuilt Caddy/CrowdSec toolchain image so the shipped
binaries pick up upstream fixes, and bumps the digest pin in the
Dockerfile.
Give the bundled PowerDNS plugin its own module entry in the repository
workspace so it is compiled and tested alongside the backend with identical
dependency versions. This adds a make target and CI step that build the plugin
(CGO enabled, same toolchain and flags as the host binary: no trimpath, race
or cover) and a plugin.Open smoke test that always rebuilds the plugin into a
temporary directory.

The new manifest lives in the existing plugin directory and only imports the
public backend packages; no backend code is copied or moved. The
Renovate config is updated accordingly.

No behaviour change.
Introduce a small public helper package for plugins and in-tree providers that
need to make outbound HTTP requests to administrator-configured endpoints, and
consolidate the address-policy checks in the internal network package behind a
single predicate. Policy rejections now carry a stable sentinel error that
omits resolved addresses, and optional range-blocking client options are added
(off by default).

Foundation for the following commits, which add the first callers; no behaviour
change.
Wikid82 and others added 24 commits October 4, 2026 02:15
Add a go get step for github.com/jackc/pgproto3/v2@v2.3.3 before go mod
tidy to address CVE-2026-32286, a buffer overflow in pgproto3/v2. The
bundled crowdsec and cscli binaries otherwise resolve to a vulnerable
version via MVS.
Rebuilds the prebuilt Caddy/CrowdSec toolchain image so the shipped
binaries pick up upstream fixes, and bumps the digest pin in the
Dockerfile.
Automated checksum update for GeoLite2-Country.mmdb database.

Old: aa10ad6c6dc7daa32344954a9bdfae83d8e791540b7d17f7d06086aeb5b630cc
New: ff539785596f72ac2a07048f08506b38134bcf3b568182fd65f4534817bf91d7

Auto-generated by: .github/workflows/update-geolite2.yml
Update the docs-site npm override and lockfile to http-cache-semantics
4.3.0. Add scripts/npm/docs-site/http-cache-semantics.sh to automate
the bump. It refuses to add an override that is not already declared
and preserves the existing range prefix.
Pin the transitive `feed` dependency to ^6.0.0 via npm overrides and
refresh the lockfile. Add scripts/npm/docs-site/feed.sh to bump the
override to the latest release, refusing to run in modules that don't
already declare it.
@github-actions github-actions Bot added automated Automatically generated by CI/CD weekly-promotion Weekly promotion from nightly to main labels Oct 5, 2026
@codecov

codecov Bot commented Oct 5, 2026

Copy link
Copy Markdown

@github-advanced-security

Copy link
Copy Markdown
Contributor

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

✅ Supply Chain Verification Results

✅ PASSED

📦 SBOM Summary

  • Components: 1870

🔍 Vulnerability Scan

Severity Count
🔴 Critical 0
🟠 High 0
🟡 Medium 0
🟢 Low 0
Total 0

📎 Artifacts

  • SBOM (CycloneDX JSON) and Grype results available in workflow artifacts

Generated by Supply Chain Verification workflow • View Details

@Wikid82
Wikid82 merged commit 6339578 into main Oct 5, 2026
121 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated Automatically generated by CI/CD weekly-promotion Weekly promotion from nightly to main

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants