Some checks failed
CICD / Build and Publish CICD Base Image (push) Successful in 36s
CICD / Build and Push CICD Image (push) Has been cancelled
CICD / Build CICD Image Failure Postmortem (push) Has been cancelled
CICD / Backend Tests (push) Has been cancelled
CICD / Pre-commit Checks (push) Has been cancelled
CICD / Frontend Tests (push) Has been cancelled
CICD / Backend Doctests (push) Has been cancelled
CICD / Frontend Dependency Audit (push) Has been cancelled
CICD / Backend Dependency Audit (push) Has been cancelled
CICD / CICD Tests Complete (push) Has been cancelled
CICD / Build Backend Base Image (push) Has been cancelled
CICD / Build Frontend Base Image (push) Has been cancelled
CICD / Build Integration Tester Image (push) Has been cancelled
CICD / Build E2E Tester Image (push) Has been cancelled
CICD / Build Frontend Main Image (push) Has been cancelled
CICD / Production Images Complete (push) Has been cancelled
CICD / End-to-End Tests (push) Has been cancelled
CICD / E2E Tests Failure Postmortem (push) Has been cancelled
CICD / Build Backend Main Image (push) Has been cancelled
CICD / Production Image Failures Postmortem (push) Has been cancelled
CICD / Source Lanes Failure Postmortem (push) Has been cancelled
CICD / Runtime Black-Box Integration Tests (push) Has been cancelled
CICD / Integration Tests Failure Postmortem (push) Has been cancelled
## Summary This PR integrates security-focused checks into the existing quality gates and aligns local workflows with CI/CD execution. ## What changed - Added Bandit to pre-commit backend checks. - Integrated eslint-plugin-security into the existing frontend ESLint setup used by pre-commit. - Added dedicated audit tasks: - backend audit via pip-audit - frontend audit via yarn npm audit - Updated CI/CD workflow to include and gate on frontend/backend audit jobs. - Switched backend vulnerability scanning from Safety to pip-audit to avoid interactive/auth requirements in CI. - Updated backend dependency set and lockfile to resolve test dependency conflicts and keep the environment solvable. - Marked backend integration API tests with the integration marker so marker-based unit/integration separation works consistently. ## Validation - Pre-commit hooks run and pass after formatting/autofixes. - Branch commit created successfully after hook-driven file updates. - Branch pushed to remote and tracking is configured. ## Notes - pip-audit now executes from backend context (for example via uv --directory backend run ...), matching project layout. - Remaining reported vulnerabilities depend on upstream package fix availability/constraints and may require follow-up once publishable fix versions are consumable. ## Follow-ups (optional) - Add a curated pip-audit ignore policy for non-actionable/transient advisories with rationale. - Open a focused follow-up PR for remaining dependency advisories once upstream fixes are practically installable. Co-authored-by: copilotcoder <copilotcoder@darkhelm.org> Reviewed-on: #74
110 lines
3.3 KiB
Bash
Executable File
110 lines
3.3 KiB
Bash
Executable File
#!/bin/bash
|
|
|
|
# Quick Renovate JSON Validator
|
|
# Simple validation that doesn't require Renovate installation
|
|
|
|
echo "🔍 Quick Renovate Configuration Check"
|
|
echo "====================================="
|
|
|
|
# Check if renovate.json exists
|
|
if [ ! -f "renovate.json" ]; then
|
|
echo "❌ renovate.json not found in current directory"
|
|
exit 1
|
|
fi
|
|
|
|
echo "✓ Found renovate.json"
|
|
|
|
# Validate JSON syntax with Node.js (should be available)
|
|
if command -v node &> /dev/null; then
|
|
echo ""
|
|
echo "🔧 Validating JSON syntax..."
|
|
|
|
if node -e "
|
|
try {
|
|
const config = JSON.parse(require('fs').readFileSync('renovate.json', 'utf8'));
|
|
console.log('✓ JSON syntax is valid');
|
|
console.log('✓ Configuration has', Object.keys(config).length, 'top-level properties');
|
|
|
|
// Check for required/recommended fields
|
|
if (config.extends) {
|
|
console.log('✓ Base configuration extends:', config.extends);
|
|
}
|
|
if (config.schedule) {
|
|
console.log('✓ Update schedule configured');
|
|
}
|
|
if (config.packageRules) {
|
|
console.log('✓ Package rules defined:', config.packageRules.length, 'rules');
|
|
}
|
|
|
|
} catch(e) {
|
|
console.error('❌ JSON syntax error:', e.message);
|
|
process.exit(1);
|
|
}"; then
|
|
echo "✓ JSON validation passed"
|
|
else
|
|
echo "❌ JSON validation failed"
|
|
exit 1
|
|
fi
|
|
else
|
|
echo "⚠️ Node.js not available, skipping JSON validation"
|
|
fi
|
|
|
|
# Check for supported package files
|
|
echo ""
|
|
echo "📋 Checking for supported package managers..."
|
|
|
|
PACKAGE_FILES_FOUND=0
|
|
|
|
# Python (uv/pip)
|
|
if [ -f "backend/pyproject.toml" ]; then
|
|
echo "✓ Python: backend/pyproject.toml"
|
|
PACKAGE_FILES_FOUND=$((PACKAGE_FILES_FOUND + 1))
|
|
fi
|
|
|
|
# Node.js (npm/yarn)
|
|
if [ -f "frontend/package.json" ]; then
|
|
echo "✓ Node.js: frontend/package.json"
|
|
PACKAGE_FILES_FOUND=$((PACKAGE_FILES_FOUND + 1))
|
|
|
|
# Check for yarn.lock
|
|
if [ -f "frontend/yarn.lock" ]; then
|
|
echo " └─ Yarn PnP detected (yarn.lock present)"
|
|
fi
|
|
fi
|
|
|
|
# Docker
|
|
DOCKERFILE_COUNT=$(find . -name "Dockerfile*" -type f | wc -l)
|
|
if [ $DOCKERFILE_COUNT -gt 0 ]; then
|
|
echo "✓ Docker: $DOCKERFILE_COUNT Dockerfile(s) found"
|
|
find . -name "Dockerfile*" -type f | head -3 | sed 's|^./| └─ |'
|
|
if [ $DOCKERFILE_COUNT -gt 3 ]; then
|
|
echo " └─ ... and $((DOCKERFILE_COUNT - 3)) more"
|
|
fi
|
|
PACKAGE_FILES_FOUND=$((PACKAGE_FILES_FOUND + 1))
|
|
fi
|
|
|
|
# GitHub Actions / Gitea Actions
|
|
WORKFLOW_COUNT=$(find .gitea/workflows -name "*.yml" -o -name "*.yaml" 2>/dev/null | wc -l)
|
|
if [ $WORKFLOW_COUNT -gt 0 ]; then
|
|
echo "✓ Gitea Actions: $WORKFLOW_COUNT workflow(s) found"
|
|
fi
|
|
|
|
if [ $PACKAGE_FILES_FOUND -eq 0 ]; then
|
|
echo "⚠️ No supported package files found"
|
|
echo " Renovate looks for: pyproject.toml, package.json, Dockerfile, etc."
|
|
else
|
|
echo "✓ Found $PACKAGE_FILES_FOUND package manager types to monitor"
|
|
fi
|
|
|
|
echo ""
|
|
echo "🚀 Status: Basic configuration validation complete!"
|
|
echo ""
|
|
echo "📋 Next steps:"
|
|
echo " 1. Add RENOVATE_TOKEN secret to your Gitea repository"
|
|
echo " 2. Enable .gitea/workflows/renovate.yml workflow"
|
|
echo " 3. Test with manual workflow trigger (dry-run mode)"
|
|
echo ""
|
|
echo "📚 For full validation, see: docs/RENOVATE_SETUP_GUIDE.md"
|
|
echo ""
|
|
echo "✅ Quick validation complete!"
|