Commit Graph

9047 Commits

Author SHA1 Message Date
Ryan Ahearn
f90f32f032 Document how to run the owasp scan locally 2022-08-23 16:59:39 -04:00
Ryan Ahearn
2550464b8f Run scans every day 2022-08-23 16:44:34 -04:00
Ryan Ahearn
2df4b42da2 Use api-scan owasp action 2022-08-19 12:23:05 -04:00
Ryan Ahearn
fb188395a9 First cut at running OWASP in github actions 2022-08-19 12:12:58 -04:00
Ryan Ahearn
806e2ad2dc Review and update uses of PRNG 2022-08-19 15:26:12 +00:00
Ryan Ahearn
3c035531aa Clean up and validate low static-scan findings 2022-08-19 14:32:11 +00:00
Ryan Ahearn
53f2519c2a Verify potential sql-injection findings are false positives 2022-08-18 19:07:54 +00:00
Ryan Ahearn
e77cedb039 Clean up xml finding from static-scan 2022-08-18 17:52:44 +00:00
Ryan Ahearn
fb1e6b3e9d Implement bandit static security scan 2022-08-12 17:19:28 -04:00
Ryan Ahearn
6e96ffdc09 Create shared project setup action 2022-08-12 16:34:15 -04:00
Ryan Ahearn
ebc0083330 Add pip-audit github check 2022-08-12 15:22:01 -04:00
Ryan Ahearn
51a9207069 Ignore vuln on mistune included via notifications-utils 2022-08-12 15:22:01 -04:00
Ryan Ahearn
a6669501cc Upgrade pip packages 2022-08-12 15:22:01 -04:00
Ryan Ahearn
2597011cee make audit for python dependency audits 2022-08-12 15:36:48 +00:00
Ben Klaas
55bc3e54ed Merge pull request #23 from 18F/jim/080522/sampleenv
sample env
2022-08-09 09:47:40 -05:00
Jim Moffet
a3002c89db Merge pull request #22 from 18F/devdocs_update
Devdocs update
2022-08-05 09:16:56 -07:00
jimmoffet
9f8ed4e3fc sample env 2022-08-05 09:14:58 -07:00
Ben Klaas
b32585d20d Remove old QUICKSTART 2022-08-05 02:34:29 +00:00
Ben Klaas
9f21018d8e Update QUICKSTART 2022-08-05 02:22:21 +00:00
Jim Moffet
03679453a0 Merge pull request #16 from 18F/ch/run-tests-on-ci
Run tests and deploy from CI
2022-08-02 17:58:25 -07:00
Jim Moffet
ff5dd69ce3 Merge pull request #21 from 18F/jim/run-tests-on-ci
workflow env
2022-08-02 17:23:23 -07:00
jimmoffet
6d0fd97b3e skip two failing redis tests 2022-08-02 16:55:21 -07:00
jimmoffet
ed8b7fe724 temporarily disable redis for tests 2022-08-02 16:26:37 -07:00
jimmoffet
f02ee79d0b workflow env 2022-08-02 16:06:12 -07:00
Jim Moffet
b860f9e55a Merge branch 'main' into ch/run-tests-on-ci 2022-08-02 15:29:21 -07:00
jimmoffet
c3d4268acc sample.env update 2022-08-01 12:23:14 -07:00
Jim Moffet
1bbb8a4aab Update README 2022-08-01 10:56:16 -07:00
Jim Moffet
1fbc4d6241 Update README 2022-08-01 10:53:27 -07:00
Jim Moffet
f7060af2ff Update README 2022-08-01 10:50:50 -07:00
Jim Moffet
5ace04bd96 Merge pull request #20 from 18F/jim/071422/updatereadme
update readme with SES/SNS instructions
2022-07-25 15:23:06 -07:00
James Moffet
18a04fd719 configs 2022-07-25 15:19:05 -07:00
James Moffet
f0cb133129 update readme with SES/SNS instructions 2022-07-14 13:36:05 -05:00
Christa Hartsock
efe73fac2e Only run deploy on main branch if tests pass 2022-07-07 17:09:37 -07:00
Christa Hartsock
db9fc27320 Run tests on CI push, gate deploy on them 2022-07-07 16:59:37 -07:00
Christa Hartsock
6a7e5aa776 Use full_command in CI script rather than passing args 2022-07-07 16:52:06 -07:00
Christa Hartsock
e0b74511e8 Remove logging from startup script 2022-07-07 16:49:44 -07:00
Christa Hartsock
c341fd4c99 Log the PIDs from run function 2022-07-07 16:40:39 -07:00
Christa Hartsock
1e294eb8c4 Remove startup script logging 2022-07-07 16:27:11 -07:00
Christa Hartsock
64b30feb08 Remove pytest from non-test file 2022-07-07 16:22:21 -07:00
Christa Hartsock
0f062354aa Try to read gunicorn log 2022-07-07 16:18:04 -07:00
Christa Hartsock
9204290455 Quote variables in CI script 2022-07-07 15:58:21 -07:00
Christa Hartsock
a7f5d0c49f Remove unused Github Actions config 2022-07-07 15:41:16 -07:00
Christa Hartsock
0318c8d619 Use the 18f cg-deploy github action 2022-07-07 15:41:16 -07:00
Christa Hartsock
29e7e8cc31 Log into cloud.gov before trying to deploy 2022-07-07 15:41:16 -07:00
Christa Hartsock
bf4b944c17 Attempt deploy from branch 2022-07-07 15:41:16 -07:00
Christa Hartsock
c4cdaed683 Skip tests that fail because of timezone handling 2022-07-07 15:41:16 -07:00
Christa Hartsock
0a0efb1503 Deploy from CI when tests pass 2022-07-07 15:41:16 -07:00
Christa Hartsock
041a892e86 Pull admin base url from test config in tests 2022-07-07 15:41:16 -07:00
Christa Hartsock
2e6f622ace Do not care about admin base url in test 2022-07-07 15:41:16 -07:00
Christa Hartsock
2b995f6982 Update CI postgres hostname for tests 2022-07-07 15:41:16 -07:00