mirror of
https://github.com/GSA/notifications-api.git
synced 2026-08-22 07:16:06 -04:00
Compare commits
44 Commits
test-branc
...
06-02-2026
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2545eb980f | ||
|
|
be991afeb2 | ||
|
|
e6815ed918 | ||
|
|
9c15262b06 | ||
|
|
b988d472ae | ||
|
|
ac96886a4a | ||
|
|
32bd7af1b0 | ||
|
|
8c4a8ea43a | ||
|
|
b52ece0f84 | ||
|
|
9ccc698bb3 | ||
|
|
bf60cdf9e4 | ||
|
|
e3dabd1c1a | ||
|
|
c5b7a6e45c | ||
|
|
47b28fc9f7 | ||
|
|
620a730903 | ||
|
|
90ef879c60 | ||
|
|
7e24314397 | ||
|
|
2090127c7a | ||
|
|
3d384f78ca | ||
|
|
c171648bb1 | ||
|
|
0de64dc74a | ||
|
|
66e9ce1d39 | ||
|
|
e095649189 | ||
|
|
7a0e43f474 | ||
|
|
eab4e45450 | ||
|
|
412b36f5cf | ||
|
|
9fc9c1dcf1 | ||
|
|
11030c0a0d | ||
|
|
6ede7e5b1b | ||
|
|
a8060cec04 | ||
|
|
76df6bbabe | ||
|
|
b4196f1c5e | ||
|
|
dbfe67db31 | ||
|
|
2f7afb4d57 | ||
|
|
bdd4b67414 | ||
|
|
3d5c6be492 | ||
|
|
f85184ed62 | ||
|
|
ee922d735f | ||
|
|
af4a47dd7f | ||
|
|
268136b1b5 | ||
|
|
773460dcaf | ||
|
|
d033af8f76 | ||
|
|
776a33a9e3 | ||
|
|
931c7791ba |
10
.ds.baseline
10
.ds.baseline
@@ -133,7 +133,7 @@
|
||||
"filename": ".github/workflows/checks.yml",
|
||||
"hashed_secret": "5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8",
|
||||
"is_verified": false,
|
||||
"line_number": 28,
|
||||
"line_number": 29,
|
||||
"is_secret": false
|
||||
},
|
||||
{
|
||||
@@ -141,7 +141,7 @@
|
||||
"filename": ".github/workflows/checks.yml",
|
||||
"hashed_secret": "5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8",
|
||||
"is_verified": false,
|
||||
"line_number": 45,
|
||||
"line_number": 46,
|
||||
"is_secret": false
|
||||
}
|
||||
],
|
||||
@@ -151,7 +151,7 @@
|
||||
"filename": ".github/workflows/daily_checks.yml",
|
||||
"hashed_secret": "5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8",
|
||||
"is_verified": false,
|
||||
"line_number": 63,
|
||||
"line_number": 66,
|
||||
"is_secret": false
|
||||
},
|
||||
{
|
||||
@@ -159,7 +159,7 @@
|
||||
"filename": ".github/workflows/daily_checks.yml",
|
||||
"hashed_secret": "5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8",
|
||||
"is_verified": false,
|
||||
"line_number": 79,
|
||||
"line_number": 82,
|
||||
"is_secret": false
|
||||
}
|
||||
],
|
||||
@@ -374,5 +374,5 @@
|
||||
}
|
||||
]
|
||||
},
|
||||
"generated_at": "2025-09-11T16:22:46Z"
|
||||
"generated_at": "2026-06-02T14:59:28Z"
|
||||
}
|
||||
|
||||
4
.github/actions/setup-project/action.yml
vendored
4
.github/actions/setup-project/action.yml
vendored
@@ -10,12 +10,12 @@ runs:
|
||||
&& sudo apt-get install -y --no-install-recommends \
|
||||
libcurl4-openssl-dev
|
||||
- name: Set up Python 3.13.2
|
||||
uses: actions/setup-python@v4
|
||||
uses: actions/setup-python@v6
|
||||
with:
|
||||
python-version: "3.13.2"
|
||||
- name: Install poetry
|
||||
shell: bash
|
||||
run: pip install poetry==2.1.3
|
||||
run: pip install poetry==2.3.4
|
||||
- name: Install poetry export
|
||||
shell: bash
|
||||
run: poetry self add poetry-plugin-export
|
||||
|
||||
7
.github/dependabot.yml
vendored
7
.github/dependabot.yml
vendored
@@ -3,16 +3,19 @@
|
||||
# Please see the documentation for all configuration options:
|
||||
# https://docs.github.com/github/administering-a-repository/configuration-options-for-dependency-updates
|
||||
|
||||
# Note: Setting open-pull-requests-limit to 0 disables automatic version update PRs.
|
||||
# Security updates are still active and managed separately in repository settings under
|
||||
# "Security & analysis" > "Dependabot security updates"
|
||||
|
||||
version: 2
|
||||
updates:
|
||||
- package-ecosystem: "pip" # See documentation for possible values
|
||||
directory: "/" # Location of package manifests
|
||||
schedule:
|
||||
interval: "daily"
|
||||
open-pull-requests-limit: 0 # Disable version update PRs; security updates still active
|
||||
labels:
|
||||
- "dependabot" # Custom label to identify Dependabot PRs
|
||||
assignees:
|
||||
- "alexjanousekGSA"
|
||||
ignore:
|
||||
# gevent 25.8+ breaks Celery/Kombu compatibility (potentially)
|
||||
- dependency-name: "gevent"
|
||||
|
||||
2
.github/workflows/adr-accepted.yml
vendored
2
.github/workflows/adr-accepted.yml
vendored
@@ -19,7 +19,7 @@ jobs:
|
||||
run: exit 0
|
||||
|
||||
- name: checkout main branch
|
||||
uses: actions/checkout@v4
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
ref: main
|
||||
ssh-key: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||
|
||||
12
.github/workflows/checks.yml
vendored
12
.github/workflows/checks.yml
vendored
@@ -14,6 +14,7 @@ env:
|
||||
WERKZEUG_DEBUG_PIN: off
|
||||
REDIS_ENABLED: 0
|
||||
AWS_US_TOLL_FREE_NUMBER: "+18556438890"
|
||||
ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: true
|
||||
|
||||
jobs:
|
||||
|
||||
@@ -37,7 +38,7 @@ jobs:
|
||||
- 5432:5432
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@v6
|
||||
- uses: ./.github/actions/setup-project
|
||||
- name: Install application dependencies
|
||||
run: make bootstrap
|
||||
@@ -70,7 +71,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
environment: staging
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@v6
|
||||
- uses: ./.github/actions/setup-project
|
||||
- name: Install poetry packages
|
||||
run: poetry install
|
||||
@@ -84,7 +85,7 @@ jobs:
|
||||
pip-audit:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@v6
|
||||
- uses: ./.github/actions/setup-project
|
||||
- name: Create requirements.txt
|
||||
run: poetry export --output requirements.txt
|
||||
@@ -93,11 +94,12 @@ jobs:
|
||||
inputs: requirements.txt
|
||||
ignore-vulns: |
|
||||
PYSEC-2023-312
|
||||
CVE-2026-4539
|
||||
|
||||
static-scan:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@v6
|
||||
- uses: ./.github/actions/setup-project
|
||||
- name: Install bandit
|
||||
run: pip install bandit
|
||||
@@ -122,7 +124,7 @@ jobs:
|
||||
# Maps tcp port 5432 on service container to the host
|
||||
- 5432:5432
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@v6
|
||||
- uses: ./.github/actions/setup-project
|
||||
- name: Install application dependencies
|
||||
run: make bootstrap
|
||||
|
||||
2
.github/workflows/codeql.yml
vendored
2
.github/workflows/codeql.yml
vendored
@@ -56,7 +56,7 @@ jobs:
|
||||
# your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@v4
|
||||
uses: actions/checkout@v6
|
||||
|
||||
# Initializes the CodeQL tools for scanning.
|
||||
- name: Initialize CodeQL
|
||||
|
||||
13
.github/workflows/daily_checks.yml
vendored
13
.github/workflows/daily_checks.yml
vendored
@@ -19,11 +19,13 @@ env:
|
||||
REDIS_ENABLED: 0
|
||||
AWS_US_TOLL_FREE_NUMBER: "+18556438890"
|
||||
|
||||
|
||||
|
||||
jobs:
|
||||
pip-audit:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@v6
|
||||
- uses: ./.github/actions/setup-project
|
||||
- name: Create requirements.txt
|
||||
run: poetry export --output requirements.txt
|
||||
@@ -32,8 +34,9 @@ jobs:
|
||||
inputs: requirements.txt
|
||||
ignore-vulns: |
|
||||
PYSEC-2023-312
|
||||
CVE-2026-4539
|
||||
- name: Upload pip-audit artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
uses: actions/upload-artifact@v7
|
||||
with:
|
||||
name: pip-audit-report
|
||||
path: /tmp/pip-audit-output.txt
|
||||
@@ -41,14 +44,14 @@ jobs:
|
||||
static-scan:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@v6
|
||||
- uses: ./.github/actions/setup-project
|
||||
- name: Install bandit
|
||||
run: pip install bandit
|
||||
- name: Run scan
|
||||
run: bandit -r app/ -f txt -o /tmp/bandit-output.txt --confidence-level medium
|
||||
- name: Upload bandit artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
uses: actions/upload-artifact@v7
|
||||
with:
|
||||
name: bandit-report
|
||||
path: /tmp/bandit-output.txt
|
||||
@@ -71,7 +74,7 @@ jobs:
|
||||
# Maps tcp port 5432 on service container to the host
|
||||
- 5432:5432
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@v6
|
||||
- uses: ./.github/actions/setup-project
|
||||
- name: Install application dependencies
|
||||
run: make bootstrap
|
||||
|
||||
2
.github/workflows/deploy-demo.yml
vendored
2
.github/workflows/deploy-demo.yml
vendored
@@ -12,7 +12,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
environment: demo
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
fetch-depth: 2
|
||||
|
||||
|
||||
2
.github/workflows/deploy-prod.yml
vendored
2
.github/workflows/deploy-prod.yml
vendored
@@ -16,7 +16,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
environment: production
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
fetch-depth: 2
|
||||
|
||||
|
||||
4
.github/workflows/deploy.yml
vendored
4
.github/workflows/deploy.yml
vendored
@@ -18,7 +18,7 @@ jobs:
|
||||
|
||||
environment: staging
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
fetch-depth: 2
|
||||
|
||||
@@ -113,6 +113,6 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
if: ${{ github.event.workflow_run.conclusion == 'failure' }}
|
||||
steps:
|
||||
- uses: actions/github-script@v6
|
||||
- uses: actions/github-script@v9
|
||||
with:
|
||||
script: core.setFailed('Checks failed, not deploying')
|
||||
|
||||
6
.github/workflows/drift.yml
vendored
6
.github/workflows/drift.yml
vendored
@@ -13,7 +13,7 @@ jobs:
|
||||
environment: staging
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
uses: actions/checkout@v6
|
||||
|
||||
# Looks like we need to install Terraform ourselves now!
|
||||
# https://github.com/actions/runner-images/issues/10796#issuecomment-2417064348
|
||||
@@ -50,7 +50,7 @@ jobs:
|
||||
# environment: demo
|
||||
# steps:
|
||||
# - name: Checkout
|
||||
# uses: actions/checkout@v4
|
||||
# uses: actions/checkout@v6
|
||||
# with:
|
||||
# ref: 'production'
|
||||
|
||||
@@ -89,7 +89,7 @@ jobs:
|
||||
environment: production
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
ref: 'production'
|
||||
|
||||
|
||||
4
.github/workflows/terraform-demo.yml
vendored
4
.github/workflows/terraform-demo.yml
vendored
@@ -16,7 +16,7 @@ jobs:
|
||||
environment: demo
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
uses: actions/checkout@v6
|
||||
|
||||
# Looks like we need to install Terraform ourselves now!
|
||||
# https://github.com/actions/runner-images/issues/10796#issuecomment-2417064348
|
||||
@@ -59,7 +59,7 @@ jobs:
|
||||
|
||||
# inspiration: https://learn.hashicorp.com/tutorials/terraform/github-actions#review-actions-workflow
|
||||
- name: Update PR
|
||||
uses: actions/github-script@v7
|
||||
uses: actions/github-script@v9
|
||||
# we would like to update the PR even when a prior step failed
|
||||
if: ${{ always() }}
|
||||
with:
|
||||
|
||||
4
.github/workflows/terraform-production.yml
vendored
4
.github/workflows/terraform-production.yml
vendored
@@ -16,7 +16,7 @@ jobs:
|
||||
environment: production
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
uses: actions/checkout@v6
|
||||
|
||||
# Looks like we need to install Terraform ourselves now!
|
||||
# https://github.com/actions/runner-images/issues/10796#issuecomment-2417064348
|
||||
@@ -59,7 +59,7 @@ jobs:
|
||||
|
||||
# inspiration: https://learn.hashicorp.com/tutorials/terraform/github-actions#review-actions-workflow
|
||||
- name: Update PR
|
||||
uses: actions/github-script@v7
|
||||
uses: actions/github-script@v9
|
||||
# we would like to update the PR even when a prior step failed
|
||||
if: ${{ always() }}
|
||||
with:
|
||||
|
||||
4
.github/workflows/terraform-staging.yml
vendored
4
.github/workflows/terraform-staging.yml
vendored
@@ -16,7 +16,7 @@ jobs:
|
||||
environment: staging
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
uses: actions/checkout@v6
|
||||
|
||||
# Looks like we need to install Terraform ourselves now!
|
||||
# https://github.com/actions/runner-images/issues/10796#issuecomment-2417064348
|
||||
@@ -60,7 +60,7 @@ jobs:
|
||||
|
||||
# inspiration: https://learn.hashicorp.com/tutorials/terraform/github-actions#review-actions-workflow
|
||||
- name: Update PR
|
||||
uses: actions/github-script@v7
|
||||
uses: actions/github-script@v9
|
||||
# we would like to update the PR even when a prior step failed
|
||||
if: ${{ always() }}
|
||||
with:
|
||||
|
||||
907
poetry.lock
generated
907
poetry.lock
generated
File diff suppressed because it is too large
Load Diff
@@ -24,6 +24,7 @@ click-didyoumean = "==0.3.1"
|
||||
click-plugins = "==1.1.1.2"
|
||||
click-repl = "==0.3.0"
|
||||
deprecated = "==1.3.1"
|
||||
dulwich = "^1.2.5"
|
||||
gevent = "==25.5.1"
|
||||
expiringdict = "==1.2.2"
|
||||
flask = "~=3.1"
|
||||
@@ -34,15 +35,15 @@ flask-sqlalchemy = "^3.1.1"
|
||||
gunicorn = {version = "==25.1.0", extras = ["gevent"]}
|
||||
iso8601 = "==2.1.0"
|
||||
jsonschema = {version = "==4.26.0", extras = ["format"]}
|
||||
lxml = "==6.0.2"
|
||||
lxml = "==6.1.0"
|
||||
marshmallow = "^4.2.2"
|
||||
marshmallow-sqlalchemy = "^1.4.2"
|
||||
newrelic = "^11.5.0"
|
||||
packaging = "==26.0"
|
||||
poetry-dotenv-plugin = "==0.2.0"
|
||||
psycopg2-binary = "==2.9.11"
|
||||
pyjwt = "==2.10.1"
|
||||
python-dotenv = "==1.2.1"
|
||||
pyjwt = "==2.13.0"
|
||||
python-dotenv = "==1.2.2"
|
||||
sqlalchemy = "==2.0.47"
|
||||
werkzeug = "^3.1.5"
|
||||
faker = "^40.5.1"
|
||||
@@ -56,38 +57,39 @@ python-json-logger = "^4.0.0"
|
||||
regex = "^2026.2.19"
|
||||
shapely = "^2.1.2"
|
||||
smartypants = "^2.0.1"
|
||||
mistune = "^3.2.0"
|
||||
mistune = "^3.2.1"
|
||||
blinker = "^1.9.0"
|
||||
cryptography = "^46.0.5"
|
||||
idna = "^3.11"
|
||||
cryptography = "^46.0.7"
|
||||
idna = "^3.15"
|
||||
jmespath = "^1.1.0"
|
||||
markupsafe = "^3.0.3"
|
||||
mako = "^1.3.12"
|
||||
pycparser = "^3.0"
|
||||
python-dateutil = "^2.9.0.post0"
|
||||
pyyaml = "^6.0.3"
|
||||
s3transfer = "^0.13.1"
|
||||
s3transfer = "^0.16.0"
|
||||
six = "^1.16.0"
|
||||
urllib3 = "^2.6.3"
|
||||
webencodings = "^0.5.1"
|
||||
itsdangerous = "^2.2.0"
|
||||
jinja2 = "^3.1.6"
|
||||
redis = "^6.4.0"
|
||||
requests = "^2.32.5"
|
||||
virtualenv = "^21.0.0"
|
||||
requests = "^2.33.0"
|
||||
virtualenv = "^21.1.0"
|
||||
marshmallow-enum = "^1.5.1"
|
||||
awscli = "^1.40.36"
|
||||
awscli = "^1.44.38"
|
||||
typing-extensions = "^4.15.0"
|
||||
aiohttp = "^3.13.3"
|
||||
aiohttp = "^3.13.4"
|
||||
pytest = "^9.0.2"
|
||||
filelock = ">=3.20.3"
|
||||
pyasn1 = ">=0.6.2"
|
||||
pyasn1 = ">=0.6.3"
|
||||
jaraco-context = ">=6.1.0"
|
||||
wheel = ">=0.46.2"
|
||||
|
||||
|
||||
[tool.poetry.group.dev.dependencies]
|
||||
bandit = "*"
|
||||
black = "^26.1.0"
|
||||
black = "^26.3.1"
|
||||
cyclonedx-python-lib = "^11.6.0"
|
||||
cloudfoundry-client = "*"
|
||||
exceptiongroup = "==1.3.1"
|
||||
|
||||
@@ -238,12 +238,11 @@ def test_decode_jwt_token_returns_error_with_no_secrets(client):
|
||||
assert exc.value.short_message == "Invalid token: API key not found"
|
||||
|
||||
|
||||
@pytest.mark.parametrize("service_id", ["not-a-valid-id", 1234])
|
||||
def test_requires_auth_should_not_allow_service_id_with_the_wrong_data_type(
|
||||
client, service_jwt_secret, service_id
|
||||
client, service_jwt_secret
|
||||
):
|
||||
token = create_jwt_token(
|
||||
client_id=service_id,
|
||||
client_id="not-a-valid-id",
|
||||
secret=service_jwt_secret,
|
||||
)
|
||||
|
||||
@@ -256,6 +255,16 @@ def test_requires_auth_should_not_allow_service_id_with_the_wrong_data_type(
|
||||
)
|
||||
|
||||
|
||||
def test_requires_auth_should_not_allow_service_id_with_a_non_string(
|
||||
client, service_jwt_secret
|
||||
):
|
||||
with pytest.raises(TypeError):
|
||||
create_jwt_token(
|
||||
client_id=1234,
|
||||
secret=service_jwt_secret,
|
||||
)
|
||||
|
||||
|
||||
def test_requires_auth_returns_error_when_service_doesnt_exist(client, sample_api_key):
|
||||
# get service ID and secret the wrong way around
|
||||
token = create_jwt_token(
|
||||
|
||||
Reference in New Issue
Block a user