Commit 537b85aba4
Verified · cmc ci/build: success ci/test: success
Layout: unified · split
.gitbay/ci.yml +18 −4
| @@ -22,22 +22,38 @@ jobs: | |||
| 22 | # build on purpose: an advisory that only lands in a report nobody reads is | 22 | # build on purpose: an advisory that only lands in a report nobody reads is |
| 23 | # the state this replaced. @latest matches deploy/audit.sh, so a run scans | 23 | # the state this replaced. @latest matches deploy/audit.sh, so a run scans |
| 24 | # against the database as it is today, not as it was at commit time. | 24 | # against the database as it is today, not as it was at commit time. |
| 25 | # | ||
| 26 | # Nightly rather than per-push, because that last sentence is the whole | ||
| 27 | # job: the trigger is the advisory database, not the code. An advisory | ||
| 28 | # published against code nobody touched was invisible until someone | ||
| 29 | # happened to push, while a rebase that changed nothing re-scanned it. | ||
| 30 | # A schedule asks the question on the cadence the answer changes. | ||
| 31 | # `build trigger krz/gitbay vuln` runs it on demand before a release | ||
| 32 | # (#177). | ||
| 25 | vuln: | 33 | vuln: |
| 34 | schedule: "0 3 * * *" | ||
| 26 | steps: | 35 | steps: |
| 27 | - go run golang.org/x/vuln/cmd/govulncheck@latest ./... | 36 | - go run golang.org/x/vuln/cmd/govulncheck@latest ./... |
| 28 | paths-ignore: | ||
| 29 | - .gitbay/wiki/** | ||
| 30 | # SonarCloud static analysis. Report-only: unlike vuln this does not | 37 | # SonarCloud static analysis. Report-only: unlike vuln this does not |
| 31 | # gate, so a first scan of an existing codebase does not turn every | 38 | # gate, so a first scan of an existing codebase does not turn every |
| 32 | # build red before anyone has read what it says. Flip the trailing | 39 | # build red before anyone has read what it says. Flip the trailing |
| 33 | # `|| true` off to make the quality gate binding. | 40 | # `|| true` off to make the quality gate binding. |
| 34 | # | 41 | # |
| 42 | # Also nightly (#177). Report-only means it cannot fail a build, so | ||
| 43 | # analysing every push of a branch that is about to be squashed away | ||
| 44 | # informs nobody, and a stack being rebased analysed the same tree four | ||
| 45 | # times. A scheduled job is registered by a default-branch push, so | ||
| 46 | # this now tracks main — which is what the per-branch handling in the | ||
| 47 | # step below was protecting in the first place (#154). It still works | ||
| 48 | # on a branch when triggered by hand. | ||
| 49 | # | ||
| 35 | # One step, because each step runs in its own `sh -c` and an export | 50 | # One step, because each step runs in its own `sh -c` and an export |
| 36 | # would not survive to the next. The scanner is cached under the | 51 | # would not survive to the next. The scanner is cached under the |
| 37 | # runner's home rather than re-downloading ~50MB per build, and the | 52 | # runner's home rather than re-downloading ~50MB per build, and the |
| 38 | # linux-x64 bundle carries its own JRE, which is why the host needs no | 53 | # linux-x64 bundle carries its own JRE, which is why the host needs no |
| 39 | # Java. | 54 | # Java. |
| 40 | sonar: | 55 | sonar: |
| 56 | schedule: "30 3 * * *" | ||
| 41 | steps: | 57 | steps: |
| 42 | - | | 58 | - | |
| 43 | set -eu | 59 | set -eu |
| @@ -70,5 +86,3 @@ jobs: | |||
| 70 | fi | 86 | fi |
| 71 | SONAR_HOST_URL=https://sonarcloud.io \ | 87 | SONAR_HOST_URL=https://sonarcloud.io \ |
| 72 | "$SCANNER/bin/sonar-scanner" -Dsonar.scm.revision="${GITBAY_SHA:-}" $BRANCH_ARG || true | 88 | "$SCANNER/bin/sonar-scanner" -Dsonar.scm.revision="${GITBAY_SHA:-}" $BRANCH_ARG || true |
| 73 | paths-ignore: | ||
| 74 | - .gitbay/wiki/** | ||
.gitbay/wiki/Admin.org +4 −1
| @@ -480,7 +480,10 @@ trusts and refuses to do. Operational checklist: | |||
| 480 | (the module list is deliberately short — review it on each release), | 480 | (the module list is deliberately short — review it on each release), |
| 481 | and a short fuzz pass over every attacker-facing parser (pkt-line, | 481 | and a short fuzz pass over every attacker-facing parser (pkt-line, |
| 482 | commit, SSHSIG armor, OpenPGP key, SSH tokenizer). Run it before | 482 | commit, SSHSIG armor, OpenPGP key, SSH tokenizer). Run it before |
| 483 | tagging a release. | 483 | tagging a release. CI's own =vuln= job runs =govulncheck= nightly |
| 484 | against main rather than per push, because =@latest= scans today's | ||
| 485 | advisory database and an advisory lands without anyone pushing; | ||
| 486 | =build trigger krz/gitbay vuln= runs it on demand. | ||
| 484 | - *Web responses* carry a scripts-forbidden CSP, =X-Frame-Options: | 487 | - *Web responses* carry a scripts-forbidden CSP, =X-Frame-Options: |
| 485 | DENY=, =nosniff=, =no-referrer=, and HSTS when TLS is on — no | 488 | DENY=, =nosniff=, =no-referrer=, and HSTS when TLS is on — no |
| 486 | configuration needed. | 489 | configuration needed. |