Commit 537b85aba4

537b85aba4d72d3d09c2501712976ecf78cd4a76

parent: 03620cf7bd

Verified · cmc ci/build: success ci/test: success

cmc <hello@cleberg.net> · 2026-09-06 21:43 UTC

ci, wiki: run vuln and sonar nightly, not on every push

Two of the four jobs never informed a merge: sonar is report-only and
cannot fail a build, and vuln's trigger is the advisory database rather
than the code. Branches now run build and test; vuln and sonar track
main on a schedule.

Closes #177

Layout: unified · split

.gitbay/ci.yml +18 −4
@@ -22,22 +22,38 @@ jobs:
22 # build on purpose: an advisory that only lands in a report nobody reads is 22 # build on purpose: an advisory that only lands in a report nobody reads is
23 # the state this replaced. @latest matches deploy/audit.sh, so a run scans 23 # the state this replaced. @latest matches deploy/audit.sh, so a run scans
24 # against the database as it is today, not as it was at commit time. 24 # against the database as it is today, not as it was at commit time.
25 #
26 # Nightly rather than per-push, because that last sentence is the whole
27 # job: the trigger is the advisory database, not the code. An advisory
28 # published against code nobody touched was invisible until someone
29 # happened to push, while a rebase that changed nothing re-scanned it.
30 # A schedule asks the question on the cadence the answer changes.
31 # `build trigger krz/gitbay vuln` runs it on demand before a release
32 # (#177).
25 vuln: 33 vuln:
34 schedule: "0 3 * * *"
26 steps: 35 steps:
27 - go run golang.org/x/vuln/cmd/govulncheck@latest ./... 36 - go run golang.org/x/vuln/cmd/govulncheck@latest ./...
28 paths-ignore:
29 - .gitbay/wiki/**
30 # SonarCloud static analysis. Report-only: unlike vuln this does not 37 # SonarCloud static analysis. Report-only: unlike vuln this does not
31 # gate, so a first scan of an existing codebase does not turn every 38 # gate, so a first scan of an existing codebase does not turn every
32 # build red before anyone has read what it says. Flip the trailing 39 # build red before anyone has read what it says. Flip the trailing
33 # `|| true` off to make the quality gate binding. 40 # `|| true` off to make the quality gate binding.
34 # 41 #
42 # Also nightly (#177). Report-only means it cannot fail a build, so
43 # analysing every push of a branch that is about to be squashed away
44 # informs nobody, and a stack being rebased analysed the same tree four
45 # times. A scheduled job is registered by a default-branch push, so
46 # this now tracks main — which is what the per-branch handling in the
47 # step below was protecting in the first place (#154). It still works
48 # on a branch when triggered by hand.
49 #
35 # One step, because each step runs in its own `sh -c` and an export 50 # One step, because each step runs in its own `sh -c` and an export
36 # would not survive to the next. The scanner is cached under the 51 # would not survive to the next. The scanner is cached under the
37 # runner's home rather than re-downloading ~50MB per build, and the 52 # runner's home rather than re-downloading ~50MB per build, and the
38 # linux-x64 bundle carries its own JRE, which is why the host needs no 53 # linux-x64 bundle carries its own JRE, which is why the host needs no
39 # Java. 54 # Java.
40 sonar: 55 sonar:
56 schedule: "30 3 * * *"
41 steps: 57 steps:
42 - | 58 - |
43 set -eu 59 set -eu
@@ -70,5 +86,3 @@ jobs:
70 fi 86 fi
71 SONAR_HOST_URL=https://sonarcloud.io \ 87 SONAR_HOST_URL=https://sonarcloud.io \
72 "$SCANNER/bin/sonar-scanner" -Dsonar.scm.revision="${GITBAY_SHA:-}" $BRANCH_ARG || true 88 "$SCANNER/bin/sonar-scanner" -Dsonar.scm.revision="${GITBAY_SHA:-}" $BRANCH_ARG || true
73 paths-ignore:
74 - .gitbay/wiki/**
.gitbay/wiki/Admin.org +4 −1
@@ -480,7 +480,10 @@ trusts and refuses to do. Operational checklist:
480 (the module list is deliberately short — review it on each release), 480 (the module list is deliberately short — review it on each release),
481 and a short fuzz pass over every attacker-facing parser (pkt-line, 481 and a short fuzz pass over every attacker-facing parser (pkt-line,
482 commit, SSHSIG armor, OpenPGP key, SSH tokenizer). Run it before 482 commit, SSHSIG armor, OpenPGP key, SSH tokenizer). Run it before
483 tagging a release. 483 tagging a release. CI's own =vuln= job runs =govulncheck= nightly
484 against main rather than per push, because =@latest= scans today's
485 advisory database and an advisory lands without anyone pushing;
486 =build trigger krz/gitbay vuln= runs it on demand.
484- *Web responses* carry a scripts-forbidden CSP, =X-Frame-Options: 487- *Web responses* carry a scripts-forbidden CSP, =X-Frame-Options:
485 DENY=, =nosniff=, =no-referrer=, and HSTS when TLS is on — no 488 DENY=, =nosniff=, =no-referrer=, and HSTS when TLS is on — no
486 configuration needed. 489 configuration needed.