Two things, both about not finding out late. No workflow declared `permissions`, so all eighteen jobs across the four workflows ran on a token with the default full repository scope. Every one of them only checks out code, and deploy reaches the cluster over SSH with the deploy key, and Renovate writes through its own bot PAT rather than the Actions token. So `contents: read` is all any of them needed. The panel image ships 15 known advisories and nothing was looking. Add a scan-deps job that fails on anything new, and record the eight current ones by ID in the workflow. It is a list rather than a baseline count so that the diff that accepts an advisory says so in words, and it lives in our workflow instead of the package manifest so a subtree sync from forust/userbot cannot quietly widen the exemption. Both halves were checked to fail on a regression, not just to pass today: removing one --ignore-vuln turns the Python step red, and dropping --audit-level to moderate turns the npm one red on the devalue advisory. npm audits production dependencies only. All seven findings in the full tree are build- or test-time: the esbuild advisory needs a vite dev server exposed to the internet, and nanoid's infinite loop needs a custom generator called with size 0, which postcss does not do. None are in the 91 kB bundle the panel serves, so failing on them would be noise that trains people to ignore the job. The starlette entries are the reason the job is not "fail on everything": fastapi 0.115.12 pins starlette<0.47.0 and the last four fixes need 0.49.1 through 1.3.1, so clearing them is a jump to fastapi 0.141.x and is upstream's call, not a drive-by. Four of the seven are reachable in principle, which the comment on the job sets out. The panel answers only on userbot.workstation.internal with no public route, which is what keeps those four from being an internet-facing DoS. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
77 lines
2.5 KiB
YAML
77 lines
2.5 KiB
YAML
name: renovate-ci
|
|
|
|
on:
|
|
pull_request:
|
|
push:
|
|
branches:
|
|
- main
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
validate-renovate:
|
|
runs-on: [self-hosted, linux, arch, homelab]
|
|
timeout-minutes: 20
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
|
|
|
# renovate/k8s/cronjob.yaml is the single source of truth for the image tag,
|
|
# so the same version that runs in the cluster is the one validated here.
|
|
- name: Resolve the deployed Renovate image
|
|
id: image
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
image="$(sed -n 's|.*image:[[:space:]]*\(renovate/renovate:[^[:space:]]*\).*|\1|p' \
|
|
renovate/k8s/cronjob.yaml | head -1)"
|
|
if [ -z "$image" ]; then
|
|
echo "::error::no renovate/renovate image found in renovate/k8s/cronjob.yaml"
|
|
exit 1
|
|
fi
|
|
echo "using $image"
|
|
echo "image=$image" >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Validate Renovate repository config
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
docker run --rm \
|
|
-v "$PWD/renovate:/opt/renovate:ro" \
|
|
-e RENOVATE_CONFIG_FILE=/opt/renovate/renovate.json \
|
|
"${{ steps.image.outputs.image }}" \
|
|
renovate-config-validator /opt/renovate/renovate.json
|
|
|
|
# The CronJob cannot read the repository, so renovate/k8s/configmap.yaml
|
|
# carries an inlined copy of the config. Fail if it no longer matches.
|
|
- name: Check the generated Renovate ConfigMap
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
./.gitea/workflows/sync-renovate-configmap.sh --check
|
|
|
|
- name: Validate Renovate Kubernetes manifests
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh kubeconform)"
|
|
export PATH="$tools_dir:$PATH"
|
|
kubeconform \
|
|
-strict \
|
|
-ignore-missing-schemas \
|
|
-summary \
|
|
renovate/k8s/namespace.yaml \
|
|
renovate/k8s/configmap.yaml \
|
|
renovate/k8s/cronjob.yaml
|
|
|
|
- name: Validate Renovate Compose file
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
source .gitea/workflows/compose-lint.sh
|
|
mapfile -t safe_flags < <(compose_safe_flags)
|
|
validate_compose_file renovate/renovate-compose.yaml \
|
|
${safe_flags[@]+"${safe_flags[@]}"}
|