Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 28 additions & 0 deletions .github/actions/install-convox/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
name: Install Convox CLI
description: Install a pinned, checksum-verified Convox CLI (linux amd64) into /usr/local/bin.

inputs:
version:
description: Convox CLI release version
default: "3.25.7"
sha256:
description: SHA-256 of the convox-linux asset for that version
default: 6a0ffe6faf269302c311c2f8e4d1cdc116902c933c7d91f461c47d8a25190759

runs:
using: composite
steps:
- name: Install Convox CLI
shell: bash
env:
CONVOX_VERSION: ${{ inputs.version }}
CONVOX_SHA256: ${{ inputs.sha256 }}
run: |
set -euo pipefail
tmp="$(mktemp -d)"
curl -fsSL -o "${tmp}/convox" \
"https://github.com/convox/convox/releases/download/${CONVOX_VERSION}/convox-linux"
echo "${CONVOX_SHA256} ${tmp}/convox" | sha256sum --check --strict
sudo install -m 0755 "${tmp}/convox" /usr/local/bin/convox
rm -rf "${tmp}"
convox version || true
29 changes: 29 additions & 0 deletions .github/actions/install-task/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
name: Install Task
description: Install a pinned, checksum-verified Task (taskfile.dev) binary into /usr/local/bin.

inputs:
version:
description: Task release version
default: "3.53.1"
sha256:
description: SHA-256 of task_linux_amd64.tar.gz for that version (from task_checksums.txt)
default: a54a408f6861ff921f6e87774180db31bacd8c1e7c944ca696db9fea49a82fc7

runs:
using: composite
steps:
- name: Install Task
shell: bash
env:
TASK_VERSION: ${{ inputs.version }}
TASK_SHA256: ${{ inputs.sha256 }}
run: |
set -euo pipefail
tmp="$(mktemp -d)"
curl -fsSL -o "${tmp}/task.tar.gz" \
"https://github.com/go-task/task/releases/download/v${TASK_VERSION}/task_linux_amd64.tar.gz"
echo "${TASK_SHA256} ${tmp}/task.tar.gz" | sha256sum --check --strict
tar -xzf "${tmp}/task.tar.gz" -C "${tmp}" task
sudo install -m 0755 "${tmp}/task" /usr/local/bin/task
rm -rf "${tmp}"
task --version
43 changes: 43 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
version: 2

updates:
- package-ecosystem: gomod
directory: /
schedule:
interval: weekly
ignore:
# Replaced by the local modules in internal/shims (see go.mod replace directives)
- dependency-name: github.com/docker/docker
- dependency-name: github.com/moby/buildkit
groups:
go-minor-patch:
update-types: [minor, patch]

- package-ecosystem: bun
directories:
- /web
- /docs
- /mock-oauth
schedule:
interval: weekly
groups:
bun-minor-patch:
update-types: [minor, patch]

- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
groups:
actions-minor-patch:
update-types: [minor, patch]

- package-ecosystem: docker
directories:
- /
- /mock-oauth
schedule:
interval: weekly
groups:
docker-minor-patch:
update-types: [minor, patch]
79 changes: 34 additions & 45 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,9 @@ on:
pull_request:
branches: [main]

permissions:
contents: read

jobs:
go-tests:
runs-on: ubuntu-latest
Expand All @@ -14,10 +17,10 @@ jobs:
TEST_DATABASE_URL: postgres://postgres:postgres@localhost:55432/gateway_test?sslmode=disable
GOLANGCI_LINT_VERSION: v2.11.1
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0

- name: Setup Go
uses: actions/setup-go@v5
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
with:
go-version: "1.26.9"

Expand All @@ -27,25 +30,13 @@ jobs:
sudo apt-get install -y libfido2-dev libudev-dev pkg-config

- name: Install Task
run: |
curl -sL https://taskfile.dev/install.sh | sh -s -- -b /usr/local/bin
task --version
uses: ./.github/actions/install-task

- name: Go deps
run: task go:deps

- name: Install Convox CLI
run: |
set -euo pipefail
ARCH=$(uname -m)
URL="https://github.com/convox/convox/releases/latest/download/convox-linux"
if [ "$ARCH" = "aarch64" ] || [ "$ARCH" = "arm64" ]; then
URL="https://github.com/convox/convox/releases/latest/download/convox-linux-arm64"
fi
curl -fsSL "$URL" -o /tmp/convox
sudo mv /tmp/convox /usr/local/bin/convox
sudo chmod 755 /usr/local/bin/convox
convox version || true
uses: ./.github/actions/install-convox

- name: Install Go tools
run: task go:tools
Expand All @@ -58,15 +49,15 @@ jobs:
env:
GOLANGCI_LINT_VERSION: v2.11.1
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0

- name: Setup Go
uses: actions/setup-go@v5
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
with:
go-version: "1.26.9"

- name: Cache golangci-lint cache
uses: actions/cache@v4
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
with:
path: |
~/.cache/golangci-lint
Expand All @@ -78,24 +69,15 @@ jobs:
sudo apt-get install -y libfido2-dev libudev-dev pkg-config

- name: Install Task
run: |
curl -sL https://taskfile.dev/install.sh | sh -s -- -b /usr/local/bin
task --version

- name: Install golangci-lint
run: |
curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh \
| sudo sh -s -- -b /usr/local/bin "${GOLANGCI_LINT_VERSION}"
golangci-lint version
uses: ./.github/actions/install-task

- name: Go deps (lint warmup)
run: task go:deps

- name: Verify golangci-lint config
run: task go:lint:config

# The action installs the pinned golangci-lint release and verifies .golangci.yml
# against its JSON schema (verify: true) before linting.
- name: golangci-lint
uses: golangci/golangci-lint-action@v8
uses: golangci/golangci-lint-action@4afd733a84b1f43292c63897423277bb7f4313a9 # v8.0.0
with:
version: ${{ env.GOLANGCI_LINT_VERSION }}
env:
Expand All @@ -121,30 +103,41 @@ jobs:
run: task shellcheck

- name: Install govulncheck
run: go install golang.org/x/vuln/cmd/govulncheck@latest
run: go install golang.org/x/vuln/cmd/govulncheck@v1.8.0

- name: Check for vulnerabilities
run: task go:sec:vuln

- name: Install TruffleHog
env:
TRUFFLEHOG_VERSION: "3.97.9"
TRUFFLEHOG_SHA256: 40377e6572495412fb9ba0bc21c9401f73b72f1d2afd11b9931bc4a5ed622866
run: |
curl -sSfL https://raw.githubusercontent.com/trufflesecurity/trufflehog/main/scripts/install.sh | sh -s -- -b /usr/local/bin
set -euo pipefail
tmp="$(mktemp -d)"
curl -fsSL -o "${tmp}/trufflehog.tar.gz" \
"https://github.com/trufflesecurity/trufflehog/releases/download/v${TRUFFLEHOG_VERSION}/trufflehog_${TRUFFLEHOG_VERSION}_linux_amd64.tar.gz"
echo "${TRUFFLEHOG_SHA256} ${tmp}/trufflehog.tar.gz" | sha256sum --check --strict
tar -xzf "${tmp}/trufflehog.tar.gz" -C "${tmp}" trufflehog
sudo install -m 0755 "${tmp}/trufflehog" /usr/local/bin/trufflehog
rm -rf "${tmp}"
trufflehog --version

- name: Scan for secrets
run: task go:sec:secrets

web-tests:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0

- name: Setup Node
uses: actions/setup-node@v4
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: "20"

- name: Setup Bun
uses: oven-sh/setup-bun@v2
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version: "1.3.1"

Expand All @@ -154,9 +147,7 @@ jobs:
bun install --frozen-lockfile

- name: Install Task
run: |
curl -sL https://taskfile.dev/install.sh | sh -s -- -b /usr/local/bin
task --version
uses: ./.github/actions/install-task

- name: Web lint (Typecheck, Biome, and knip)
run: task web:lint
Expand All @@ -170,17 +161,15 @@ jobs:
mock-oauth-tests:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0

- name: Setup Bun
uses: oven-sh/setup-bun@v2
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version: "1.3.1"

- name: Install Task
run: |
curl -sL https://taskfile.dev/install.sh | sh -s -- -b /usr/local/bin
task --version
uses: ./.github/actions/install-task

- name: Mock OAuth lint (Typecheck and Biome)
run: task mock-oauth:lint
Expand Down
21 changes: 12 additions & 9 deletions .github/workflows/docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,11 +6,8 @@ on:
paths: ["docs/**"]
workflow_dispatch:

# Sets permissions of the GITHUB_TOKEN to allow deployment to GitHub Pages
permissions:
contents: read
pages: write
id-token: write

# Allow only one concurrent deployment, skipping runs queued between the run in-progress and latest queued.
# However, do NOT cancel in-progress runs as we want to allow these production deployments to complete.
Expand All @@ -23,32 +20,38 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0

- name: Setup Bun
uses: oven-sh/setup-bun@v2
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version: "1.3.1"

- name: Install dependencies
run: cd docs && bun install
run: cd docs && bun install --frozen-lockfile

- name: Build docs
run: cd docs && bun run build

- name: Setup Pages
uses: actions/configure-pages@v5
uses: actions/configure-pages@983d7736d9b0ae728b81ab479565c72886d7745b # v5.0.0

- name: Upload artifact
uses: actions/upload-pages-artifact@v3
uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3.0.1
with:
path: docs/dist

deploy:
needs: build
runs-on: ubuntu-latest
# Only the deploy job may publish to GitHub Pages
permissions:
pages: write
id-token: write
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
steps:
- name: Deploy to GitHub Pages
id: deployment
uses: actions/deploy-pages@v4
uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4.0.5
Loading
Loading