diff --git a/.github/workflows/backup.yml b/.github/workflows/backup.yml index d8284b33..acdf4153 100644 --- a/.github/workflows/backup.yml +++ b/.github/workflows/backup.yml @@ -104,8 +104,10 @@ jobs: - name: Notify on failure if: failure() - uses: slackapi/slack-github-action@v1.24.0 + uses: slackapi/slack-github-action@v2.1.0 with: + webhook: ${{ secrets.SLACK_WEBHOOK_URL }} + webhook-type: incoming-webhook payload: | { "attachments": [{ @@ -113,5 +115,3 @@ jobs: "text": "❌ Database backup workflow failed for ${{ github.repository }}" }] } - env: - SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }} diff --git a/.github/workflows/canary.yml b/.github/workflows/canary.yml index 14d41058..c6767696 100644 --- a/.github/workflows/canary.yml +++ b/.github/workflows/canary.yml @@ -42,6 +42,7 @@ jobs: rollback: name: Auto-Rollback + needs: [canary-10, canary-50, production-rollout] if: failure() runs-on: ubuntu-latest steps: diff --git a/.github/workflows/coverage.yml b/.github/workflows/coverage.yml index 6ecf0383..a9235d03 100644 --- a/.github/workflows/coverage.yml +++ b/.github/workflows/coverage.yml @@ -23,6 +23,7 @@ jobs: with: node-version: '20' cache: 'npm' + cache-dependency-path: frontend/package-lock.json - name: Install dependencies run: npm ci @@ -36,6 +37,6 @@ jobs: uses: codecov/codecov-action@v4 with: token: ${{ secrets.CODECOV_TOKEN }} - directory: frontend/coverage + directory: coverage flags: frontend fail_ci_if_error: false diff --git a/.github/workflows/fuzz-testing.yml b/.github/workflows/fuzz-testing.yml index fdf5a746..a9d3f22a 100644 --- a/.github/workflows/fuzz-testing.yml +++ b/.github/workflows/fuzz-testing.yml @@ -133,7 +133,7 @@ jobs: - name: Install Rust uses: dtolnay/rust-toolchain@stable with: - components: rustfmt, clippy, llvm-tools-preview + components: rustfmt, clippy, llvm-tools - name: Install grcov run: cargo install grcov @@ -156,7 +156,7 @@ jobs: --output-path coverage.lcov - name: Upload Coverage to Codecov - uses: codecov/codecov-action@v5 + uses: codecov/codecov-action@v4 with: file: contracts/coverage.lcov flags: fuzz-testing diff --git a/.github/workflows/performance-monitoring.yml b/.github/workflows/performance-monitoring.yml index 6ffc07db..6b2d74fa 100644 --- a/.github/workflows/performance-monitoring.yml +++ b/.github/workflows/performance-monitoring.yml @@ -28,15 +28,16 @@ jobs: - name: Build bundle run: npm run build + working-directory: frontend env: NODE_ENV: production ANALYZE: 'false' + NEXT_TELEMETRY_DISABLED: '1' - name: Check bundle size run: | BUNDLE_SIZE=$(du -sb frontend/.next/static | awk '{print $1}') - BUNDLE_SIZE_MB=$(echo "scale=2; $BUNDLE_SIZE / 1048576" | bc) - MAX_SIZE_MB=5.0 + BUNDLE_SIZE_MB=$(echo "scale=2; $BUNDLE_SIZE / 1048576" | bc) MAX_SIZE_MB=5.0 echo "Bundle Size: ${BUNDLE_SIZE_MB}MB" @@ -49,7 +50,7 @@ jobs: - name: Analyze bundle with lighthouse run: | - npm install -g @lhci/cli@0.11.x + npm install -g @lhci/cli@0.14.x lhci autorun --config=./lighthouse/lighthouse.config.json || true continue-on-error: true diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 5b03fdb6..e4e1f407 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -30,6 +30,8 @@ jobs: - uses: actions/setup-node@v4 with: node-version: ${{ env.NODE_VERSION }} + cache: 'npm' + cache-dependency-path: package-lock.json - run: npm ci diff --git a/.github/workflows/sdk-generation.yml b/.github/workflows/sdk-generation.yml index 44a16884..60a011b0 100644 --- a/.github/workflows/sdk-generation.yml +++ b/.github/workflows/sdk-generation.yml @@ -86,7 +86,7 @@ jobs: path: backend/docs/api/openapi/ - name: Install oasdiff - run: npm install -g @openapi-diff/openapi-diff + run: npm install -g @oasdiff/oasdiff - name: Fetch previous OpenAPI spec run: | diff --git a/.github/workflows/security-audit-pipeline.yml b/.github/workflows/security-audit-pipeline.yml index b9ec13e4..e5a6e949 100644 --- a/.github/workflows/security-audit-pipeline.yml +++ b/.github/workflows/security-audit-pipeline.yml @@ -234,11 +234,6 @@ jobs: if: >- ${{ (github.event_name == 'push' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') && (github.event.inputs.scan_type == 'all' || github.event.inputs.scan_type == 'dast' || github.event_name != 'workflow_dispatch') }} - services: - backend: - image: node:20-alpine - ports: - - 3001:3001 steps: - name: Checkout uses: actions/checkout@v4 diff --git a/.github/workflows/security-audit.yml b/.github/workflows/security-audit.yml index 00f0b455..55fa3300 100644 --- a/.github/workflows/security-audit.yml +++ b/.github/workflows/security-audit.yml @@ -71,34 +71,37 @@ jobs: --exclude-low \ --solc-remaps "" || true - # Convert to human-readable format + # Generate a human-readable Markdown checklist slither . \ --exclude-dependencies \ --exclude-low \ - --risk high,medium \ - --output-to-file {severity}-{type}-slither-report.md + --checklist \ + --markdown-root . \ + 2>&1 > slither-checklist.md || true - name: Parse Slither Results id: parse_slither working-directory: contracts run: | - if [ -f "HIGH-high-slither-report.md" ]; then - echo "slither_high_findings=true" >> $GITHUB_OUTPUT - echo "## 🔴 Slither: Critical Findings Found" >> $GITHUB_STEP_SUMMARY - cat HIGH-high-slither-report.md >> $GITHUB_STEP_SUMMARY - fi + if [ -f "slither-checklist.md" ]; then + # Check for high severity in the checklist output + if grep -qi "high" slither-checklist.md; then + echo "slither_high_findings=true" >> $GITHUB_OUTPUT + echo "## 🔴 Slither: Critical Findings Found" >> $GITHUB_STEP_SUMMARY + cat slither-checklist.md >> $GITHUB_STEP_SUMMARY + fi - if [ -f "MEDIUM-medium-slither-report.md" ]; then - echo "slither_medium_findings=true" >> $GITHUB_OUTPUT - echo "## 🟠 Slither: Medium-Risk Findings" >> $GITHUB_STEP_SUMMARY - cat MEDIUM-medium-slither-report.md >> $GITHUB_STEP_SUMMARY + if grep -qi "medium" slither-checklist.md; then + echo "slither_medium_findings=true" >> $GITHUB_OUTPUT + echo "## 🟠 Slither: Medium-Risk Findings" >> $GITHUB_STEP_SUMMARY + fi fi - name: Move Slither reports if: always() working-directory: contracts run: | - mv -f *slither-report.md ${{ github.workspace }}/${{ env.SECURITY_REPORT_DIR }}/ || true + mv -f slither-checklist.md ${{ github.workspace }}/${{ env.SECURITY_REPORT_DIR }}/slither-checklist.md || true mv -f ${{ runner.temp }}/slither-report.json ${{ github.workspace }}/${{ env.SECURITY_REPORT_DIR }}/ || true - name: Upload Slither Artifacts @@ -170,7 +173,8 @@ jobs: for file in mythril-*.json; do if [ -f "$file" ]; then # Count issues by severity - CRITICAL=$((CRITICAL + $(jq '[.issues[] | select(.severity=="High")] | length' "$file" 2>/dev/null || echo 0))) + FILE_CRITICAL=$(jq '[.issues[] | select(.severity=="High")] | length' "$file" 2>/dev/null || echo 0) + CRITICAL_COUNT=$((CRITICAL_COUNT + FILE_CRITICAL)) fi done