Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions .github/workflows/backup.yml
Original file line number Diff line number Diff line change
Expand Up @@ -104,14 +104,14 @@ jobs:

- name: Notify on failure
if: failure()
uses: slackapi/slack-github-action@v1.24.0
uses: slackapi/slack-github-action@v2.1.0
with:
webhook: ${{ secrets.SLACK_WEBHOOK_URL }}
webhook-type: incoming-webhook
payload: |
{
"attachments": [{
"color": "danger",
"text": "❌ Database backup workflow failed for ${{ github.repository }}"
}]
}
env:
SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }}
1 change: 1 addition & 0 deletions .github/workflows/canary.yml
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,7 @@ jobs:

rollback:
name: Auto-Rollback
needs: [canary-10, canary-50, production-rollout]
if: failure()
runs-on: ubuntu-latest
steps:
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/coverage.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,7 @@ jobs:
with:
node-version: '20'
cache: 'npm'
cache-dependency-path: frontend/package-lock.json

- name: Install dependencies
run: npm ci
Expand All @@ -36,6 +37,6 @@ jobs:
uses: codecov/codecov-action@v4
with:
token: ${{ secrets.CODECOV_TOKEN }}
directory: frontend/coverage
directory: coverage
flags: frontend
fail_ci_if_error: false
4 changes: 2 additions & 2 deletions .github/workflows/fuzz-testing.yml
Original file line number Diff line number Diff line change
Expand Up @@ -133,7 +133,7 @@ jobs:
- name: Install Rust
uses: dtolnay/rust-toolchain@stable
with:
components: rustfmt, clippy, llvm-tools-preview
components: rustfmt, clippy, llvm-tools

- name: Install grcov
run: cargo install grcov
Expand All @@ -156,7 +156,7 @@ jobs:
--output-path coverage.lcov

- name: Upload Coverage to Codecov
uses: codecov/codecov-action@v5
uses: codecov/codecov-action@v4
with:
file: contracts/coverage.lcov
flags: fuzz-testing
Expand Down
7 changes: 4 additions & 3 deletions .github/workflows/performance-monitoring.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,15 +28,16 @@ jobs:

- name: Build bundle
run: npm run build
working-directory: frontend
env:
NODE_ENV: production
ANALYZE: 'false'
NEXT_TELEMETRY_DISABLED: '1'

- name: Check bundle size
run: |
BUNDLE_SIZE=$(du -sb frontend/.next/static | awk '{print $1}')
BUNDLE_SIZE_MB=$(echo "scale=2; $BUNDLE_SIZE / 1048576" | bc)
MAX_SIZE_MB=5.0
BUNDLE_SIZE_MB=$(echo "scale=2; $BUNDLE_SIZE / 1048576" | bc) MAX_SIZE_MB=5.0

echo "Bundle Size: ${BUNDLE_SIZE_MB}MB"

Expand All @@ -49,7 +50,7 @@ jobs:

- name: Analyze bundle with lighthouse
run: |
npm install -g @lhci/cli@0.11.x
npm install -g @lhci/cli@0.14.x
lhci autorun --config=./lighthouse/lighthouse.config.json || true
continue-on-error: true

Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,8 @@ jobs:
- uses: actions/setup-node@v4
with:
node-version: ${{ env.NODE_VERSION }}
cache: 'npm'
cache-dependency-path: package-lock.json

- run: npm ci

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/sdk-generation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -86,7 +86,7 @@ jobs:
path: backend/docs/api/openapi/

- name: Install oasdiff
run: npm install -g @openapi-diff/openapi-diff
run: npm install -g @oasdiff/oasdiff

- name: Fetch previous OpenAPI spec
run: |
Expand Down
5 changes: 0 additions & 5 deletions .github/workflows/security-audit-pipeline.yml
Original file line number Diff line number Diff line change
Expand Up @@ -234,11 +234,6 @@ jobs:
if: >-
${{ (github.event_name == 'push' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch')
&& (github.event.inputs.scan_type == 'all' || github.event.inputs.scan_type == 'dast' || github.event_name != 'workflow_dispatch') }}
services:
backend:
image: node:20-alpine
ports:
- 3001:3001
steps:
- name: Checkout
uses: actions/checkout@v4
Expand Down
32 changes: 18 additions & 14 deletions .github/workflows/security-audit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -71,34 +71,37 @@ jobs:
--exclude-low \
--solc-remaps "" || true

# Convert to human-readable format
# Generate a human-readable Markdown checklist
slither . \
--exclude-dependencies \
--exclude-low \
--risk high,medium \
--output-to-file {severity}-{type}-slither-report.md
--checklist \
--markdown-root . \
2>&1 > slither-checklist.md || true

- name: Parse Slither Results
id: parse_slither
working-directory: contracts
run: |
if [ -f "HIGH-high-slither-report.md" ]; then
echo "slither_high_findings=true" >> $GITHUB_OUTPUT
echo "## 🔴 Slither: Critical Findings Found" >> $GITHUB_STEP_SUMMARY
cat HIGH-high-slither-report.md >> $GITHUB_STEP_SUMMARY
fi
if [ -f "slither-checklist.md" ]; then
# Check for high severity in the checklist output
if grep -qi "high" slither-checklist.md; then
echo "slither_high_findings=true" >> $GITHUB_OUTPUT
echo "## 🔴 Slither: Critical Findings Found" >> $GITHUB_STEP_SUMMARY
cat slither-checklist.md >> $GITHUB_STEP_SUMMARY
fi

if [ -f "MEDIUM-medium-slither-report.md" ]; then
echo "slither_medium_findings=true" >> $GITHUB_OUTPUT
echo "## 🟠 Slither: Medium-Risk Findings" >> $GITHUB_STEP_SUMMARY
cat MEDIUM-medium-slither-report.md >> $GITHUB_STEP_SUMMARY
if grep -qi "medium" slither-checklist.md; then
echo "slither_medium_findings=true" >> $GITHUB_OUTPUT
echo "## 🟠 Slither: Medium-Risk Findings" >> $GITHUB_STEP_SUMMARY
fi
fi

- name: Move Slither reports
if: always()
working-directory: contracts
run: |
mv -f *slither-report.md ${{ github.workspace }}/${{ env.SECURITY_REPORT_DIR }}/ || true
mv -f slither-checklist.md ${{ github.workspace }}/${{ env.SECURITY_REPORT_DIR }}/slither-checklist.md || true
mv -f ${{ runner.temp }}/slither-report.json ${{ github.workspace }}/${{ env.SECURITY_REPORT_DIR }}/ || true

- name: Upload Slither Artifacts
Expand Down Expand Up @@ -170,7 +173,8 @@ jobs:
for file in mythril-*.json; do
if [ -f "$file" ]; then
# Count issues by severity
CRITICAL=$((CRITICAL + $(jq '[.issues[] | select(.severity=="High")] | length' "$file" 2>/dev/null || echo 0)))
FILE_CRITICAL=$(jq '[.issues[] | select(.severity=="High")] | length' "$file" 2>/dev/null || echo 0)
CRITICAL_COUNT=$((CRITICAL_COUNT + FILE_CRITICAL))
fi
done

Expand Down
Loading