From 17eee253a51f5efe624cf5d5b36427651beee3da Mon Sep 17 00:00:00 2001 From: David Date: Sun, 27 Sep 2026 08:01:42 -0400 Subject: [PATCH 1/2] ci: add Dependabot and security checks --- .github/dependabot.yml | 32 +++++++++++++++++ .github/workflows/origin89-security.yml | 47 +++++++++++++++++++++++++ CONTRIBUTING.md | 4 ++- requirements-dev.txt | 2 ++ 4 files changed, 84 insertions(+), 1 deletion(-) create mode 100644 .github/dependabot.yml create mode 100644 .github/workflows/origin89-security.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..b5ee46c --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,32 @@ +# Adapted from origin89hq/engineering templates/dependabot.yml; see its docs/dependencies.md. +version: 2 + +updates: + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly + cooldown: + default-days: 3 # zizmor: ignore[dependabot-cooldown] three days matches the Origin89 dependency policy + groups: + actions: + patterns: ["*"] + update-types: [minor, patch] + commit-message: + prefix: ci + + # requirements-dev.txt is compiled by uv pip compile from requirements-dev.in; + # the uv ecosystem reruns it with the options recorded in the file header. + - package-ecosystem: uv + directory: / + schedule: + interval: weekly + cooldown: + default-days: 3 # zizmor: ignore[dependabot-cooldown] three days matches the Origin89 dependency policy + groups: + python: + patterns: ["*"] + update-types: [minor, patch] + commit-message: + prefix: chore + include: scope diff --git a/.github/workflows/origin89-security.yml b/.github/workflows/origin89-security.yml new file mode 100644 index 0000000..dd2345a --- /dev/null +++ b/.github/workflows/origin89-security.yml @@ -0,0 +1,47 @@ +# Adapted from origin89hq/engineering templates/workflows/origin89-security.yml. +name: origin89-security + +on: + push: + branches: [main] + pull_request: + # New advisories arrive without a code change. + schedule: + - cron: "17 6 * * 1" + +permissions: + contents: read + +jobs: + dependency-review: + if: github.event_name == 'pull_request' + runs-on: ubuntu-latest + timeout-minutes: 5 + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + with: + persist-credentials: false + - uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0 + with: + fail-on-severity: moderate + fail-on-scopes: runtime, development + # Checked only for dependencies the pull request adds. Unknown + # licenses are reported without failing. + allow-licenses: >- + 0BSD, Apache-2.0, BlueOak-1.0.0, BSD-2-Clause, BSD-3-Clause, + CC-BY-4.0, CC0-1.0, ISC, MIT, MPL-2.0, Python-2.0, Unicode-3.0, + Unlicense, Zlib + + zizmor: + runs-on: ubuntu-latest + timeout-minutes: 5 + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + with: + persist-credentials: false + - uses: zizmorcore/zizmor-action@cc914d7f3750a2d13d75c7f184a1060aa0e9d482 # v0.6.4 + with: + version: 1.30.1 + advanced-security: false + annotations: true + min-severity: medium diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 34076f4..3faff23 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -39,7 +39,9 @@ Dependency updates start in `requirements-dev.in`; regenerate the hash-locked ```sh uv pip compile requirements-dev.in --python-version 3.12 \ - --generate-hashes --universal --no-header -o requirements-dev.txt + --generate-hashes --universal -o requirements-dev.txt ``` +Keep the generated header: Dependabot reads the compile options from it. + Update the export selected by `just gerbers` when filing a reviewed board revision. diff --git a/requirements-dev.txt b/requirements-dev.txt index 8667fb6..ab028c9 100644 --- a/requirements-dev.txt +++ b/requirements-dev.txt @@ -1,3 +1,5 @@ +# This file was autogenerated by uv via the following command: +# uv pip compile requirements-dev.in --python-version 3.12 --generate-hashes --universal -o requirements-dev.txt aiofiles==25.1.0 \ --hash=sha256:a8d728f0a29de45dc521f18f07297428d56992a742f0cd2701ba86e44d23d5b2 \ --hash=sha256:abe311e527c862958650f9438e859c1fa7568a141b22abcd015e120e86a85695 From 4e8d6bb70e604b9243d738993e6eaf82a0b2b056 Mon Sep 17 00:00:00 2001 From: David Date: Sun, 27 Sep 2026 08:02:22 -0400 Subject: [PATCH 2/2] ci: use a seven-day Dependabot cooldown --- .github/dependabot.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index b5ee46c..c719589 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -7,7 +7,7 @@ updates: schedule: interval: weekly cooldown: - default-days: 3 # zizmor: ignore[dependabot-cooldown] three days matches the Origin89 dependency policy + default-days: 7 groups: actions: patterns: ["*"] @@ -22,7 +22,7 @@ updates: schedule: interval: weekly cooldown: - default-days: 3 # zizmor: ignore[dependabot-cooldown] three days matches the Origin89 dependency policy + default-days: 7 groups: python: patterns: ["*"]