Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 32 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
# Adapted from origin89hq/engineering templates/dependabot.yml; see its docs/dependencies.md.
version: 2

updates:
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
cooldown:
default-days: 7
groups:
actions:
patterns: ["*"]
update-types: [minor, patch]
commit-message:
prefix: ci

# requirements-dev.txt is compiled by uv pip compile from requirements-dev.in;
# the uv ecosystem reruns it with the options recorded in the file header.
- package-ecosystem: uv
directory: /
schedule:
interval: weekly
cooldown:
default-days: 7
groups:
python:
patterns: ["*"]
update-types: [minor, patch]
commit-message:
prefix: chore
include: scope
47 changes: 47 additions & 0 deletions .github/workflows/origin89-security.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
# Adapted from origin89hq/engineering templates/workflows/origin89-security.yml.
name: origin89-security

on:
push:
branches: [main]
pull_request:
# New advisories arrive without a code change.
schedule:
- cron: "17 6 * * 1"

permissions:
contents: read

jobs:
dependency-review:
if: github.event_name == 'pull_request'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Run a dependency scanner on scheduled events

On a scheduled run, this condition unconditionally skips dependency-review; the only remaining job is zizmor, which audits workflow definitions rather than the packages pinned in requirements-dev.txt. Consequently, a vulnerability disclosed after a dependency was merged is not evaluated by the weekly run despite the schedule's stated purpose. Add a scheduled vulnerability scanner for the existing lock file, or otherwise remove the misleading advisory coverage.

Useful? React with 👍 / 👎.

runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0
with:
fail-on-severity: moderate
fail-on-scopes: runtime, development
# Checked only for dependencies the pull request adds. Unknown
# licenses are reported without failing.
allow-licenses: >-
0BSD, Apache-2.0, BlueOak-1.0.0, BSD-2-Clause, BSD-3-Clause,
CC-BY-4.0, CC0-1.0, ISC, MIT, MPL-2.0, Python-2.0, Unicode-3.0,
Unlicense, Zlib

zizmor:
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- uses: zizmorcore/zizmor-action@cc914d7f3750a2d13d75c7f184a1060aa0e9d482 # v0.6.4
with:
version: 1.30.1
advanced-security: false
annotations: true
min-severity: medium
4 changes: 3 additions & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,9 @@ Dependency updates start in `requirements-dev.in`; regenerate the hash-locked

```sh
uv pip compile requirements-dev.in --python-version 3.12 \
--generate-hashes --universal --no-header -o requirements-dev.txt
--generate-hashes --universal -o requirements-dev.txt
```

Keep the generated header: Dependabot reads the compile options from it.

Update the export selected by `just gerbers` when filing a reviewed board revision.
2 changes: 2 additions & 0 deletions requirements-dev.txt
Original file line number Diff line number Diff line change
@@ -1,3 +1,5 @@
# This file was autogenerated by uv via the following command:
# uv pip compile requirements-dev.in --python-version 3.12 --generate-hashes --universal -o requirements-dev.txt
aiofiles==25.1.0 \
--hash=sha256:a8d728f0a29de45dc521f18f07297428d56992a742f0cd2701ba86e44d23d5b2 \
--hash=sha256:abe311e527c862958650f9438e859c1fa7568a141b22abcd015e120e86a85695
Expand Down
Loading