Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/actions/setup-duckdb/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ runs:
using: composite
steps:
- shell: bash
run: |
run: | # zizmor: ignore[github-env] appends a fixed RUNNER_TEMP path holding the checksum-verified CLI
set -euo pipefail
archive="$RUNNER_TEMP/duckdb-cli.zip"
install_dir="$RUNNER_TEMP/duckdb-cli"
Expand Down
2 changes: 1 addition & 1 deletion .github/actions/setup/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ runs:
with:
node-version: 24
package-manager-cache: false
- uses: pnpm/action-setup@f520eceda224fe1a4aed5a2a27a194379a409996 # v6
- uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 # v6
with:
run_install: false
cache: true
Expand Down
36 changes: 36 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
# See origin89hq/engineering docs/dependencies.md.
version: 2

updates:
# Composite actions are not scanned from the root directory.
- package-ecosystem: github-actions
directories:
- /
- /.github/actions/setup
- /.github/actions/setup-duckdb
schedule:
interval: weekly
cooldown:
default-days: 7
groups:
actions:
patterns: ["*"]
update-types: [minor, patch]
commit-message:
prefix: ci

# pnpm workspaces use the npm ecosystem from the directory holding the lockfile.
- package-ecosystem: npm
directory: /
schedule:
interval: weekly
# At least pnpm's minimumReleaseAge, or the frozen install rejects the update.
cooldown:
default-days: 7
groups:
npm:
patterns: ["*"]
update-types: [minor, patch]
commit-message:
prefix: chore
include: scope
47 changes: 47 additions & 0 deletions .github/workflows/origin89-security.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
# See origin89hq/engineering docs/dependencies.md.
name: origin89-security

on:
push:
branches: [main]
pull_request:
# New advisories arrive without a code change.
schedule:
- cron: "17 6 * * 1"

permissions:
contents: read

jobs:
dependency-review:
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0
with:
fail-on-severity: moderate
fail-on-scopes: runtime, development
# Checked only for dependencies the pull request adds. Unknown
# licenses are reported without failing.
allow-licenses: >-
0BSD, Apache-2.0, BlueOak-1.0.0, BSD-2-Clause, BSD-3-Clause,
CC-BY-4.0, CC0-1.0, ISC, MIT, MPL-2.0, Python-2.0, Unicode-3.0,
Unlicense, Zlib

zizmor:
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- uses: zizmorcore/zizmor-action@cc914d7f3750a2d13d75c7f184a1060aa0e9d482 # v0.6.4
with:
version: 1.30.1
advanced-security: false
annotations: true
min-severity: medium
2 changes: 1 addition & 1 deletion .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ name: Publish the dataset
# much again when it is retired. That is about $2.50 a version, and four merges that touched
# records in a day were four of them for one day's figures. A day's merges now go out together.
# `workflow_dispatch` publishes at once when something should not wait.
on:
on: # zizmor: ignore[dangerous-triggers] reviewed: only the manual main-branch deploy triggers it, and it checks out main, not the run's head
schedule:
# Eleven hours after the daily pull opens its pull request, so a day's records go out the
# evening they are merged.
Expand Down
Loading