From b1b87f49a44841d5c0fb016fbb8189f5e617a7ad Mon Sep 17 00:00:00 2001 From: maziggy Date: Wed, 4 Feb 2026 14:43:36 +0100 Subject: [PATCH 1/9] Updated CI --- .github/workflows/codeql.yml | 46 ++++++++++++++++++++++++++++++++++++ 1 file changed, 46 insertions(+) create mode 100644 .github/workflows/codeql.yml diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml new file mode 100644 index 000000000..616b887ab --- /dev/null +++ b/.github/workflows/codeql.yml @@ -0,0 +1,46 @@ +name: CodeQL + +on: + push: + branches: ['**'] + pull_request: + branches: ['**'] + schedule: + # Run weekly on Sunday at 3:00 UTC + - cron: '0 3 * * 0' + +# Cancel in-progress runs for the same branch +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +permissions: + contents: read + security-events: write + +jobs: + analyze: + name: Analyze + runs-on: ubuntu-latest + strategy: + fail-fast: false + matrix: + language: ['javascript-typescript', 'python'] + steps: + - name: Checkout repository + uses: actions/checkout@v4 + + - name: Initialize CodeQL + uses: github/codeql-action/init@v3 + with: + languages: ${{ matrix.language }} + # Use default queries plus security-extended + queries: security-extended + + - name: Autobuild + uses: github/codeql-action/autobuild@v3 + + - name: Perform CodeQL Analysis + uses: github/codeql-action/analyze@v3 + with: + category: '/language:${{ matrix.language }}' From 0569c48fac2aa559fbba1350dd669b806bac2ec2 Mon Sep 17 00:00:00 2001 From: maziggy Date: Wed, 4 Feb 2026 14:48:15 +0100 Subject: [PATCH 2/9] Updated all CodeQL actions to v4 --- .github/workflows/codeql.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 616b887ab..684587bd3 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -31,16 +31,16 @@ jobs: uses: actions/checkout@v4 - name: Initialize CodeQL - uses: github/codeql-action/init@v3 + uses: github/codeql-action/init@v4 with: languages: ${{ matrix.language }} # Use default queries plus security-extended queries: security-extended - name: Autobuild - uses: github/codeql-action/autobuild@v3 + uses: github/codeql-action/autobuild@v4 - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v3 + uses: github/codeql-action/analyze@v4 with: category: '/language:${{ matrix.language }}' From 1401962a082ff71a5ea5d0e1b56ba6a37ebaf309 Mon Sep 17 00:00:00 2001 From: maziggy Date: Wed, 4 Feb 2026 14:47:15 +0100 Subject: [PATCH 3/9] Fixed ruff errors --- backend/app/core/permissions.py | 4 ++-- backend/app/schemas/github_backup.py | 4 ++-- backend/app/schemas/notification.py | 4 ++-- backend/app/schemas/notification_template.py | 4 ++-- backend/app/services/firmware_update.py | 4 ++-- 5 files changed, 10 insertions(+), 10 deletions(-) diff --git a/backend/app/core/permissions.py b/backend/app/core/permissions.py index 18b2b7735..a6c56d409 100644 --- a/backend/app/core/permissions.py +++ b/backend/app/core/permissions.py @@ -4,10 +4,10 @@ This module defines all permissions using a string enum with `resource:action` n Permissions are additive across groups - a user has all permissions from all their groups. """ -from enum import Enum +from enum import StrEnum -class Permission(str, Enum): +class Permission(StrEnum): """All available permissions in the system. Permissions follow the pattern: resource:action diff --git a/backend/app/schemas/github_backup.py b/backend/app/schemas/github_backup.py index 2fe8299b1..ca3cfe587 100644 --- a/backend/app/schemas/github_backup.py +++ b/backend/app/schemas/github_backup.py @@ -2,12 +2,12 @@ import re from datetime import datetime -from enum import Enum +from enum import StrEnum from pydantic import BaseModel, Field, field_validator -class ScheduleType(str, Enum): +class ScheduleType(StrEnum): """Backup schedule types.""" HOURLY = "hourly" diff --git a/backend/app/schemas/notification.py b/backend/app/schemas/notification.py index ca8ff5b41..785227f9e 100644 --- a/backend/app/schemas/notification.py +++ b/backend/app/schemas/notification.py @@ -1,13 +1,13 @@ """Pydantic schemas for notification providers.""" from datetime import datetime -from enum import Enum +from enum import StrEnum from typing import Any from pydantic import BaseModel, Field, field_validator -class ProviderType(str, Enum): +class ProviderType(StrEnum): """Supported notification provider types.""" CALLMEBOT = "callmebot" diff --git a/backend/app/schemas/notification_template.py b/backend/app/schemas/notification_template.py index 544a3c57e..c3f0467ef 100644 --- a/backend/app/schemas/notification_template.py +++ b/backend/app/schemas/notification_template.py @@ -1,12 +1,12 @@ """Pydantic schemas for notification templates.""" from datetime import datetime -from enum import Enum +from enum import StrEnum from pydantic import BaseModel, Field -class EventType(str, Enum): +class EventType(StrEnum): """Supported notification event types.""" PRINT_START = "print_start" diff --git a/backend/app/services/firmware_update.py b/backend/app/services/firmware_update.py index 7d395b0b5..fdf26760f 100644 --- a/backend/app/services/firmware_update.py +++ b/backend/app/services/firmware_update.py @@ -11,7 +11,7 @@ Orchestrates firmware updates for Bambu Lab printers: import asyncio import logging from dataclasses import dataclass -from enum import Enum +from enum import StrEnum from sqlalchemy import select from sqlalchemy.ext.asyncio import AsyncSession @@ -30,7 +30,7 @@ from backend.app.services.printer_manager import printer_manager logger = logging.getLogger(__name__) -class FirmwareUploadStatus(str, Enum): +class FirmwareUploadStatus(StrEnum): """Status of a firmware upload operation.""" IDLE = "idle" From de604972d85c7a4e93c9cfc6e58f7fe3c6c92f09 Mon Sep 17 00:00:00 2001 From: maziggy Date: Wed, 4 Feb 2026 14:43:36 +0100 Subject: [PATCH 4/9] - Updated all CodeQL actions to v4 - Fixed ruff errors - Updated CI --- .github/workflows/codeql.yml | 46 ------------------------------------ 1 file changed, 46 deletions(-) delete mode 100644 .github/workflows/codeql.yml diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml deleted file mode 100644 index 684587bd3..000000000 --- a/.github/workflows/codeql.yml +++ /dev/null @@ -1,46 +0,0 @@ -name: CodeQL - -on: - push: - branches: ['**'] - pull_request: - branches: ['**'] - schedule: - # Run weekly on Sunday at 3:00 UTC - - cron: '0 3 * * 0' - -# Cancel in-progress runs for the same branch -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true - -permissions: - contents: read - security-events: write - -jobs: - analyze: - name: Analyze - runs-on: ubuntu-latest - strategy: - fail-fast: false - matrix: - language: ['javascript-typescript', 'python'] - steps: - - name: Checkout repository - uses: actions/checkout@v4 - - - name: Initialize CodeQL - uses: github/codeql-action/init@v4 - with: - languages: ${{ matrix.language }} - # Use default queries plus security-extended - queries: security-extended - - - name: Autobuild - uses: github/codeql-action/autobuild@v4 - - - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v4 - with: - category: '/language:${{ matrix.language }}' From c87609c5580379de61723068217b657c561ebd55 Mon Sep 17 00:00:00 2001 From: maziggy Date: Thu, 5 Feb 2026 09:05:25 +0100 Subject: [PATCH 5/9] Changed issue templates --- .github/ISSUE_TEMPLATE/bug_report.yml | 8 ++++++-- .github/ISSUE_TEMPLATE/feature_request.yml | 4 +++- 2 files changed, 9 insertions(+), 3 deletions(-) diff --git a/.github/ISSUE_TEMPLATE/bug_report.yml b/.github/ISSUE_TEMPLATE/bug_report.yml index 8b301742c..8a351faf4 100644 --- a/.github/ISSUE_TEMPLATE/bug_report.yml +++ b/.github/ISSUE_TEMPLATE/bug_report.yml @@ -121,7 +121,9 @@ body: id: logs attributes: label: Relevant Logs / Support Package - description: Attach a support package (.zip) or paste relevant logs here. Enable DEBUG mode for verbose logging. + description: | + Attach a support package (.zip) or paste relevant logs here. Enable DEBUG mode for verbose logging. + 💡 Tip: You can drag and drop files directly into this text box. render: shell placeholder: | Drag and drop your support package .zip file here, or paste logs... @@ -130,7 +132,9 @@ body: id: screenshots attributes: label: Screenshots - description: If applicable, add screenshots to help explain your problem. + description: | + If applicable, add screenshots to help explain your problem. + 💡 Tip: You can drag and drop images directly into this text box. - type: textarea id: additional diff --git a/.github/ISSUE_TEMPLATE/feature_request.yml b/.github/ISSUE_TEMPLATE/feature_request.yml index e2df823ba..015299091 100644 --- a/.github/ISSUE_TEMPLATE/feature_request.yml +++ b/.github/ISSUE_TEMPLATE/feature_request.yml @@ -71,7 +71,9 @@ body: id: mockups attributes: label: Mockups or Examples - description: If you have any mockups, screenshots, or examples from other software, please share them. + description: | + If you have any mockups, screenshots, or examples from other software, please share them. + 💡 Tip: You can drag and drop images directly into this text box. - type: checkboxes id: contribution From c164ae42ecd1740e22af689e574c972e65e7ca55 Mon Sep 17 00:00:00 2001 From: maziggy Date: Thu, 5 Feb 2026 12:18:00 +0100 Subject: [PATCH 6/9] Added Bandit and Trivy to CI --- .github/workflows/security.yml | 87 ++++++++++++++++++++++++++++++++++ 1 file changed, 87 insertions(+) diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 957e191ae..4e33a5948 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -4,6 +4,22 @@ on: schedule: # Run weekly on Monday at 6:00 UTC - cron: '0 6 * * 1' + push: + paths: + - 'backend/**' + - 'frontend/**' + - 'Dockerfile' + - 'docker-compose*.yml' + - 'requirements.txt' + - 'frontend/package*.json' + pull_request: + paths: + - 'backend/**' + - 'frontend/**' + - 'Dockerfile' + - 'docker-compose*.yml' + - 'requirements.txt' + - 'frontend/package*.json' workflow_dispatch: # Allow manual trigger @@ -16,6 +32,77 @@ permissions: contents: read jobs: + bandit: + name: Python Security Analysis (Bandit) + runs-on: ubuntu-latest + permissions: + contents: read + security-events: write + steps: + - uses: actions/checkout@v4 + + - name: Set up Python + uses: actions/setup-python@v5 + with: + python-version: ${{ env.PYTHON_VERSION }} + + - name: Install Bandit + run: pip install bandit[sarif] + + - name: Run Bandit + run: | + bandit -r backend/ -f sarif -o bandit-results.sarif --severity-level medium || true + + - name: Upload Bandit results to GitHub Security + uses: github/codeql-action/upload-sarif@v3 + if: always() + with: + sarif_file: bandit-results.sarif + category: bandit + + trivy: + name: Container Security Scan (Trivy) + runs-on: ubuntu-latest + permissions: + contents: read + security-events: write + steps: + - uses: actions/checkout@v4 + + - name: Build Docker image + run: docker build -t bambuddy:security-scan . + + - name: Run Trivy vulnerability scanner + uses: aquasecurity/trivy-action@master + with: + image-ref: 'bambuddy:security-scan' + format: 'sarif' + output: 'trivy-results.sarif' + severity: 'CRITICAL,HIGH,MEDIUM' + + - name: Upload Trivy results to GitHub Security + uses: github/codeql-action/upload-sarif@v3 + if: always() + with: + sarif_file: trivy-results.sarif + category: trivy + + - name: Run Trivy for Dockerfile/IaC + uses: aquasecurity/trivy-action@master + with: + scan-type: 'config' + scan-ref: '.' + format: 'sarif' + output: 'trivy-config-results.sarif' + severity: 'CRITICAL,HIGH,MEDIUM' + + - name: Upload Trivy config results + uses: github/codeql-action/upload-sarif@v3 + if: always() + with: + sarif_file: trivy-config-results.sarif + category: trivy-config + backend-audit: name: Backend Security Audit runs-on: ubuntu-latest From 239d0c7748a7e552b4f1d7f0e608e9de6f632c20 Mon Sep 17 00:00:00 2001 From: maziggy Date: Thu, 5 Feb 2026 12:24:52 +0100 Subject: [PATCH 7/9] Updated CI --- .github/workflows/ci.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 04d2cf559..739e6d1f4 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -4,7 +4,8 @@ on: push: branches: [main] pull_request: - # Run on all PRs, but skip for repo owner (runs local tests) + branches: [main] + # Run on PRs targeting main, but skip for repo owner (runs local tests) # Skip CI for PRs authored by repo owner (they run tests locally) # Uses PR author instead of triggering actor so rebasing by owner doesn't skip CI From a8860b44ae1df851cf002433297819cf34dec976 Mon Sep 17 00:00:00 2001 From: maziggy Date: Thu, 5 Feb 2026 12:34:06 +0100 Subject: [PATCH 8/9] Updated CI --- .github/workflows/security.yml | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 4e33a5948..a66b638d6 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -54,7 +54,7 @@ jobs: bandit -r backend/ -f sarif -o bandit-results.sarif --severity-level medium || true - name: Upload Bandit results to GitHub Security - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@v4 if: always() with: sarif_file: bandit-results.sarif @@ -73,7 +73,7 @@ jobs: run: docker build -t bambuddy:security-scan . - name: Run Trivy vulnerability scanner - uses: aquasecurity/trivy-action@master + uses: aquasecurity/trivy-action@v0.33.1 with: image-ref: 'bambuddy:security-scan' format: 'sarif' @@ -81,14 +81,14 @@ jobs: severity: 'CRITICAL,HIGH,MEDIUM' - name: Upload Trivy results to GitHub Security - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@v4 if: always() with: sarif_file: trivy-results.sarif category: trivy - name: Run Trivy for Dockerfile/IaC - uses: aquasecurity/trivy-action@master + uses: aquasecurity/trivy-action@v0.33.1 with: scan-type: 'config' scan-ref: '.' @@ -97,7 +97,7 @@ jobs: severity: 'CRITICAL,HIGH,MEDIUM' - name: Upload Trivy config results - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@v4 if: always() with: sarif_file: trivy-config-results.sarif From 837c0a9eecb8ba4e7dc81e7b0adddb7487a5ab62 Mon Sep 17 00:00:00 2001 From: maziggy Date: Thu, 5 Feb 2026 14:05:29 +0100 Subject: [PATCH 9/9] Fixed Trivy workflow --- .github/workflows/security.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index a66b638d6..13c8ba815 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -73,7 +73,7 @@ jobs: run: docker build -t bambuddy:security-scan . - name: Run Trivy vulnerability scanner - uses: aquasecurity/trivy-action@v0.33.1 + uses: aquasecurity/trivy-action@0.33.1 with: image-ref: 'bambuddy:security-scan' format: 'sarif' @@ -88,7 +88,7 @@ jobs: category: trivy - name: Run Trivy for Dockerfile/IaC - uses: aquasecurity/trivy-action@v0.33.1 + uses: aquasecurity/trivy-action@0.33.1 with: scan-type: 'config' scan-ref: '.'