maziggy
7c0eeed8d5
Both workflows now parse package-lock.json directly instead of trusting npm ls. The lockfile correctly marks minimatch as dev: true and doesn't contain npm/tar at all —
...
so all three npm-internal packages will be filtered out regardless of which npm version CI uses.
2026-02-20 19:32:07 +01:00
maziggy
4991192246
Updated CI
2026-02-20 19:22:50 +01:00
maziggy
802bfe330a
Updated CI
2026-02-20 19:19:20 +01:00
maziggy
5d48ab88f0
Updated CI
2026-02-20 19:10:56 +01:00
maziggy
2c0d1c2fe6
Updated CI
2026-02-20 18:29:50 +01:00
maziggy
036ae16ad5
Updated CI
2026-02-18 18:08:23 +01:00
maziggy
a361671952
Updated CI
2026-02-18 17:47:49 +01:00
dependabot[bot]
971aa960a8
build(deps): bump aquasecurity/trivy-action
...
Bumps the github_actions group with 1 update in the /.github/workflows directory: [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action ).
Updates `aquasecurity/trivy-action` from 0.33.1 to 0.34.0
- [Release notes](https://github.com/aquasecurity/trivy-action/releases )
- [Commits](https://github.com/aquasecurity/trivy-action/compare/0.33.1...0.34.0 )
---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
dependency-version: 0.34.0
dependency-type: direct:production
dependency-group: github_actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-18 16:31:35 +00:00
maziggy
10cae700f4
Updated CI
2026-02-18 17:27:37 +01:00
dependabot[bot]
1d0875ee83
build(deps): bump aquasecurity/trivy-action
...
Bumps the github_actions group with 1 update in the /.github/workflows directory: [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action ).
Updates `aquasecurity/trivy-action` from 0.33.1 to 0.34.0
- [Release notes](https://github.com/aquasecurity/trivy-action/releases )
- [Commits](https://github.com/aquasecurity/trivy-action/compare/0.33.1...0.34.0 )
---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
dependency-version: 0.34.0
dependency-type: direct:production
dependency-group: github_actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-18 15:56:12 +00:00
maziggy
101288d1b2
Updated CI
2026-02-18 13:28:33 +01:00
maziggy
6ee25a2157
The only-labels: 'feedback' parameter tells the stale bot to only process issues that have the feedback label. All other issues (feature requests with future, bug
...
reports, etc.) will be left alone.
2026-02-16 08:35:43 +01:00
maziggy
1e5b263acb
Added -n auto to run tests in parallel via pytest-xdist
2026-02-10 17:57:40 +01:00
maziggy
23d539f284
Fix CI backend-tests failing to collect FTP test suite
...
CI only installed requirements.txt, missing pyOpenSSL from
requirements-dev.txt. This caused an ImportError on
TLS_FTPHandler during test collection, blocking all
unit/services tests. Also adds pytest-timeout to dev deps
instead of ad-hoc pip install in CI.
2026-02-10 17:49:58 +01:00
maziggy
cf19ac8d39
Added two steps to the docker-test job in ci.yml
2026-02-08 07:53:32 +01:00
maziggy
74e84277cf
Add CodeQL advanced setup workflow with accepted-risk exclusions
2026-02-06 13:25:23 +01:00
maziggy
46ba5ff417
Fix Bandit detection and update Trivy to v0.69.1
...
- Fix defusedxml import style in print_queue.py to be recognized by Bandit
(use `import defusedxml.ElementTree as ET` not `from defusedxml import`)
- Update Trivy scanner version from 0.65.0 to 0.69.1
2026-02-05 17:50:16 +01:00
maziggy
fc4f565eba
Update Trivy scanner to v0.69.1
...
Pin the latest Trivy scanner version for improved vulnerability detection.
2026-02-05 17:33:51 +01:00
maziggy
7841237d4e
Fixed Trivy workflow
2026-02-05 14:05:29 +01:00
maziggy
45e08b023a
Updated CI
2026-02-05 12:34:06 +01:00
maziggy
f9431ced0c
Updated CI
2026-02-05 12:24:52 +01:00
maziggy
c01839b2ce
Added Bandit and Trivy to CI
2026-02-05 12:18:00 +01:00
MartinNYHC
a91a9eacbf
Delete .github/workflows/codeql.yml
2026-02-04 16:07:37 +01:00
maziggy
bff7da2861
Updated all CodeQL actions to v4
2026-02-04 14:48:15 +01:00
maziggy
ab63fed637
Updated CI
2026-02-04 14:43:36 +01:00
maziggy
d2c720e70f
Updated CI
2026-01-29 15:10:34 +01:00
maziggy
86ad13398a
Updated CI
2026-01-29 13:31:07 +01:00
maziggy
54abee53f8
Updated Github workflow
2026-01-28 09:15:46 +01:00
maziggy
a1c59fd6cb
Updated the workflow:
...
- Changed stale-issue-label from feedback to stale (so stale issues get the "stale" label)
- Added remove-issue-labels: 'feedback' to remove the feedback label when issues are auto-closed
2026-01-28 07:13:35 +01:00
maziggy
56efb44c4f
Added explicit permissions: issues: write
2026-01-27 11:44:23 +01:00
maziggy
aa5ab135c7
Added stale issues workflow
2026-01-27 11:15:13 +01:00
maziggy
51df60cb91
Fixed CI
2026-01-26 15:53:54 +01:00
maziggy
580225a38d
Add security scanning to CI pipeline
...
- Add pip-audit check to PR workflow (non-blocking warning)
- Add npm audit check to PR workflow (non-blocking, high severity only)
- Create scheduled weekly security audit workflow that:
- Runs strict pip-audit and npm audit
- Creates/updates GitHub issues when vulnerabilities found
- Uploads audit results as artifacts
- Supports manual trigger via workflow_dispatch
2026-01-26 13:21:02 +01:00
maziggy
164d22f2bb
Add security scanning to CI pipeline
...
- Add pip-audit check to PR workflow (non-blocking warning)
- Add npm audit check to PR workflow (non-blocking warning)
- Create scheduled weekly security audit workflow that:
- Runs strict pip-audit and npm audit
- Creates/updates GitHub issues when vulnerabilities found
- Uploads audit results as artifacts
- Supports manual trigger via workflow_dispatch
2026-01-26 13:18:29 +01:00
maziggy
4babcf6187
Updated CI
2026-01-22 12:32:45 +01:00
maziggy
7bca0d733f
Fixed Github CI
2026-01-21 16:02:30 +01:00
maziggy
0d1056ded4
Added timeouts to Github CI runner
...
- Backend tests: 10 min (step-level)
- Frontend tests: 10 min (step-level)
- Docker tests: 20 min (job-level, since it has multiple build/test steps)
2026-01-21 15:27:24 +01:00
maziggy
8abfaa391a
Rename Docker Test job back to Docker Build for branch protection
2026-01-11 07:59:19 +01:00
maziggy and Claude Opus 4.5
02dbc5a84f
Add full Docker test suite to CI (matches test_docker.sh)
...
- Test 1: Build production image, verify imports & static files
- Test 2: Backend unit tests in Docker container
- Test 3: Frontend unit tests in Docker container
- Test 4: Integration tests (health, API, static files)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com >
2026-01-11 07:53:03 +01:00
maziggy and Claude Opus 4.5
c665c3e6a3
Add Docker integration tests to CI
...
Match test_docker.sh workflow:
- Build Docker image
- Verify backend imports
- Verify static files exist
- Test health endpoint
- Test API endpoint
- Test static files served
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com >
2026-01-11 07:47:21 +01:00
maziggy and Claude Opus 4.5
11482dd4d3
Run all backend tests in CI (unit + integration)
...
Previously only ran tests/unit/, now runs tests/ to match
test_backend.sh workflow (513 tests instead of 239).
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com >
2026-01-11 07:45:12 +01:00
maziggy
1a5d867e14
Enabled Github CI
2026-01-11 07:06:32 +01:00
maziggy
b6a7dabbab
Disbaled CI temp.
2025-12-11 14:56:04 +01:00
maziggy
ff53e62ef8
Add comprehensive automated testing infrastructure
...
Backend:
- pytest configuration with async support and coverage
- Unit tests for notification service (23 tests)
- Unit tests for smart plug manager (12 tests)
- Unit tests for archive service (16 tests)
- Integration tests for API endpoints
- Fix: notifications now send immediately (digest is summary only)
Frontend:
- Vitest configuration with jsdom and coverage
- MSW for API mocking
- Component tests for Toggle, Button, Card, ConfirmModal (77 tests)
- Test utilities with custom render wrapper
CI/CD:
- GitHub Actions workflow for automated testing
- Backend lint, unit tests, integration tests
- Frontend lint, type-check, unit tests, build
2025-12-11 10:03:40 +01:00