maziggy
62f2e616a0
Changed CI
2026-04-23 08:57:15 +02:00
maziggy
a58ab8b8db
Updated .github/workflows/ci.yml
2026-04-12 15:05:28 +02:00
maziggy
d29688000f
Updated CI
2026-04-07 17:16:48 +02:00
maziggy
0b0ab23052
Added stats CI
2026-04-07 16:19:42 +02:00
maziggy
240b6cb408
Added stats CI
2026-04-07 16:11:43 +02:00
maziggy
fd140e3c64
Added stats CI
2026-04-07 16:08:54 +02:00
maziggy
7841d2f997
Housekeeping
2026-03-26 14:20:11 +01:00
maziggy
ba991702e5
Housekeeping
2026-03-26 14:08:10 +01:00
maziggy
ac75d4957f
Changed pipeline
2026-03-26 13:52:52 +01:00
maziggy
deecc8b7dc
Updated .github/workflows/security.yml
2026-03-20 11:07:08 +01:00
maziggy
c2cf041af2
Update CI Node.js version from 20 to 22 LTS
...
Node 20 is being deprecated on GitHub Actions runners.
Bump to Node 22 (Active LTS) in ci.yml and security.yml.
2026-03-13 15:34:22 +01:00
maziggy
7c0eeed8d5
Both workflows now parse package-lock.json directly instead of trusting npm ls. The lockfile correctly marks minimatch as dev: true and doesn't contain npm/tar at all —
...
so all three npm-internal packages will be filtered out regardless of which npm version CI uses.
2026-02-20 19:32:07 +01:00
maziggy
4991192246
Updated CI
2026-02-20 19:22:50 +01:00
maziggy
802bfe330a
Updated CI
2026-02-20 19:19:20 +01:00
maziggy
5d48ab88f0
Updated CI
2026-02-20 19:10:56 +01:00
maziggy
2c0d1c2fe6
Updated CI
2026-02-20 18:29:50 +01:00
maziggy
036ae16ad5
Updated CI
2026-02-18 18:08:23 +01:00
maziggy
a361671952
Updated CI
2026-02-18 17:47:49 +01:00
dependabot[bot]
971aa960a8
build(deps): bump aquasecurity/trivy-action
...
Bumps the github_actions group with 1 update in the /.github/workflows directory: [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action ).
Updates `aquasecurity/trivy-action` from 0.33.1 to 0.34.0
- [Release notes](https://github.com/aquasecurity/trivy-action/releases )
- [Commits](https://github.com/aquasecurity/trivy-action/compare/0.33.1...0.34.0 )
---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
dependency-version: 0.34.0
dependency-type: direct:production
dependency-group: github_actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-18 16:31:35 +00:00
maziggy
10cae700f4
Updated CI
2026-02-18 17:27:37 +01:00
dependabot[bot]
1d0875ee83
build(deps): bump aquasecurity/trivy-action
...
Bumps the github_actions group with 1 update in the /.github/workflows directory: [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action ).
Updates `aquasecurity/trivy-action` from 0.33.1 to 0.34.0
- [Release notes](https://github.com/aquasecurity/trivy-action/releases )
- [Commits](https://github.com/aquasecurity/trivy-action/compare/0.33.1...0.34.0 )
---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
dependency-version: 0.34.0
dependency-type: direct:production
dependency-group: github_actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-18 15:56:12 +00:00
maziggy
101288d1b2
Updated CI
2026-02-18 13:28:33 +01:00
maziggy
6ee25a2157
The only-labels: 'feedback' parameter tells the stale bot to only process issues that have the feedback label. All other issues (feature requests with future, bug
...
reports, etc.) will be left alone.
2026-02-16 08:35:43 +01:00
maziggy
1e5b263acb
Added -n auto to run tests in parallel via pytest-xdist
2026-02-10 17:57:40 +01:00
maziggy
23d539f284
Fix CI backend-tests failing to collect FTP test suite
...
CI only installed requirements.txt, missing pyOpenSSL from
requirements-dev.txt. This caused an ImportError on
TLS_FTPHandler during test collection, blocking all
unit/services tests. Also adds pytest-timeout to dev deps
instead of ad-hoc pip install in CI.
2026-02-10 17:49:58 +01:00
maziggy
cf19ac8d39
Added two steps to the docker-test job in ci.yml
2026-02-08 07:53:32 +01:00
maziggy
74e84277cf
Add CodeQL advanced setup workflow with accepted-risk exclusions
2026-02-06 13:25:23 +01:00
maziggy
46ba5ff417
Fix Bandit detection and update Trivy to v0.69.1
...
- Fix defusedxml import style in print_queue.py to be recognized by Bandit
(use `import defusedxml.ElementTree as ET` not `from defusedxml import`)
- Update Trivy scanner version from 0.65.0 to 0.69.1
2026-02-05 17:50:16 +01:00
maziggy
fc4f565eba
Update Trivy scanner to v0.69.1
...
Pin the latest Trivy scanner version for improved vulnerability detection.
2026-02-05 17:33:51 +01:00
maziggy
7841237d4e
Fixed Trivy workflow
2026-02-05 14:05:29 +01:00
maziggy
45e08b023a
Updated CI
2026-02-05 12:34:06 +01:00
maziggy
f9431ced0c
Updated CI
2026-02-05 12:24:52 +01:00
maziggy
c01839b2ce
Added Bandit and Trivy to CI
2026-02-05 12:18:00 +01:00
MartinNYHC
a91a9eacbf
Delete .github/workflows/codeql.yml
2026-02-04 16:07:37 +01:00
maziggy
bff7da2861
Updated all CodeQL actions to v4
2026-02-04 14:48:15 +01:00
maziggy
ab63fed637
Updated CI
2026-02-04 14:43:36 +01:00
maziggy
d2c720e70f
Updated CI
2026-01-29 15:10:34 +01:00
maziggy
86ad13398a
Updated CI
2026-01-29 13:31:07 +01:00
maziggy
54abee53f8
Updated Github workflow
2026-01-28 09:15:46 +01:00
maziggy
a1c59fd6cb
Updated the workflow:
...
- Changed stale-issue-label from feedback to stale (so stale issues get the "stale" label)
- Added remove-issue-labels: 'feedback' to remove the feedback label when issues are auto-closed
2026-01-28 07:13:35 +01:00
maziggy
56efb44c4f
Added explicit permissions: issues: write
2026-01-27 11:44:23 +01:00
maziggy
aa5ab135c7
Added stale issues workflow
2026-01-27 11:15:13 +01:00
maziggy
51df60cb91
Fixed CI
2026-01-26 15:53:54 +01:00
maziggy
580225a38d
Add security scanning to CI pipeline
...
- Add pip-audit check to PR workflow (non-blocking warning)
- Add npm audit check to PR workflow (non-blocking, high severity only)
- Create scheduled weekly security audit workflow that:
- Runs strict pip-audit and npm audit
- Creates/updates GitHub issues when vulnerabilities found
- Uploads audit results as artifacts
- Supports manual trigger via workflow_dispatch
2026-01-26 13:21:02 +01:00
maziggy
164d22f2bb
Add security scanning to CI pipeline
...
- Add pip-audit check to PR workflow (non-blocking warning)
- Add npm audit check to PR workflow (non-blocking warning)
- Create scheduled weekly security audit workflow that:
- Runs strict pip-audit and npm audit
- Creates/updates GitHub issues when vulnerabilities found
- Uploads audit results as artifacts
- Supports manual trigger via workflow_dispatch
2026-01-26 13:18:29 +01:00
maziggy
4babcf6187
Updated CI
2026-01-22 12:32:45 +01:00
maziggy
7bca0d733f
Fixed Github CI
2026-01-21 16:02:30 +01:00
maziggy
0d1056ded4
Added timeouts to Github CI runner
...
- Backend tests: 10 min (step-level)
- Frontend tests: 10 min (step-level)
- Docker tests: 20 min (job-level, since it has multiple build/test steps)
2026-01-21 15:27:24 +01:00
maziggy
8abfaa391a
Rename Docker Test job back to Docker Build for branch protection
2026-01-11 07:59:19 +01:00
maziggy and Claude Opus 4.5
02dbc5a84f
Add full Docker test suite to CI (matches test_docker.sh)
...
- Test 1: Build production image, verify imports & static files
- Test 2: Backend unit tests in Docker container
- Test 3: Frontend unit tests in Docker container
- Test 4: Integration tests (health, API, static files)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com >
2026-01-11 07:53:03 +01:00