Commit Graph
74 Commits
Author SHA1 Message Date
maziggy fdd20e49b3 chore(security): bump idna >=3.15 (CVE-2026-45409) + ignore disputed PyJWT advisory
- requirements.txt: pin idna>=3.15 to clear ReDoS in idna.encode() on
    crafted Unicode payloads. Transitive via anyio/httpx/requests/yarl,
    so the explicit floor stops a future downstream loosening from
    silently downgrading us.
  - security.yml: permanently --ignore-vuln CVE-2025-45768 (PyJWT). The
    advisory is disputed by the maintainers — "key length is chosen by
    the application" — and no fix version exists. Bambuddy is safe:
    auto-generates secrets via secrets.token_urlsafe(64) and rejects
    file-loaded secrets shorter than 32 chars (auth.py:177, :184).
  - security.yml: drop the stale Pygments --ignore-vuln CVE-2026-4539.
    Pygments has been patched upstream; the ignore no longer matches
    anything.
2026-05-20 12:56:22 +02:00
maziggy 46468c9602 Updated .github/workflows/cleanup-ghcr.yml 2026-05-01 11:49:46 +02:00
maziggy 44e4b6b5d7 Workflow: .github/workflows/cleanup-ghcr.yml runs Sundays at 03:00 UTC across both packages, with a manual workflow_dispatch and a dry_run toggle. It builds the live-digest
set the same way we just did, so it won't ever delete a digest still referenced by a tagged manifest.
2026-05-01 09:41:01 +02:00
maziggy f45f6a131d Updated Github issue template 2026-04-29 13:08:16 +02:00
maziggy 62f2e616a0 Changed CI 2026-04-23 08:57:15 +02:00
maziggy a4c7d6d5cf Updated issue template 2026-04-20 15:10:59 +02:00
maziggy a58ab8b8db Updated .github/workflows/ci.yml 2026-04-12 15:05:28 +02:00
maziggy 4c27ee680b docs: require companion docs PRs for user-visible changes 2026-04-10 15:20:02 +02:00
maziggy d29688000f Updated CI 2026-04-07 17:16:48 +02:00
maziggy 0b0ab23052 Added stats CI 2026-04-07 16:19:42 +02:00
maziggy 240b6cb408 Added stats CI 2026-04-07 16:11:43 +02:00
maziggy fd140e3c64 Added stats CI 2026-04-07 16:08:54 +02:00
maziggy 39a7898e52 Added Spoolbuddy options to Github issue template 2026-03-30 12:46:43 +02:00
maziggy 7841d2f997 Housekeeping 2026-03-26 14:20:11 +01:00
maziggy ba991702e5 Housekeeping 2026-03-26 14:08:10 +01:00
maziggy ac75d4957f Changed pipeline 2026-03-26 13:52:52 +01:00
maziggy deecc8b7dc Updated .github/workflows/security.yml 2026-03-20 11:07:08 +01:00
maziggy 97d8108ba6 Updated .github/ISSUE_TEMPLATE/bug_report.yml 2026-03-14 12:10:46 +01:00
maziggy c2cf041af2 Update CI Node.js version from 20 to 22 LTS
Node 20 is being deprecated on GitHub Actions runners.
  Bump to Node 22 (Active LTS) in ci.yml and security.yml.
2026-03-13 15:34:22 +01:00
maziggy b4b8758b13 Uodated issue template 2026-02-28 13:10:28 +01:00
MartinNYHC 18f43e46ac Make version check mandatory in bug report template 2026-02-24 17:50:20 +01:00
maziggy 60f1be8935 Updated .github/ISSUE_TEMPLATE/bug_report.yml 2026-02-24 16:49:13 +01:00
maziggy 3dc9ebcb6c Updated .github/ISSUE_TEMPLATE/bug_report.yml 2026-02-24 16:47:50 +01:00
maziggy b7cc68122b Both workflows now parse package-lock.json directly instead of trusting npm ls. The lockfile correctly marks minimatch as dev: true and doesn't contain npm/tar at all —
so all three npm-internal packages will be filtered out regardless of which npm version CI uses.
2026-02-20 19:31:41 +01:00
maziggy fce89490f7 Updated CI 2026-02-20 19:22:32 +01:00
maziggy fea89a7ece Updated CI 2026-02-20 19:18:59 +01:00
maziggy 63b668f0ed Updated CI 2026-02-20 19:10:26 +01:00
maziggy 6ab48fa338 Updated CI 2026-02-20 18:28:34 +01:00
maziggy 4cb80a4335 Housekeeping 2026-02-19 16:32:44 +01:00
maziggy fbf676a77f Updated CI 2026-02-18 18:08:07 +01:00
maziggy c0948f7868 Updated CI 2026-02-18 17:47:29 +01:00
maziggy 2bfb9d22c5 Updated CI 2026-02-18 17:26:09 +01:00
maziggy 289dc2d5d6 Updated CI 2026-02-18 13:28:11 +01:00
maziggy bd84f8d87a Housekeeping 2026-02-17 08:57:27 +01:00
maziggy 6ee25a2157 The only-labels: 'feedback' parameter tells the stale bot to only process issues that have the feedback label. All other issues (feature requests with future, bug
reports, etc.) will be left alone.
2026-02-16 08:35:43 +01:00
maziggy 1e5b263acb Added -n auto to run tests in parallel via pytest-xdist 2026-02-10 17:57:40 +01:00
maziggy 23d539f284 Fix CI backend-tests failing to collect FTP test suite
CI only installed requirements.txt, missing pyOpenSSL from
requirements-dev.txt. This caused an ImportError on
TLS_FTPHandler during test collection, blocking all
unit/services tests. Also adds pytest-timeout to dev deps
instead of ad-hoc pip install in CI.
2026-02-10 17:49:58 +01:00
maziggy cf19ac8d39 Added two steps to the docker-test job in ci.yml 2026-02-08 07:53:32 +01:00
maziggy 74e84277cf Add CodeQL advanced setup workflow with accepted-risk exclusions 2026-02-06 13:25:23 +01:00
maziggy 46ba5ff417 Fix Bandit detection and update Trivy to v0.69.1
- Fix defusedxml import style in print_queue.py to be recognized by Bandit
  (use `import defusedxml.ElementTree as ET` not `from defusedxml import`)
- Update Trivy scanner version from 0.65.0 to 0.69.1
2026-02-05 17:50:16 +01:00
maziggy fc4f565eba Update Trivy scanner to v0.69.1
Pin the latest Trivy scanner version for improved vulnerability detection.
2026-02-05 17:33:51 +01:00
maziggy 7841237d4e Fixed Trivy workflow 2026-02-05 14:05:29 +01:00
maziggy 45e08b023a Updated CI 2026-02-05 12:34:06 +01:00
maziggy f9431ced0c Updated CI 2026-02-05 12:24:52 +01:00
maziggy c01839b2ce Added Bandit and Trivy to CI 2026-02-05 12:18:00 +01:00
maziggy 861cc006d4 Changed issue templates 2026-02-05 09:05:25 +01:00
MartinNYHC a91a9eacbf Delete .github/workflows/codeql.yml 2026-02-04 16:07:37 +01:00
maziggy bff7da2861 Updated all CodeQL actions to v4 2026-02-04 14:48:15 +01:00
maziggy ab63fed637 Updated CI 2026-02-04 14:43:36 +01:00
maziggy e87fe7ad87 Add H2D Pro printer model support
- Add H2D Pro option to printer model dropdowns (add/edit modals)
- Support both O1E and O2D internal codes for H2D Pro compatibility
- Add O2D to RTSP-capable and chamber temp supported models
- Add H2DPRO variant to firmware check mapping
- Add H2D Pro and X1E to bug report issue template

Closes #192
2026-01-30 15:38:52 +01:00