Skip to content

Fix GitHub Actions permissions and update dependencies - #49

Open
DrMattChristian wants to merge 21 commits into
StJudeWasHere:mainfrom
DrMattChristian:main
Open

DrMattChristian wants to merge 21 commits into
StJudeWasHere:mainfrom
DrMattChristian:main

Conversation

@DrMattChristian

Copy link
Copy Markdown
Contributor

This pull request updates the CI/CD pipeline and Docker configuration to improve build flexibility, security, and documentation accuracy. The main changes include enhancements to the GitHub Actions workflows for building and testing, updates to Docker and Node.js versions, and documentation corrections.

CI/CD Workflow Improvements

  • Enhanced Docker build workflow: The .github/workflows/build.yml file now supports manual workflow dispatches with custom tags and platform selection, dynamic platform detection, and improved multi-platform build support with conditional QEMU setup. It also refines Docker registry login logic and adds detailed image annotations. [1] [2]
  • Updated action versions and permissions: Both the build and test workflows (build.yml and test.yml) update action references to use specific commit SHAs for improved security and reproducibility, and explicitly set contents: read permissions. [1] [2] [3]

Dockerfile and Dependency Updates

  • Node.js and Dockerfile improvements: The Dockerfile now uses Node.js 24 (up from 18) and Alpine 3.22 for the frontend build, and adds an Open Containers image description label for better metadata. [1] [2]

Documentation and Configuration Updates

  • MySQL version pinning: Updates the MySQL image version to 8.4.10 in docker-compose.yml, README.md, and docs/INSTALL.md for consistency and to avoid ambiguity. [1] [2] [3]

DrMattChristian and others added 18 commits September 17, 2025 14:21
…n permissions

If a GitHub Actions job or workflow has no explicit permissions set, then the repository permissions are used. Repositories created under organizations inherit the organization permissions. The organizations or repositories created before February 2023 have the default permissions set to read-write. Often these permissions do not adhere to the principle of least privilege and can be reduced to read-only, leaving the write permission only to a specific types as issues: write or pull-requests: write.

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
…n permissions

If a GitHub Actions job or workflow has no explicit permissions set, then the repository permissions are used. Repositories created under organizations inherit the organization permissions. The organizations or repositories created before February 2023 have the default permissions set to read-write. Often these permissions do not adhere to the principle of least privilege and can be reduced to read-only, leaving the write permission only to a specific types as issues: write or pull-requests: write.

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Bumps the go_modules group with 1 update in the / directory: [golang.org/x/crypto](https://github.com/golang/crypto).


Updates `golang.org/x/crypto` from 0.41.0 to 0.45.0
- [Commits](golang/crypto@v0.41.0...v0.45.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-version: 0.45.0
  dependency-type: direct:production
  dependency-group: go_modules
...

Signed-off-by: dependabot[bot] <support@github.com>
…/go_modules-dd7da38a6b

# Conflicts:
#	go.mod
#	go.sum
…odules-dd7da38a6b

Bump golang.org/x/crypto from 0.41.0 to 0.51.0 in the go_modules group across 1 directory
…by-commit-sha

Pin all GitHub Actions to full-length commit SHAs
Add QEMU setup and publish linux/amd64 and linux/arm64 images so GHCR gets explicit platform metadata for ARM64 builds.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…ing-docker-metadata

Build multi-arch container images
…-build-failure

Fix Docker image publishing for forked and PR workflow runs
* Update GitHub Actions to Node 24 SHAs

Enable manual dispatch for the Docker image workflow.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Use fallback build date for workflow_dispatch

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add manual docker tags and image description

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Make manual Docker tags unique across runs

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add manual docker tags and image description
* Use a build-push action version with annotations support
* Pin docker/build-push-action to a full SHA
* Update frontend build image to Node 24
* Use dynamic image name in workflow
This updates the Docker DB service to a newer MySQL 8.4 patch release to avoid the startup crash seen with the previous tag. The compose example and install docs now match.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@DrMattChristian
DrMattChristian marked this pull request as ready for review June 26, 2026 13:06
Copilot AI review requested due to automatic review settings June 26, 2026 13:06

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the project’s CI/CD workflows and container/runtime configuration to improve security (explicit permissions + pinned action SHAs), add flexibility for manual/multi-platform Docker builds, and align documentation/runtime versions (Node, MySQL).

Changes:

  • Adds workflow_dispatch support and more dynamic multi-platform build behavior in the Docker build workflow, and pins GitHub Actions dependencies by SHA.
  • Updates the Docker build to use newer Node/Alpine images and adds OCI image description metadata.
  • Pins MySQL image version in docker-compose.yml and docs for consistency.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
.github/workflows/build.yml Adds manual dispatch + dynamic platforms/QEMU logic; pins actions; refines login/push/caching and adds metadata/annotations.
.github/workflows/test.yml Adds explicit contents: read permissions; pins action SHAs for reproducibility.
Dockerfile Updates Node/Alpine versions for the frontend stage; adds OCI description label.
docker-compose.yml Pins MySQL image to 8.4.10.
README.md Updates example compose snippet to use mysql:8.4.10.
docs/INSTALL.md Updates installation compose snippet to use mysql:8.4.10.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .github/workflows/build.yml Outdated
DrMattChristian and others added 3 commits June 26, 2026 09:00
docker/build-push-action expects each annotation line to be scoped (e.g. index: / manifest:). docker/metadata-action will output the annotations exactly as provided here, so the current unscoped org.opencontainers.image.description=... line will likely be ignored (or fail) when passed to with.annotations in the build step. Add both index: and manifest: scopes so the description is applied for multi-platform (index) and single-platform (manifest) builds.

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
…cross 1 directory (#9)

* Bump golang.org/x/net in the go_modules group across 1 directory

Bumps the go_modules group with 1 update in the / directory: [golang.org/x/net](https://github.com/golang/net).


Updates `golang.org/x/net` from 0.54.0 to 0.55.0
- [Commits](golang/net@v0.54.0...v0.55.0)

---
updated-dependencies:
- dependency-name: golang.org/x/net
  dependency-version: 0.55.0
  dependency-type: direct:production
  dependency-group: go_modules
...

Signed-off-by: dependabot[bot] <support@github.com>

* Narrow x/net dependency bump

Co-authored-by: DrMattChristian <15859944+DrMattChristian@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: DrMattChristian <15859944+DrMattChristian@users.noreply.github.com>
…p across 1 directory (#10)

* Bump golang.org/x/crypto in the go_modules group across 1 directory

Bumps the go_modules group with 1 update in the / directory: [golang.org/x/crypto](https://github.com/golang/crypto).


Updates `golang.org/x/crypto` from 0.51.0 to 0.52.0
- [Commits](golang/crypto@v0.51.0...v0.52.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-version: 0.52.0
  dependency-type: direct:production
  dependency-group: go_modules
...

Signed-off-by: dependabot[bot] <support@github.com>

* Align crypto bump with reviewed target v0.52.0

Co-authored-by: DrMattChristian <15859944+DrMattChristian@users.noreply.github.com>

* Revert v0.52 crypto pin and restore latest module set

Co-authored-by: DrMattChristian <15859944+DrMattChristian@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: DrMattChristian <15859944+DrMattChristian@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants