Repository navigation
Fix GitHub Actions permissions and update dependencies - #49
Open
DrMattChristian wants to merge 21 commits into
Open
DrMattChristian wants to merge 21 commits into
DrMattChristian wants to merge 21 commits into
Conversation
…n permissions If a GitHub Actions job or workflow has no explicit permissions set, then the repository permissions are used. Repositories created under organizations inherit the organization permissions. The organizations or repositories created before February 2023 have the default permissions set to read-write. Often these permissions do not adhere to the principle of least privilege and can be reduced to read-only, leaving the write permission only to a specific types as issues: write or pull-requests: write. Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
…n permissions If a GitHub Actions job or workflow has no explicit permissions set, then the repository permissions are used. Repositories created under organizations inherit the organization permissions. The organizations or repositories created before February 2023 have the default permissions set to read-write. Often these permissions do not adhere to the principle of least privilege and can be reduced to read-only, leaving the write permission only to a specific types as issues: write or pull-requests: write. Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Bumps the go_modules group with 1 update in the / directory: [golang.org/x/crypto](https://github.com/golang/crypto). Updates `golang.org/x/crypto` from 0.41.0 to 0.45.0 - [Commits](golang/crypto@v0.41.0...v0.45.0) --- updated-dependencies: - dependency-name: golang.org/x/crypto dependency-version: 0.45.0 dependency-type: direct:production dependency-group: go_modules ... Signed-off-by: dependabot[bot] <support@github.com>
…/go_modules-dd7da38a6b # Conflicts: # go.mod # go.sum
…odules-dd7da38a6b Bump golang.org/x/crypto from 0.41.0 to 0.51.0 in the go_modules group across 1 directory
…by-commit-sha Pin all GitHub Actions to full-length commit SHAs
Add QEMU setup and publish linux/amd64 and linux/arm64 images so GHCR gets explicit platform metadata for ARM64 builds. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…ing-docker-metadata Build multi-arch container images
…-build-failure Fix Docker image publishing for forked and PR workflow runs
* Update GitHub Actions to Node 24 SHAs Enable manual dispatch for the Docker image workflow. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Use fallback build date for workflow_dispatch Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add manual docker tags and image description Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Make manual Docker tags unique across runs Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add manual docker tags and image description * Use a build-push action version with annotations support * Pin docker/build-push-action to a full SHA * Update frontend build image to Node 24 * Use dynamic image name in workflow
This updates the Docker DB service to a newer MySQL 8.4 patch release to avoid the startup crash seen with the previous tag. The compose example and install docs now match. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
This PR updates the project’s CI/CD workflows and container/runtime configuration to improve security (explicit permissions + pinned action SHAs), add flexibility for manual/multi-platform Docker builds, and align documentation/runtime versions (Node, MySQL).
Changes:
- Adds
workflow_dispatchsupport and more dynamic multi-platform build behavior in the Docker build workflow, and pins GitHub Actions dependencies by SHA. - Updates the Docker build to use newer Node/Alpine images and adds OCI image description metadata.
- Pins MySQL image version in
docker-compose.ymland docs for consistency.
Reviewed changes
Copilot reviewed 6 out of 6 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
.github/workflows/build.yml |
Adds manual dispatch + dynamic platforms/QEMU logic; pins actions; refines login/push/caching and adds metadata/annotations. |
.github/workflows/test.yml |
Adds explicit contents: read permissions; pins action SHAs for reproducibility. |
Dockerfile |
Updates Node/Alpine versions for the frontend stage; adds OCI description label. |
docker-compose.yml |
Pins MySQL image to 8.4.10. |
README.md |
Updates example compose snippet to use mysql:8.4.10. |
docs/INSTALL.md |
Updates installation compose snippet to use mysql:8.4.10. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
docker/build-push-action expects each annotation line to be scoped (e.g. index: / manifest:). docker/metadata-action will output the annotations exactly as provided here, so the current unscoped org.opencontainers.image.description=... line will likely be ignored (or fail) when passed to with.annotations in the build step. Add both index: and manifest: scopes so the description is applied for multi-platform (index) and single-platform (manifest) builds. Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
…cross 1 directory (#9) * Bump golang.org/x/net in the go_modules group across 1 directory Bumps the go_modules group with 1 update in the / directory: [golang.org/x/net](https://github.com/golang/net). Updates `golang.org/x/net` from 0.54.0 to 0.55.0 - [Commits](golang/net@v0.54.0...v0.55.0) --- updated-dependencies: - dependency-name: golang.org/x/net dependency-version: 0.55.0 dependency-type: direct:production dependency-group: go_modules ... Signed-off-by: dependabot[bot] <support@github.com> * Narrow x/net dependency bump Co-authored-by: DrMattChristian <15859944+DrMattChristian@users.noreply.github.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: DrMattChristian <15859944+DrMattChristian@users.noreply.github.com>
…p across 1 directory (#10) * Bump golang.org/x/crypto in the go_modules group across 1 directory Bumps the go_modules group with 1 update in the / directory: [golang.org/x/crypto](https://github.com/golang/crypto). Updates `golang.org/x/crypto` from 0.51.0 to 0.52.0 - [Commits](golang/crypto@v0.51.0...v0.52.0) --- updated-dependencies: - dependency-name: golang.org/x/crypto dependency-version: 0.52.0 dependency-type: direct:production dependency-group: go_modules ... Signed-off-by: dependabot[bot] <support@github.com> * Align crypto bump with reviewed target v0.52.0 Co-authored-by: DrMattChristian <15859944+DrMattChristian@users.noreply.github.com> * Revert v0.52 crypto pin and restore latest module set Co-authored-by: DrMattChristian <15859944+DrMattChristian@users.noreply.github.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: DrMattChristian <15859944+DrMattChristian@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request updates the CI/CD pipeline and Docker configuration to improve build flexibility, security, and documentation accuracy. The main changes include enhancements to the GitHub Actions workflows for building and testing, updates to Docker and Node.js versions, and documentation corrections.
CI/CD Workflow Improvements
.github/workflows/build.ymlfile now supports manual workflow dispatches with custom tags and platform selection, dynamic platform detection, and improved multi-platform build support with conditional QEMU setup. It also refines Docker registry login logic and adds detailed image annotations. [1] [2]build.ymlandtest.yml) update action references to use specific commit SHAs for improved security and reproducibility, and explicitly setcontents: readpermissions. [1] [2] [3]Dockerfile and Dependency Updates
Documentation and Configuration Updates
8.4.10indocker-compose.yml,README.md, anddocs/INSTALL.mdfor consistency and to avoid ambiguity. [1] [2] [3]