Compare commits

..

11 Commits

Author SHA1 Message Date
renovate-bot b83aa96a93 chore(deps): update github/codeql-action action to v4
Security / scan (pull_request) Successful in 18s
2026-05-11 00:34:11 +00:00
JonKazama-Hellion 32f4c92f1b Merge pull request 'chore(deps): update actions/dependency-review-action action to v5' (#7) from renovate/actions-dependency-review-action-5.x into master
Security / scan (push) Failing after 11s
Reviewed-on: #7
2026-05-10 20:37:28 +00:00
renovate-bot 4c7a33a6fa chore(deps): update actions/dependency-review-action action to v5 2026-05-10 20:37:28 +00:00
JonKazama-Hellion 9eb0bc1c3e Merge pull request 'chore(deps): pin dependencies' (#5) from renovate/pin-dependencies into master
Security / scan (push) Successful in 17s
Reviewed-on: #5
2026-05-10 20:36:46 +00:00
renovate-bot 0fb0eec7df chore(deps): pin dependencies
Security / scan (pull_request) Successful in 28s
2026-05-10 12:33:03 +00:00
JonKazama-Hellion 0d4708bf11 chore(config): migrate Renovate config (#3)
Security / scan (push) Successful in 27s
Auto-merge: Renovate config migration (matchPackagePrefixes -> matchPackageNames).
2026-05-09 15:46:45 +00:00
renovate-bot f2b070e201 chore(config): migrate config renovate.json
Security / scan (pull_request) Successful in 24s
2026-05-09 15:41:56 +00:00
JonKazama-Hellion 8176f91d4c Merge pull request 'chore: Configure Renovate' (#1) from renovate/configure into master
Security / scan (push) Successful in 17s
Reviewed-on: #1
2026-05-09 10:32:11 +00:00
JonKazama-Hellion d68bb35e7a renovate.json aktualisiert
Signed-off-by: Jon Kazama <kontakt@hellion-media.de>
2026-05-09 10:32:11 +00:00
renovate-bot 10c70f8bf9 Add renovate.json 2026-05-09 10:32:11 +00:00
JonKazama-Hellion 28b9061756 chore: add reusable security scan workflow
Security / scan (push) Failing after 11s
Calls JonKazama-Hellion/security-workflows for Semgrep SAST + Trivy
filesystem vulnerability scan. Runs on push to main/master, on every
PR, and weekly Monday 06:00 UTC.
2026-05-09 11:28:10 +02:00
5 changed files with 26 additions and 11 deletions
+13
View File
@@ -0,0 +1,13 @@
name: Security
on:
push:
branches: [main, master]
pull_request:
schedule:
- cron: '0 6 * * 1'
workflow_dispatch:
jobs:
scan:
uses: JonKazama-Hellion/security-workflows/.gitea/workflows/security-scan.yml@main
+1 -1
View File
@@ -16,7 +16,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- name: Projektstruktur prüfen
run: |
+2 -2
View File
@@ -15,7 +15,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- name: Extract version from tag
id: version
@@ -53,7 +53,7 @@ jobs:
cat checksums-sha256.txt
- name: Create GitHub Release
uses: softprops/action-gh-release@v2
uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2
with:
name: "Hellion NewTab ${{ steps.version.outputs.tag }}"
body: |
+5 -5
View File
@@ -20,15 +20,15 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
uses: github/codeql-action/init@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4
with:
languages: javascript
- name: Run CodeQL Analysis
uses: github/codeql-action/analyze@v3
uses: github/codeql-action/analyze@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4
dependency-review:
name: Dependency Review
@@ -36,7 +36,7 @@ jobs:
if: github.event_name == 'pull_request'
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- name: Dependency Review
uses: actions/dependency-review-action@v4
uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0
+5 -3
View File
@@ -26,8 +26,10 @@
},
{
"description": "TypeScript type definitions stay grouped with each other",
"matchPackagePrefixes": ["@types/"],
"groupName": "type definitions"
"groupName": "type definitions",
"matchPackageNames": [
"@types/{/,}**"
]
},
{
"description": "Dev dependencies in their own group",
@@ -51,4 +53,4 @@
"commitMessageAction": "Refresh"
},
"osvVulnerabilityAlerts": true
}
}