Compare commits

..
6 Commits
Author SHA1 Message Date
renovate-bot 6838b3833e chore(deps): update minor and patch updates (nuget)
Security / Security Scan (pull_request) Failing after 24s
Build / Build (Release) (pull_request) Successful in 37s
2026-08-15 21:12:53 +00:00
JonKazama-Hellion d50f2cea90 fix(ci): security-scan inline statt reusable workflow
Security / Security Scan (push) Failing after 21s
Build / Build (Release) (push) Failing after 34s
act_runner laedt reusable workflows per git-clone ueber HTTPS. Dieser Pfad
ist auf der Forge seit 2026-08-12 defekt (git upload-pack --stateless-rpc
bricht mit BUG "packfile_uris requires sideband-all" ab). Die Scans liefen
bisher nur ueber eine im Juni gecachte Kopie im Runner.

Der Scan steht jetzt vollstaendig in dieser Datei, der Quellstand kommt als
tar-Archiv statt ueber actions/checkout. Zurueckbauen, sobald git fetch
ueber HTTPS wieder funktioniert.
2026-08-15 17:26:51 +00:00
JonKazama-Hellion 99901b64ed Merge pull request 'chore(deps): update minor and patch updates (nuget)' (#17) from renovate/minor-and-patch-updates-(nuget) into main
Security / scan (push) Successful in 21s
Build / Build (Release) (push) Successful in 30s
Reviewed-on: #17
2026-06-03 06:07:06 +00:00
renovate-bot 7ef1337ea0 chore(deps): update minor and patch updates (nuget)
Security / scan (pull_request) Successful in 20s
Build / Build (Release) (pull_request) Successful in 26s
2026-06-03 06:06:55 +00:00
JonKazama-Hellion a13713752e Merge pull request 'chore(deps): update actions/setup-dotnet digest to 9a946fd' (#19) from renovate/actions-setup-dotnet-digest into main
Security / scan (push) Successful in 21s
Build / Build (Release) (push) Successful in 27s
Reviewed-on: #19
2026-06-03 06:06:11 +00:00
renovate-bot a9f42e32c5 chore(deps): update actions/setup-dotnet digest to 9a946fd
Security / scan (pull_request) Successful in 29s
Build / Build (Release) (pull_request) Successful in 45s
2026-06-01 00:32:04 +00:00
6 changed files with 101 additions and 38 deletions
+1 -1
View File
@@ -35,7 +35,7 @@ jobs:
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
- name: Setup .NET 10 - name: Setup .NET 10
uses: actions/setup-dotnet@c2fa09f4bde5ebb9d1777cf28262a3eb3db3ced7 # v5 uses: actions/setup-dotnet@9a946fdbd5fb07b82b2f5a4466058b876ab72bb2 # v5
with: with:
dotnet-version: 10.0.x dotnet-version: 10.0.x
+1 -1
View File
@@ -54,7 +54,7 @@ jobs:
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
- name: Setup .NET 10 - name: Setup .NET 10
uses: actions/setup-dotnet@c2fa09f4bde5ebb9d1777cf28262a3eb3db3ced7 # v5 uses: actions/setup-dotnet@9a946fdbd5fb07b82b2f5a4466058b876ab72bb2 # v5
with: with:
dotnet-version: 10.0.x dotnet-version: 10.0.x
+71 -8
View File
@@ -1,4 +1,21 @@
name: Security name: Security
# Self-contained security scan: Semgrep SAST + Trivy filesystem scan.
#
# Deliberately NOT calling the reusable workflow in security-workflows:
# act_runner fetches reusable workflows by cloning them over HTTPS, and git
# fetch over HTTPS is broken on this Gitea instance since 2026-08-12
# (`git upload-pack --stateless-rpc` aborts with
# BUG("packfile_uris requires sideband-all") and dumps core). The runner only
# kept working because it still had a June copy in its action cache. Inlining
# removes that dependency entirely.
#
# For the same reason the sources are pulled as a tar archive instead of via
# actions/checkout. Restore the reusable call once the fetch path is fixed.
#
# Why one job, not two parallel jobs: act_runner v0.6.1 has a race when two
# jobs in the same task share a workspace and chown it in parallel.
on: on:
push: push:
branches: [main, master] branches: [main, master]
@@ -7,14 +24,60 @@ on:
- cron: '0 6 * * 1' - cron: '0 6 * * 1'
workflow_dispatch: workflow_dispatch:
env:
TRIVY_SEVERITY: 'CRITICAL,HIGH'
# MessageStore.cs interpoliert SQL-Strings, die plugin-lokal sicher sind;
# Semgrep matcht das Pattern, CodeQL mit Datenflussanalyse nicht.
SEMGREP_EXCLUDE_RULES: 'csharp.lang.security.sqli.csharp-sqli.csharp-sqli'
jobs: jobs:
scan: scan:
uses: JonKazama-Hellion/security-workflows/.gitea/workflows/security-scan.yml@main name: Security Scan
runs-on: ubuntu-latest
steps:
- name: Checkout sources
env:
TOKEN: ${{ github.token }}
# On pull_request the merge SHA may not be archivable, use the head.
REF: ${{ github.event.pull_request.head.sha || github.sha }}
SERVER: ${{ github.server_url }}
REPO: ${{ github.repository }}
run: |
set -eu
echo "Fetching archive for $REPO @ $REF"
curl -sfL --retry 3 --retry-delay 5 \
-H "Authorization: token $TOKEN" \
"$SERVER/$REPO/archive/$REF.tar.gz" -o /tmp/source.tar.gz
tar xzf /tmp/source.tar.gz --strip-components=1
rm -f /tmp/source.tar.gz
echo "Extracted $(find . -type f | wc -l) files"
- name: Set up Python
uses: actions/setup-python@v6
with: with:
# MessageStore.cs uses string-interpolation in CommandText for table python-version: '3.x'
# names and clause-joins that come from internal code constants, not
# user input. Values are bound via SqlParameter, the SQL surface is - name: Install Semgrep
# local-only inside a Dalamud plugin. Semgrep matches the pattern run: pip install --no-cache-dir semgrep
# without dataflow, so it flags those eight call sites; CodeQL
# would not. Suppressed for this repo only. - name: Install Trivy
semgrep-exclude-rules: 'csharp.lang.security.sqli.csharp-sqli.csharp-sqli' # Version pinned so the install script does not hit api.github.com to
# resolve "latest", which burns the runner's unauthenticated rate limit.
# renovate: datasource=github-releases depName=aquasecurity/trivy
run: curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sudo sh -s -- -b /usr/local/bin v0.70.0
- name: Run Semgrep SAST
run: |
args="--config=auto --error --severity=ERROR"
if [ -n "$SEMGREP_EXCLUDE_RULES" ]; then
for rule in $(echo "$SEMGREP_EXCLUDE_RULES" | tr ',' ' '); do
args="$args --exclude-rule=$rule"
done
fi
echo "Running: semgrep scan $args"
semgrep scan $args
- name: Run Trivy filesystem scan
# if: always() — surface Trivy findings even when Semgrep fails first.
if: always()
run: trivy fs --severity "$TRIVY_SEVERITY" --exit-code 1 --ignore-unfixed .
+2 -2
View File
@@ -14,7 +14,7 @@
<ItemGroup> <ItemGroup>
<!-- Closed ranges prevent surprise major bumps during lock file regeneration --> <!-- Closed ranges prevent surprise major bumps during lock file regeneration -->
<PackageReference Include="MessagePack" Version="[3.1.4, 4.0.0)" /> <PackageReference Include="MessagePack" Version="[3.1.4, 4.0.0)" />
<PackageReference Include="Microsoft.Data.Sqlite" Version="10.0.7" /> <PackageReference Include="Microsoft.Data.Sqlite" Version="10.0.11" />
<!-- v1.5.0 DI-container foundation; matches Lightless pin (Hosting 10.0.7) --> <!-- v1.5.0 DI-container foundation; matches Lightless pin (Hosting 10.0.7) -->
<PackageReference <PackageReference
Include="Microsoft.Extensions.DependencyInjection" Include="Microsoft.Extensions.DependencyInjection"
@@ -30,7 +30,7 @@
Media-Foundation-based codecs do not). Using the sub-package avoids pulling in Media-Foundation-based codecs do not). Using the sub-package avoids pulling in
NAudio.WinForms (which requires WindowsDesktop and does not build on Linux hosts). NAudio.WinForms (which requires WindowsDesktop and does not build on Linux hosts).
WaveOutEvent and WaveFileReader both live in NAudio.WinMM + NAudio.Core. --> WaveOutEvent and WaveFileReader both live in NAudio.WinMM + NAudio.Core. -->
<PackageReference Include="NAudio.WinMM" Version="2.2.1" /> <PackageReference Include="NAudio.WinMM" Version="2.3.0" />
<PackageReference Include="Pidgin" Version="[3.5.1, 4.0.0)" /> <PackageReference Include="Pidgin" Version="[3.5.1, 4.0.0)" />
<PackageReference Include="SixLabors.ImageSharp" Version="[3.1.12, 4.0.0)" /> <PackageReference Include="SixLabors.ImageSharp" Version="[3.1.12, 4.0.0)" />
</ItemGroup> </ItemGroup>
+24 -24
View File
@@ -27,13 +27,13 @@
}, },
"Microsoft.Data.Sqlite": { "Microsoft.Data.Sqlite": {
"type": "Direct", "type": "Direct",
"requested": "[10.0.7, )", "requested": "[10.0.11, )",
"resolved": "10.0.7", "resolved": "10.0.11",
"contentHash": "DZ6G2QuyPrsh5VS+wfiZbNBtYT6p+CkxXjD0aZHF04xso7QsG/uk0JpG30hzYlK6u/wtTzta1Dqfgbc/Sl2sDA==", "contentHash": "7je7UELzm131GiLYc4PpZvfKXIgIyzPM+v+tjcd/nbnuWRfgcONYKzDTqJlURxwVCFsVnlpmq6y6yn4qvR8QXQ==",
"dependencies": { "dependencies": {
"Microsoft.Data.Sqlite.Core": "10.0.7", "Microsoft.Data.Sqlite.Core": "10.0.11",
"SQLitePCLRaw.bundle_e_sqlite3": "2.1.11", "SQLitePCLRaw.bundle_e_sqlite3": "2.1.12",
"SQLitePCLRaw.core": "2.1.11" "SQLitePCLRaw.core": "2.1.12"
} }
}, },
"Microsoft.Extensions.DependencyInjection": { "Microsoft.Extensions.DependencyInjection": {
@@ -104,11 +104,11 @@
}, },
"NAudio.WinMM": { "NAudio.WinMM": {
"type": "Direct", "type": "Direct",
"requested": "[2.2.1, )", "requested": "[2.3.0, )",
"resolved": "2.2.1", "resolved": "2.3.0",
"contentHash": "xFHRFwH4x6aq3IxRbewvO33ugJRvZFEOfO62i7uQJRUNW2cnu6BeBTHUS0JD5KBucZbHZaYqxQG8dwZ47ezQuQ==", "contentHash": "5G1dRjsZm50T3luyuqcmI2BSvj3K4ZJaD/x776/0Epj88qOsOryDZG40+MufwIk1UFJSFWhRobBqtJYFc8Ss4g==",
"dependencies": { "dependencies": {
"NAudio.Core": "2.2.1" "NAudio.Core": "2.3.0"
} }
}, },
"Pidgin": { "Pidgin": {
@@ -141,10 +141,10 @@
}, },
"Microsoft.Data.Sqlite.Core": { "Microsoft.Data.Sqlite.Core": {
"type": "Transitive", "type": "Transitive",
"resolved": "10.0.7", "resolved": "10.0.11",
"contentHash": "xVrtBg3M1wJlBDkoT0dXEYB/wSc8bIHJPYtw/bu1AqpWgF79uPSs87DAhERR/Ilumre6TKZa1cjMg3VUUObVLA==", "contentHash": "hubA20AGenQ4Sx0ElWaPpB8DISjXpdx463+1zOGRslsT0e/t/06ITv+pHsop8CcJ0d8PZLfgnT7juCDVD79Dkw==",
"dependencies": { "dependencies": {
"SQLitePCLRaw.core": "2.1.11" "SQLitePCLRaw.core": "2.1.12"
} }
}, },
"Microsoft.Extensions.Configuration": { "Microsoft.Extensions.Configuration": {
@@ -377,29 +377,29 @@
}, },
"NAudio.Core": { "NAudio.Core": {
"type": "Transitive", "type": "Transitive",
"resolved": "2.2.1", "resolved": "2.3.0",
"contentHash": "GgkdP6K/7FqXFo7uHvoqGZTJvW4z8g2IffhOO4JHaLzKCdDOUEzVKtveoZkCuUX8eV2HAINqi7VFqlFndrnz/g==" "contentHash": "jMd7r6dB6tAtXhOYL58ntPqwERNm1/Rhw5MKOIYvsnXzuX+PTGsa2VMam6n0npZYSwlSidKa4GAm4bFcXFUlcg=="
}, },
"SQLitePCLRaw.bundle_e_sqlite3": { "SQLitePCLRaw.bundle_e_sqlite3": {
"type": "Transitive", "type": "Transitive",
"resolved": "2.1.11", "resolved": "2.1.12",
"contentHash": "DC4nA7yWnf4UZdgJDF+9Mus4/cb0Y3Sfgi3gDnAoKNAIBwzkskNAbNbyu+u4atT0ruVlZNJfwZmwiEwE5oz9LQ==", "contentHash": "mAgscpQMLw5/nfA1Q5oJVAT29yROUo1ifZGbbTpx/lwZpSxMUGoYbKfmvdm8oXER+RzxqBmmQzeBEVKfeHv2nw==",
"dependencies": { "dependencies": {
"SQLitePCLRaw.lib.e_sqlite3": "2.1.11", "SQLitePCLRaw.lib.e_sqlite3": "2.1.12",
"SQLitePCLRaw.provider.e_sqlite3": "2.1.11" "SQLitePCLRaw.provider.e_sqlite3": "2.1.12"
} }
}, },
"SQLitePCLRaw.core": { "SQLitePCLRaw.core": {
"type": "Transitive", "type": "Transitive",
"resolved": "2.1.11", "resolved": "2.1.12",
"contentHash": "PK0GLFkfhZzLQeR3PJf71FmhtHox+U3vcY6ZtswoMjrefkB9k6ErNJEnwXqc5KgXDSjige2XXrezqS39gkpQKA==" "contentHash": "ETpNw9DY3ckWLgRRAeCHj+GKOuPi61aeczkXhgHexUvqoZBAYg8RYESE2J7O1M7+o6QbdSEZwrw9bfqztUVWXg=="
}, },
"SQLitePCLRaw.provider.e_sqlite3": { "SQLitePCLRaw.provider.e_sqlite3": {
"type": "Transitive", "type": "Transitive",
"resolved": "2.1.11", "resolved": "2.1.12",
"contentHash": "Y/0ZkR+r0Cg3DQFuCl1RBnv/tmxpIZRU3HUvelPw6MVaKHwYYR8YNvgs0vuNuXCMvlyJ+Fh88U1D4tah1tt6qw==", "contentHash": "W3oH4XIfCzFrgUSDKHhN6N+dgzA5YHOR2VxX8GB6Qy7CyrJJgxPEG8NirgYWlPQC5P2jz2knSsexWu4tDUL33g==",
"dependencies": { "dependencies": {
"SQLitePCLRaw.core": "2.1.11" "SQLitePCLRaw.core": "2.1.12"
} }
}, },
"System.Diagnostics.EventLog": { "System.Diagnostics.EventLog": {
+1 -1
View File
@@ -4,7 +4,7 @@
"isRoot": true, "isRoot": true,
"tools": { "tools": {
"csharpier": { "csharpier": {
"version": "1.2.6", "version": "1.3.0",
"commands": ["csharpier"], "commands": ["csharpier"],
"rollForward": false "rollForward": false
} }