dependabot[bot]
16c28ea2f2
Bump the actions group across 1 directory with 2 updates
...
Bumps the actions group with 2 updates in the / directory: [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action ) and [actions/setup-node](https://github.com/actions/setup-node ).
Updates `aquasecurity/trivy-action` from 0.35.0 to 0.36.0
- [Release notes](https://github.com/aquasecurity/trivy-action/releases )
- [Commits](57a97c7e78...ed142fd067 )
Updates `actions/setup-node` from 6.3.0 to 6.4.0
- [Release notes](https://github.com/actions/setup-node/releases )
- [Commits](53b83947a5...48b55a011b )
---
updated-dependencies:
- dependency-name: actions/setup-node
dependency-version: 6.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: aquasecurity/trivy-action
dependency-version: 0.36.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-30 05:24:13 +00:00
nicolargo
a3771ce0cd
Improve WevUI workflow
2026-04-18 14:40:08 +02:00
dependabot[bot]
9f782b5d26
Bump the actions group with 10 updates
...
Bumps the actions group with 10 updates:
| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout ) | `5.0.1` | `6.0.2` |
| [actions/upload-artifact](https://github.com/actions/upload-artifact ) | `4.6.2` | `7.0.0` |
| [actions/download-artifact](https://github.com/actions/download-artifact ) | `5.0.0` | `8.0.1` |
| [docker/metadata-action](https://github.com/docker/metadata-action ) | `5.10.0` | `6.0.0` |
| [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action ) | `3.7.0` | `4.0.0` |
| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action ) | `3.12.0` | `4.0.0` |
| [docker/login-action](https://github.com/docker/login-action ) | `3.7.0` | `4.0.0` |
| [docker/build-push-action](https://github.com/docker/build-push-action ) | `6.19.2` | `7.0.0` |
| [github/codeql-action](https://github.com/github/codeql-action ) | `3.32.6` | `4.32.6` |
| [actions/setup-node](https://github.com/actions/setup-node ) | `5.0.0` | `6.3.0` |
Updates `actions/checkout` from 5.0.1 to 6.0.2
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](93cb6efe18...de0fac2e45 )
Updates `actions/upload-artifact` from 4.6.2 to 7.0.0
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](ea165f8d65...bbbca2ddaa )
Updates `actions/download-artifact` from 5.0.0 to 8.0.1
- [Release notes](https://github.com/actions/download-artifact/releases )
- [Commits](634f93cb29...3e5f45b2cf )
Updates `docker/metadata-action` from 5.10.0 to 6.0.0
- [Release notes](https://github.com/docker/metadata-action/releases )
- [Commits](c299e40c65...030e881283 )
Updates `docker/setup-qemu-action` from 3.7.0 to 4.0.0
- [Release notes](https://github.com/docker/setup-qemu-action/releases )
- [Commits](c7c5346462...ce360397dd )
Updates `docker/setup-buildx-action` from 3.12.0 to 4.0.0
- [Release notes](https://github.com/docker/setup-buildx-action/releases )
- [Commits](8d2750c68a...4d04d5d948 )
Updates `docker/login-action` from 3.7.0 to 4.0.0
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](c94ce9fb46...b45d80f862 )
Updates `docker/build-push-action` from 6.19.2 to 7.0.0
- [Release notes](https://github.com/docker/build-push-action/releases )
- [Commits](10e90e3645...d08e5c354a )
Updates `github/codeql-action` from 3.32.6 to 4.32.6
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](820e3160e2...0d579ffd05 )
Updates `actions/setup-node` from 5.0.0 to 6.3.0
- [Release notes](https://github.com/actions/setup-node/releases )
- [Commits](a0853c2454...53b83947a5 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 6.0.2
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: actions/upload-artifact
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: actions/download-artifact
dependency-version: 8.0.1
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: docker/metadata-action
dependency-version: 6.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: docker/setup-qemu-action
dependency-version: 4.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: docker/setup-buildx-action
dependency-version: 4.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: docker/login-action
dependency-version: 4.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: docker/build-push-action
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: github/codeql-action
dependency-version: 4.32.6
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: actions/setup-node
dependency-version: 6.3.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-19 05:28:10 +00:00
nicolargo
56e4db91dc
Make the WebUI build before the packages and Docker images build
2026-03-15 18:39:13 +01:00
nicolargo
599c193258
Harden GitHub Actions workflows: minimal permissions, SHA pins, timeouts
...
- Add top-level on caller (ci.yml) and scheduled/event
workflows (inactive_issues.yml, needs_contributor.yml)
- Declare explicit job-level permissions across all reusable workflows
- Pin all third-party actions to immutable commit SHAs (was using mutable
tags, including the critical )
- Align codeql-action on v3 across quality.yml and cyber.yml
- Add timeout-minutes on every job to prevent runaway builds
- Add concurrency group on ci.yml with cancel-in-progress for PRs only
- Add .github/dependabot.yml for automated SHA and npm dependency updates
2026-03-15 18:23:06 +01:00
nicolargo
fb19ff8176
Tru to add cyber and webui workflows in the CI pipelines (develop only)
2026-02-20 10:22:55 +01:00
nicolargo
094909bc81
Update CI
2026-02-20 09:56:45 +01:00
renovate[bot]
9eaef1da36
Update actions/setup-node action to v5
2025-09-25 16:34:58 +00:00
renovate[bot]
dbba6e0673
Update actions/checkout action to v5
2025-08-11 18:55:38 +00:00
nicolargo
fbca700562
Disable Webui audit fix in the CI,
2024-08-11 18:45:21 +02:00
nicolargo
9121b77763
Add some profiling and upgrade CI to NodeJS 20
2024-05-06 11:55:37 +02:00
nicolargo
c591461fde
Add Cyber scan (Trivy) github action
2024-03-10 19:55:02 +01:00
nicolargo
365eb11eb4
Add CI pipeline 4
2024-03-10 17:02:43 +01:00
nicolargo
ea4f11a08b
Add CI pipeline
2024-03-10 16:48:53 +01:00