Resolve the security review of #389 (findings 1-4): - .dockerignore: every env/credential pattern is now **/-prefixed (**/.env, **/.env.*, **/node_modules, **/.npmrc, ..., **/secrets, **/*.pem, **/*.key, ...) and the redundant 'secrets/' line is dropped. Docker's matcher (moby/patternmatcher) anchors slash-less patterns to the context root, so the bare forms excluded nothing under apps/server/; **/ matches the root AND any nested depth. (finding 1, 3) - tests/secrets-not-embedded.test.mjs: the dockerignore matcher is now a faithful port of moby/patternmatcher (filepath.Clean + anchored full-path match + parent-directory propagation), not gitignore basename semantics; asserts nested example paths (apps/server/.npmrc, config/server.key, apps/server/secrets/...) are excluded; requires no redundant equivalent patterns verbatim; adds mutation probes for bare-pattern and duplicate-pattern regressions. (finding 2, 3) - apps/server/Dockerfile + compose.yaml: guarantee restated precisely (credential files excluded at the context root AND at any depth). - .gitea/workflows/ci.yml: new job runs 'node --test tests/secrets-not-embedded.test.mjs' on every PR; the docker-gated layer-scan probe runs where a daemon exists, skips cleanly otherwise. (finding 4) - tests/compose-config.test.mjs: .dockerignore presence list updated to the **/-prefixed forms (node_modules, .env). Tested: secrets suite 16 tests -> 15 pass / 1 docker-gated skip / 0 fail; full suite 101 pass / 12 fail / 8 skip, failures identical to clean main (env-dependent pnpm/Node-24 suites); matcher port verified against the moby/patternmatcher evidence table.
39 lines
1.1 KiB
YAML
39 lines
1.1 KiB
YAML
name: CI
|
|
|
|
on:
|
|
pull_request:
|
|
push:
|
|
branches: [main]
|
|
|
|
jobs:
|
|
frozen-install:
|
|
name: Frozen lockfile install
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: Install Node.js 24
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: '24'
|
|
- name: Enable pnpm (corepack, pinned to 11.23.0 via packageManager)
|
|
run: corepack enable
|
|
- name: Install dependencies (frozen lockfile)
|
|
run: pnpm install --frozen-lockfile
|
|
- name: Verify workspace groups
|
|
run: pnpm -r list --depth -1
|
|
|
|
# E00-S02-T08: the static assertions of tests/secrets-not-embedded.test.mjs
|
|
# gate every PR (the docker-gated layer-scan probe inside the same file runs
|
|
# where a Docker daemon is available and skips cleanly otherwise).
|
|
secrets-not-embedded:
|
|
name: Secrets not embedded (E00-S02-T08)
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: Install Node.js 24
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: '24'
|
|
- name: Run secrets-not-embedded test suite
|
|
run: node --test tests/secrets-not-embedded.test.mjs
|