-
Notifications
You must be signed in to change notification settings - Fork 0
chore(renovate): adopt shared config and re-enable the test step #7
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
This file was deleted.
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,5 @@ | ||
| { | ||
| "$schema": "https://docs.renovatebot.com/renovate-schema.json", | ||
| "extends": ["local>EduIDE/.github:renovate-config"], | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- renovate.json ---'
cat -n renovate.json
printf '%s\n' '--- repository metadata ---'
git remote -v || true
printf '%s\n' '--- shared preset references ---'
rg -n --hidden --glob '!node_modules' --glob '!dist' 'renovate-config|EduIDE/\.github|pnpmDedupe' .
printf '%s\n' '--- GitHub repository and preset lookup ---'
curl -LfsS --max-time 15 https://api.github.com/repos/EduIDE/.github \
| jq '{full_name,default_branch,archived}'
curl -LfsS --max-time 15 https://api.github.com/repos/EduIDE/.github/contents/renovate-config.json \
| jq '{name,path,type,sha,download_url,message}'
curl -LfsS --max-time 15 'https://api.github.com/repos/EduIDE/.github/git/trees/HEAD?recursive=1' \
| jq -r '.tree[]?.path' | rg '(^|/)(renovate|renovate-config)' || trueRepository: EduIDE/EduIDE-data-bridge Length of output: 996 🏁 Script executed: #!/bin/bash
set -u
printf '%s\n' '--- shared repository tree ---'
curl -LfsS --max-time 15 \
'https://api.github.com/repos/EduIDE/.github/git/trees/main?recursive=1' \
| jq -r '.tree[]? | select(.path | test("renovate|\\.json$")) | "\(.type)\t\(.path)\t\(.sha)"'
printf '%s\n' '--- issue or pull request 4 ---'
curl -LfsS --max-time 15 https://api.github.com/repos/EduIDE/.github/issues/4 \
| jq '{number,state,title,html_url,pull_request}'
printf '%s\n' '--- pull request 4 details ---'
curl -LfsS --max-time 15 https://api.github.com/repos/EduIDE/.github/pulls/4 \
| jq '{number,state,merged,merged_at,title,html_url,merge_commit_sha}'
printf '%s\n' '--- likely preset paths ---'
for path in renovate-config.json .github/renovate-config.json renovate-config.js .github/renovate-config.js; do
status=$(curl -Lso /tmp/preset-response --max-time 15 -w '%{http_code}' \
"https://raw.githubusercontent.com/EduIDE/.github/main/$path")
printf '%s %s\n' "$status" "$path"
if [ "$status" = 200 ]; then cat /tmp/preset-response; fi
doneRepository: EduIDE/EduIDE-data-bridge Length of output: 1132 🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- pull request 4 changed files ---'
curl -LfsS --max-time 15 \
'https://api.github.com/repos/EduIDE/.github/pulls/4/files?per_page=100' \
| jq -r '.[] | "\(.status)\t\(.filename)\n\(.patch // "")"'
printf '%s\n' '--- pull request 4 head metadata ---'
curl -LfsS --max-time 15 \
https://api.github.com/repos/EduIDE/.github/pulls/4 \
| jq '{base:.base.ref,head_repo:.head.repo.full_name,head:.head.ref,sha:.head.sha}'Repository: EduIDE/EduIDE-data-bridge Length of output: 18965 Merge
🤖 Prompt for AI Agents |
||
| "postUpdateOptions": ["pnpmDedupe"] | ||
| } | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,16 @@ | ||
| { | ||
| /* The main tsconfig is type-check only (noEmit) and keeps the source module | ||
| syntax as authored. vscode-test needs real CommonJS files on disk under | ||
| out/, so the test build overrides just enough to emit them. */ | ||
| "extends": "./tsconfig.json", | ||
| "compilerOptions": { | ||
| "noEmit": false, | ||
| "outDir": "out", | ||
| "module": "commonjs", | ||
| "moduleResolution": "node10", | ||
| "verbatimModuleSyntax": false, | ||
| /* Source files import each other with explicit .ts extensions; rewrite | ||
| those to .js so the emitted requires resolve. */ | ||
| "rewriteRelativeImportExtensions": true | ||
| } | ||
| } |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win
🔎 Supported by static analysis
🏁 Script executed:
Repository: EduIDE/EduIDE-data-bridge
Length of output: 1822
🌐 Web query:
GitHub actions/checkout v4 persist-credentials default token local git config documentation GITHUB_TOKEN permissions unspecified workflow default💡 Result:
In the GitHub Actions
actions/checkout@v4action, thepersist-credentialsinput defaults totrue[1][2]. When enabled, this setting configures the local Git repository's configuration (.git/config) to include an authentication token [3][4]. This allows subsequent Git commands executed within the same workflow job to run as an authenticated user [3][5]. The token used is theGITHUB_TOKENby default (unless an alternative token or SSH key is provided via thetokenorssh-keyinputs) [5][6]. The action automatically removes this credential during the post-job cleanup phase [3][5]. Regarding permissions and usage: 1. GITHUB_TOKEN Permissions: The defaultGITHUB_TOKENprovided by GitHub Actions has read-only permissions for the repository contents by default [7]. If a workflow step requires performing authenticated Git operations that involve writing (e.g.,git push), you must explicitly grant thecontents: writepermission in your workflow YAML [7]. 2. Security Consideration: Becausepersist-credentialsistrueby default, theGITHUB_TOKENis stored in the local.git/configfile [4][8]. If a workflow step inadvertently uploads the entire workspace as an artifact (e.g., usingactions/upload-artifactwithpath: .), the configuration file containing the token may be exposed in the artifact [8]. To prevent this, you can setpersist-credentials: falsein yourcheckoutstep if your subsequent workflow steps do not require Git authentication [3][8]. 3. Troubleshooting: If you encounter "403" errors during Git operations, it is frequently because theGITHUB_TOKENlacks the necessarywritepermissions for the specific operation orpersist-credentialshas been disabled, preventing the subsequent step from using the necessary credentials [7].Citations:
🏁 Script executed:
Repository: EduIDE/EduIDE-data-bridge
Length of output: 4553
🏁 Script executed:
Repository: EduIDE/EduIDE-data-bridge
Length of output: 300
Restrict the workflow token before running repository-controlled code.
actions/checkout@v4persistsGITHUB_TOKENin the local Git configuration. Because this workflow declares nopermissions, the token can inherit write access from repository or organization settings. Addcontents: readat workflow or job scope.🧰 Tools
🪛 zizmor (1.29.0)
[warning] 11-43: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block
(excessive-permissions)
🤖 Prompt for AI Agents
Source: Linters/SAST tools