Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
# Every change routes review here; satisfies the ruleset's code-owner review rule.
* @titan-ron
13 changes: 12 additions & 1 deletion .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,18 @@
# Proposes reviewed updates for the release-tag-pinned actions in .github/workflows.
# Proposes reviewed updates for the release-tag-pinned actions in .github/workflows
# and for npm dependencies (minor/patch grouped into a single weekly PR).
version: 2
updates:
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly

- package-ecosystem: npm
directory: /
schedule:
interval: weekly
groups:
npm-minor-patch:
update-types:
- minor
- patch
35 changes: 31 additions & 4 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,10 +16,20 @@ jobs:
timeout-minutes: 15
permissions:
contents: 'read' # for actions/checkout
code-quality: 'write' # for actions/upload-code-coverage
pull-requests: 'read' # upload-code-coverage looks up the PR for pushes to main
steps:
- name: Checkout
uses: actions/checkout@v7.0.1

# Blocks PRs that introduce dependencies with known vulnerabilities;
# diffs base..head, so it only applies to pull requests.
- name: 🛡️ Dependency review
if: ${{ github.event_name == 'pull_request' }}
uses: actions/dependency-review-action@v5.0.0
with:
fail-on-severity: high

- name: Setup Node.js
uses: actions/setup-node@v7.0.0
with: { node-version-file: '.nvmrc', cache: 'npm' }
Expand All @@ -36,11 +46,28 @@ jobs:
- name: 🔎 Typecheck
run: npm run typecheck

- name: 🧪 Unit tests
run: npm run test:unit
- name: 🧪 Unit tests (with coverage)
run: npm run test:coverage:unit

- name: 🧩 Component tests (with coverage)
run: npm run test:coverage:component

- name: 🧩 Component tests
run: npm run test:component
- name: ⬆️ Upload unit coverage
# Fork PRs run with a read-only token, so the coverage API is unavailable there.
if: ${{ !github.event.pull_request.head.repo.fork }}
uses: actions/upload-code-coverage@v1.4.2
with:
file: coverage/unit/cobertura-coverage.xml
language: TypeScript
label: code-coverage/unit

- name: ⬆️ Upload component coverage
if: ${{ !github.event.pull_request.head.repo.fork }}
uses: actions/upload-code-coverage@v1.4.2
with:
file: coverage/component/cobertura-coverage.xml
language: TypeScript
label: code-coverage/component

- name: Build
run: npm run build
Expand Down
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@ dist/
# Test output
test-results/
playwright-report/
coverage/

# Editor / local tooling
.idea/
Expand Down
2 changes: 2 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,8 @@ This file provides guidance to AI coding agents (Claude Code, Codex, GitHub Copi
- `npm run typecheck` — `tsc --noEmit` (there is no linter; this is the static gate)
- `npm test` — all vitest tests (unit + component tiers)
- `npm run test:unit` / `npm run test:component` — one tier
- `npm run test:coverage` — unit + component with a combined v8 coverage report in `coverage/`
- `npm run test:coverage:unit` / `npm run test:coverage:component` — one tier, scoped to the code it exercises (`coverage/unit`, `coverage/component`); these are what CI uploads
- `npm run test:e2e` — Playwright E2E against the built app (run `npm run build` first)
- `npx vitest run tests/indexer.test.ts` — one test file
- `npx vitest run -t "pattern"` — tests matching a name
Expand Down
24 changes: 24 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
# Security Policy

## Supported versions

Cockpit is pre-1.0; only the latest state of `main` receives security fixes.

## Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, use GitHub's private vulnerability reporting: go to the
[Security tab](https://github.com/tashtit/cockpit/security) and click
**Report a vulnerability**. You should receive a response within a few days.

Please include enough detail to reproduce the issue: affected component
(main process, preload bridge, renderer, or a provider parser), steps to
reproduce, and impact as you understand it.

## Scope notes

Cockpit's renderer is sandboxed and all renderer input crossing IPC is
treated as untrusted. Reports about paths that bypass `assertKnownRepoRoot`
or otherwise act on unvalidated renderer-supplied paths are particularly
relevant.
Loading
Loading