Compare commits

...
7 Commits
Author SHA1 Message Date
dresberandClaude Sonnet 5 602ff49f7b fix(notifications): use the run's actual API event, not gitea.event_name
notifications.yml is invoked via workflow_call from the caller
workflow, so inside this job gitea.event_name reports "workflow_call"
rather than the top-level event (push/schedule/...) that actually
started the run. Comparing that against the Actions API's per-run
event field (which reports the real trigger) never matched, so
previous_conclusion always stayed "unknown" and healed notifications
never fired. Now the current run's real event is captured from the API
response itself and used for the comparison, falling back to
gitea.event_name only if the current run isn't found in the scanned
history.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-08 21:08:25 +00:00
dresberandClaude Sonnet 5 467e60627b fix(python-checks): don't fail private-index probe on expected 404 at bare /simple/ root
Gitea's PyPI registry only resolves /simple/<package>/, not the bare
/simple/ index root, so the v1.11.2 probe added to give visible
diagnostics for the private-index setup step was always 404ing even
when the index and credentials were correct. This broke installs of
private Python packages during builds. The probe now only fails hard
on 401/403 (auth rejected) or an unreachable host; a plain 404 is
logged and left to pip's own resolution to confirm.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-08 04:49:00 +00:00
dresber a7d2e552af fix private pip installation and notification of healed build 2026-09-03 21:03:12 +00:00
dresber f01c90f7c6 fix buildx fallback pin 2026-08-20 10:26:16 +02:00
dresber 9ebc572a9c switch to updated trivy version and pipeline image 2026-08-20 09:01:18 +02:00
dresber bd92604912 fix trivy vulnerability DB update outage 2026-08-13 14:45:44 +02:00
dresber a0a75210a3 switch to new image and update trivy checks 2026-07-25 21:55:15 +02:00
6 changed files with 196 additions and 76 deletions
+33 -7
View File
@@ -38,8 +38,10 @@ on:
# whose Dockerfile installs the in-house BB* packages. The Dockerfile must consume it # whose Dockerfile installs the in-house BB* packages. The Dockerfile must consume it
# via `RUN --mount=type=secret,id=pip_extra_index`, never as an ARG or ENV, so the # via `RUN --mount=type=secret,id=pip_extra_index`, never as an ARG or ENV, so the
# token is not baked into an image layer. # token is not baked into an image layer.
type: boolean # Gitea 1.27.x does not reliably propagate boolean inputs through
default: false # reusable workflows. Callers pass the literal string "true".
type: string
default: "false"
secrets: secrets:
REGISTRY_USERNAME: { required: true } REGISTRY_USERNAME: { required: true }
REGISTRY_PASSWORD: { required: true } REGISTRY_PASSWORD: { required: true }
@@ -54,17 +56,17 @@ on:
# binfmt: pin by digest (tonistiigi/binfmt@sha256:...) for the strongest posture; the version tag # binfmt: pin by digest (tonistiigi/binfmt@sha256:...) for the strongest posture; the version tag
# below is immutable enough for CI and avoids a Docker Hub token dance in the workflow. # below is immutable enough for CI and avoids a Docker Hub token dance in the workflow.
env: env:
BUILDX_VERSION: "0.35.0" BUILDX_VERSION: "0.36.1"
BUILDX_SHA256: "d41ece72044243b4f58b343441ae37446d9c29a7d6b5e11c61847bbcf8f7dfda" BUILDX_SHA256: "48af8a397ebd60178778bf63611dbcebe5f5e7a9be90eb9147b24b9587455778"
BINFMT_IMAGE: "tonistiigi/binfmt:qemu-v10.2.3" BINFMT_IMAGE: "tonistiigi/binfmt:qemu-v10.2.3"
TRIVY_VERSION: "0.71.0" TRIVY_VERSION: "0.74.0"
TRIVY_SHA256: "30a3d22b23f88c233f1658f562fb477cae3b3e8b4761109d515b7698daf85814" TRIVY_SHA256: "2ae6fe3ee734b7fdf11335663e18c75ea12dccc76062f09f164a3b0f8be4371a"
jobs: jobs:
publish: publish:
runs-on: docker runs-on: docker
container: container:
image: gitea.tech-buddy.at/bitbuddydev/gitea_runner_python314:dev-bda315b82bb23d83065b77d91fedf0e20d9accf1 image: gitea.tech-buddy.at/bitbuddydev/gitea_runner_python314:1.1.0
credentials: credentials:
username: ${{ secrets.REGISTRY_USERNAME }} username: ${{ secrets.REGISTRY_USERNAME }}
password: ${{ secrets.REGISTRY_PASSWORD }} password: ${{ secrets.REGISTRY_PASSWORD }}
@@ -180,11 +182,35 @@ jobs:
fi fi
trivy --version trivy --version
# Trivy's default vulnerability-DB source (mirror.gcr.io/aquasec/trivy-db) is a
# Google-hosted cache of the upstream GHCR image, used to dodge GHCR's unauthenticated
# rate limits. That cache occasionally 404s on a specific layer digest (a known,
# recurring upstream issue: aquasecurity/trivy). Point at the canonical GHCR source
# instead, and retry the DB download alone a few times — trivy exits 1 both for "DB
# download failed" and for "vulnerabilities found", so the download is a separate step
# from the scan to keep those two outcomes distinguishable.
export TRIVY_DB_REPOSITORY="ghcr.io/aquasecurity/trivy-db:2"
export TRIVY_JAVA_DB_REPOSITORY="ghcr.io/aquasecurity/trivy-java-db:1"
echo "=== Ensuring vulnerability DB is up to date ==="
db_attempt=1
db_max_attempts=3
until trivy image --download-db-only; do
if [ "$db_attempt" -ge "$db_max_attempts" ]; then
echo "=== Failed to download the Trivy vulnerability DB after ${db_max_attempts} attempts ==="
exit 1
fi
echo "=== DB download failed, retrying (${db_attempt}/${db_max_attempts})... ==="
db_attempt=$((db_attempt + 1))
sleep $((db_attempt * 5))
done
echo "=== Scanning ${{ steps.vars.outputs.scan_ref }} (fail on fixable ${{ inputs.scan_severity }}) ===" echo "=== Scanning ${{ steps.vars.outputs.scan_ref }} (fail on fixable ${{ inputs.scan_severity }}) ==="
trivy image \ trivy image \
--exit-code 1 \ --exit-code 1 \
--severity "${{ inputs.scan_severity }}" \ --severity "${{ inputs.scan_severity }}" \
--ignore-unfixed \ --ignore-unfixed \
--skip-db-update \
--scanners vuln,secret \ --scanners vuln,secret \
"${{ steps.vars.outputs.scan_ref }}" "${{ steps.vars.outputs.scan_ref }}"
+27 -3
View File
@@ -21,7 +21,7 @@ jobs:
scan: scan:
runs-on: docker runs-on: docker
container: container:
image: gitea.tech-buddy.at/bitbuddydev/gitea_runner_python314:dev-bda315b82bb23d83065b77d91fedf0e20d9accf1 image: gitea.tech-buddy.at/bitbuddydev/gitea_runner_python314:1.1.0
credentials: credentials:
username: ${{ secrets.REGISTRY_USERNAME }} username: ${{ secrets.REGISTRY_USERNAME }}
password: ${{ secrets.REGISTRY_PASSWORD }} password: ${{ secrets.REGISTRY_PASSWORD }}
@@ -48,8 +48,8 @@ jobs:
# checksum, never "latest": Trivy releases were compromised in the # checksum, never "latest": Trivy releases were compromised in the
# March 2026 supply-chain incident (malicious v0.69.4). Keep in sync # March 2026 supply-chain incident (malicious v0.69.4). Keep in sync
# with the ARGs in the PipelineImage Dockerfiles. # with the ARGs in the PipelineImage Dockerfiles.
TRIVY_VERSION=0.71.0 TRIVY_VERSION=0.74.0
TRIVY_SHA256=30a3d22b23f88c233f1658f562fb477cae3b3e8b4761109d515b7698daf85814 TRIVY_SHA256=2ae6fe3ee734b7fdf11335663e18c75ea12dccc76062f09f164a3b0f8be4371a
if ! command -v trivy >/dev/null 2>&1; then if ! command -v trivy >/dev/null 2>&1; then
echo "=== Trivy not in runner image, installing v${TRIVY_VERSION} ===" echo "=== Trivy not in runner image, installing v${TRIVY_VERSION} ==="
curl -sSfLO "https://github.com/aquasecurity/trivy/releases/download/v${TRIVY_VERSION}/trivy_${TRIVY_VERSION}_Linux-64bit.tar.gz" curl -sSfLO "https://github.com/aquasecurity/trivy/releases/download/v${TRIVY_VERSION}/trivy_${TRIVY_VERSION}_Linux-64bit.tar.gz"
@@ -61,10 +61,34 @@ jobs:
FULL_IMAGE="${{ secrets.DOCKER_REGISTRY }}/${{ inputs.image_name }}:${{ inputs.image_tag }}" FULL_IMAGE="${{ secrets.DOCKER_REGISTRY }}/${{ inputs.image_name }}:${{ inputs.image_tag }}"
# Trivy's default vulnerability-DB source (mirror.gcr.io/aquasec/trivy-db) is a
# Google-hosted cache of the upstream GHCR image, used to dodge GHCR's unauthenticated
# rate limits. That cache occasionally 404s on a specific layer digest (a known,
# recurring upstream issue: aquasecurity/trivy). Point at the canonical GHCR source
# instead, and retry the DB download alone a few times — trivy exits 1 both for "DB
# download failed" and for "vulnerabilities found", so the download is a separate step
# from the scan to keep those two outcomes distinguishable.
export TRIVY_DB_REPOSITORY="ghcr.io/aquasecurity/trivy-db:2"
export TRIVY_JAVA_DB_REPOSITORY="ghcr.io/aquasecurity/trivy-java-db:1"
echo "=== Ensuring vulnerability DB is up to date ==="
db_attempt=1
db_max_attempts=3
until trivy image --download-db-only; do
if [ "$db_attempt" -ge "$db_max_attempts" ]; then
echo "=== Failed to download the Trivy vulnerability DB after ${db_max_attempts} attempts ==="
exit 1
fi
echo "=== DB download failed, retrying (${db_attempt}/${db_max_attempts})... ==="
db_attempt=$((db_attempt + 1))
sleep $((db_attempt * 5))
done
echo "=== Scanning ${FULL_IMAGE} (fail on fixable ${{ inputs.scan_severity }}) ===" echo "=== Scanning ${FULL_IMAGE} (fail on fixable ${{ inputs.scan_severity }}) ==="
trivy image \ trivy image \
--exit-code 1 \ --exit-code 1 \
--severity "${{ inputs.scan_severity }}" \ --severity "${{ inputs.scan_severity }}" \
--ignore-unfixed \ --ignore-unfixed \
--skip-db-update \
--scanners vuln,secret \ --scanners vuln,secret \
"${FULL_IMAGE}" "${FULL_IMAGE}"
+67 -55
View File
@@ -40,75 +40,87 @@ jobs:
repo = "${{ gitea.repository }}" repo = "${{ gitea.repository }}"
current_run_number = int("${{ gitea.run_number }}") current_run_number = int("${{ gitea.run_number }}")
current_branch = "${{ gitea.ref_name }}" current_branch = "${{ gitea.ref_name }}"
# gitea.event_name is unreliable here: notifications.yml is itself called via
# workflow_call from the caller workflow, so inside this job it reports
# "workflow_call" rather than the top-level event (push/schedule/...) that
# actually started the run. The Actions API reports the real triggering event
# per run, so use that for the current run instead of trusting this context
# value. It is kept only as a last-resort fallback if the current run can't be
# found in the scanned history at all.
current_event = "${{ gitea.event_name }}" current_event = "${{ gitea.event_name }}"
token = os.environ["API_GITEA_TOKEN"] token = os.environ["API_GITEA_TOKEN"]
url = (
f"{server}/api/v1/repos/{repo}/actions/runs"
f"?page=1&limit=5"
)
print(f"Fetching workflow runs from: {url}")
print(f"Current run number: {current_run_number}") print(f"Current run number: {current_run_number}")
print(f"Current branch: {current_branch}") print(f"Current branch: {current_branch}")
print(f"Current event: {current_event}") print(f"Current event (context, may be inaccurate): {current_event}")
req = urllib.request.Request(
url,
headers={
"Authorization": f"token {token}",
"Accept": "application/json",
},
)
with urllib.request.urlopen(req) as response:
data = json.loads(response.read().decode("utf-8"))
runs = data.get("workflow_runs", [])
print(f"Received {len(runs)} workflow runs")
previous = "unknown" previous = "unknown"
for run in runs: # Scheduled runs can push the prior run for this branch/event beyond the
run_number = run.get("run_number") # first page. Scan a bounded history so a succeeding push after a failure
status = run.get("status") # is still reported as healed.
conclusion = run.get("conclusion") for page in range(1, 11):
branch = run.get("head_branch") url = f"{server}/api/v1/repos/{repo}/actions/runs?page={page}&limit=100"
event = run.get("event") print(f"Fetching workflow runs page {page}: {url}")
req = urllib.request.Request(
print( url,
f"Inspecting run #{run_number}: " headers={
f"status={status}, " "Authorization": f"token {token}",
f"conclusion={conclusion}, " "Accept": "application/json",
f"branch={branch}, " },
f"event={event}"
) )
with urllib.request.urlopen(req) as response:
data = json.loads(response.read().decode("utf-8"))
# aktuellen Run überspringen runs = data.get("workflow_runs", [])
if int(run_number) == current_run_number: if not isinstance(runs, list):
print(" -> skipping current run") print("Received an invalid workflow-runs payload; stopping lookup.")
continue break
print(f"Received {len(runs)} workflow runs on page {page}")
if not runs:
break
# nur abgeschlossene Runs for run in runs:
if status != "completed": run_number = run.get("run_number")
print(" -> skipping non-completed run") status = run.get("status")
continue conclusion = run.get("conclusion")
branch = run.get("head_branch")
event = run.get("event")
# nur gleicher Branch print(
if branch != current_branch: f"Inspecting run #{run_number}: "
print(" -> skipping different branch") f"status={status}, "
continue f"conclusion={conclusion}, "
f"branch={branch}, "
f"event={event}"
)
# nur gleiches Event # aktuellen Run überspringen, aber dessen echtes Trigger-Event merken
if event != current_event: if str(run_number) == str(current_run_number):
print(" -> skipping different event") current_event = event or current_event
continue print(f" -> skipping current run (actual event={event})")
continue
previous = conclusion or "unknown" # nur abgeschlossene Runs
if status != "completed":
print(" -> skipping non-completed run")
continue
print(f" -> selected previous conclusion: {previous}") # nur gleicher Branch
break if branch != current_branch:
print(" -> skipping different branch")
continue
# nur gleiches Event
if event != current_event:
print(" -> skipping different event")
continue
previous = conclusion or "unknown"
print(f" -> selected previous conclusion: {previous}")
break
if previous != "unknown" or len(runs) < 100:
break
print(f"Previous conclusion final: {previous}") print(f"Previous conclusion final: {previous}")
+61 -5
View File
@@ -22,14 +22,16 @@ on:
type: boolean type: boolean
default: true default: true
use_private_index: use_private_index:
type: boolean # Gitea 1.27.x does not reliably propagate boolean inputs through
default: false # reusable workflows. Keep this a string until that regression is fixed.
type: string
default: "false"
jobs: jobs:
check: check:
runs-on: docker runs-on: docker
container: container:
image: gitea.tech-buddy.at/bitbuddydev/gitea_runner_python314:dev-bda315b82bb23d83065b77d91fedf0e20d9accf1 image: gitea.tech-buddy.at/bitbuddydev/gitea_runner_python314:1.1.0
credentials: credentials:
username: ${{ secrets.REGISTRY_USERNAME }} username: ${{ secrets.REGISTRY_USERNAME }}
password: ${{ secrets.REGISTRY_PASSWORD }} password: ${{ secrets.REGISTRY_PASSWORD }}
@@ -38,15 +40,69 @@ jobs:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: actions/checkout@v4
- name: Configure private package index # Keep this step unconditional. A Gitea Actions update can otherwise silently
if: ${{ inputs.use_private_index }} # skip it when a boolean workflow_call input is not propagated as expected;
# pip then misleadingly reports that the private package does not exist.
- name: Configure and verify private package index
env: env:
PRIVATE_INDEX_ENABLED: ${{ inputs.use_private_index }}
PRIVATE_INDEX_URL: ${{ secrets.PIP_EXTRA_INDEX_URL }} PRIVATE_INDEX_URL: ${{ secrets.PIP_EXTRA_INDEX_URL }}
run: | run: |
echo "Private package index requested: ${PRIVATE_INDEX_ENABLED:-<empty>}"
if [ "${PRIVATE_INDEX_ENABLED}" != "true" ]; then
echo "Private package index is not requested for this workflow call."
exit 0
fi
if [ -z "$PRIVATE_INDEX_URL" ]; then if [ -z "$PRIVATE_INDEX_URL" ]; then
echo "use_private_index=true but the PIP_EXTRA_INDEX_URL secret is empty or not set" echo "use_private_index=true but the PIP_EXTRA_INDEX_URL secret is empty or not set"
exit 1 exit 1
fi fi
# Probe the configured simple index before pip resolves dependencies. The
# probe deliberately prints only scheme/host/path, never URL credentials.
# NOTE: Gitea's PyPI package registry does not serve a browsable listing at
# the bare /simple/ root (only /simple/<package>/ resolves per PEP 503), so a
# 404 against the configured URL is expected there and is not itself a fault.
# This probe therefore only fails hard on auth rejection (401/403) or an
# unreachable/erroring host; a plain 404 is logged and deferred to pip's own
# resolution, which is the real signal for whether the package is installable.
python - "$PRIVATE_INDEX_URL" <<'PY'
import base64
import sys
from urllib.error import HTTPError, URLError
from urllib.parse import unquote, urlsplit, urlunsplit
from urllib.request import Request, urlopen
configured_url = sys.argv[1]
parsed = urlsplit(configured_url)
hostname = parsed.hostname or "<missing host>"
port = f":{parsed.port}" if parsed.port else ""
safe_url = urlunsplit((parsed.scheme, f"{hostname}{port}", parsed.path, parsed.query, ""))
request = Request(safe_url, headers={"Accept": "application/vnd.pypi.simple.v1+json"})
if parsed.username is not None:
credentials = f"{unquote(parsed.username)}:{unquote(parsed.password or '')}".encode()
request.add_header("Authorization", "Basic " + base64.b64encode(credentials).decode())
try:
with urlopen(request, timeout=15) as response: # nosec B310 -- configured CI package index
print(f"Private package-index probe: HTTP {response.status} at {safe_url}")
except HTTPError as error:
print(f"Private package-index probe: HTTP {error.code} at {safe_url}")
if error.code in {401, 403}:
print("Authentication was rejected by the private package index.")
raise SystemExit(1)
if error.code == 404:
print(
"Bare index root returned 404; Gitea's PyPI registry does not "
"serve a listing at /simple/ (only /simple/<package>/ resolves "
"per PEP 503). Treating this as expected and deferring to pip's "
"own dependency resolution to confirm the index actually works."
)
else:
raise SystemExit(1)
except URLError as error:
print(f"Private package-index probe could not reach {safe_url}: {error.reason}")
raise SystemExit(1)
PY
pip config --site set global.extra-index-url "$PRIVATE_INDEX_URL" pip config --site set global.extra-index-url "$PRIVATE_INDEX_URL"
- name: Install Tools & Deps - name: Install Tools & Deps
+5 -3
View File
@@ -17,8 +17,10 @@ on:
type: string type: string
use_private_index: use_private_index:
# build backends that need the in-house BB* packages to resolve build dependencies # build backends that need the in-house BB* packages to resolve build dependencies
type: boolean # Gitea 1.27.x does not reliably propagate boolean inputs through
default: false # reusable workflows. Callers pass the literal string "true".
type: string
default: "false"
secrets: secrets:
REGISTRY_USERNAME: { required: true } REGISTRY_USERNAME: { required: true }
REGISTRY_PASSWORD: { required: true } REGISTRY_PASSWORD: { required: true }
@@ -30,7 +32,7 @@ jobs:
publish: publish:
runs-on: docker runs-on: docker
container: container:
image: gitea.tech-buddy.at/bitbuddydev/gitea_runner_python314:dev-bda315b82bb23d83065b77d91fedf0e20d9accf1 image: gitea.tech-buddy.at/bitbuddydev/gitea_runner_python314:1.1.0
credentials: credentials:
username: ${{ secrets.REGISTRY_USERNAME }} username: ${{ secrets.REGISTRY_USERNAME }}
password: ${{ secrets.REGISTRY_PASSWORD }} password: ${{ secrets.REGISTRY_PASSWORD }}
+1 -1
View File
@@ -20,7 +20,7 @@ jobs:
security: security:
runs-on: docker runs-on: docker
container: container:
image: gitea.tech-buddy.at/bitbuddydev/gitea_runner_python314:dev-bda315b82bb23d83065b77d91fedf0e20d9accf1 image: gitea.tech-buddy.at/bitbuddydev/gitea_runner_python314:1.1.0
credentials: credentials:
username: ${{ secrets.REGISTRY_USERNAME }} username: ${{ secrets.REGISTRY_USERNAME }}
password: ${{ secrets.REGISTRY_PASSWORD }} password: ${{ secrets.REGISTRY_PASSWORD }}