21 Commits

Author SHA1 Message Date
David Barragán Merino
86fc3dd765 👷 Pass explicit secrets to reusable workflows
Replace secrets: inherit with the secrets each reusable workflow
actually uses, and declare them under on.workflow_call.secrets in the
called workflow. Declared as required: false so behaviour is unchanged
if a secret is missing.

Signed-off-by: David Barragán Merino <david.barragan@kaleidos.net>
2026-09-30 17:01:58 +02:00
David Barragán Merino
fa3e01f7c7 👷 Disable checkout credential persistence
Set persist-credentials: false on every actions/checkout step, so the
job token is not left in .git/config for the rest of the job. No step
after checkout pushes or fetches with it. The only authenticated operation,
gh release in release.yml, uses GH_TOKEN.

Signed-off-by: David Barragán Merino <david.barragan@kaleidos.net>
2026-09-30 17:01:58 +02:00
David Barragán Merino
d1aa07087d 👷 Pin GitHub Actions to commit SHAs
Signed-off-by: David Barragán Merino <david.barragan@kaleidos.net>
2026-09-30 15:29:28 +02:00
David Barragán Merino
534b1a6702 🐛 Fix script injection in GitHub Actions workflows
Values coming from `${{ }}` expressions were interpolated directly into
`run:` scripts, so GitHub substituted them into the shell source before
bash parsed it. A commit title containing a double quote broke the
"Write step summary" step of the bundle build with a syntax error, and
the same pattern allowed arbitrary command execution on the
self-hosted runners.

Pass every expression used inside `run:` through step/job `env:` and
reference it as a quoted shell variable instead. Use the runner's
default variables (GITHUB_RUN_ID, GITHUB_REPOSITORY, ...) where the
value comes from the `github` context.

Also validate `plugin_name` in plugins-deploy-package.yml against
`^[a-z0-9][a-z0-9-]*$`, since it is free-form and reaches paths,
worker names, GITHUB_ENV and action inputs.

Affected workflows: build-bundle, build-docker,
build-docker-admin-console, plugins-deploy-package,
plugins-deploy-api-doc, plugins-deploy-styles-doc, release, tests-e2e.

Signed-off-by: David Barragán Merino <david.barragan@kaleidos.net>
2026-09-28 17:00:08 +02:00
David Barragán Merino
6d4060e7a9 🔧 Release admin-console images on final tags 2026-09-23 11:17:42 +02:00
bameda
757a5bd479 ♻️ Rebalance CI runners and drop pinned ubuntu-24.04
Move build-docker and build-docker-devenv jobs from penpot-extended-runner
to penpot-standar-runner, point tests-exporter at the canonical
penpot-extended-runner label instead of the stale penpot-runner-02 alias,
and switch build-tag/release notify jobs from ubuntu-24.04 to ubuntu-latest.

Signed-off-by: David Barragán Merino <david.barragan@kaleidos.net>
2026-09-10 19:22:46 +02:00
Kobi Hikri
7e36192034 🔧 Pin mattermost-notify action to its v2.1.0 commit SHA
The notify steps referenced mattermost/action-mattermost-notify@master, a
mutable branch that runs in CI with access to the MATTERMOST_WEBHOOK_URL
secret. Pinning to the immutable commit of the latest release (v2.1.0,
ae31bb6) keeps the exact reviewed code from executing, per GitHub third-party
action hardening guidance, while staying easy to bump.
2026-07-16 14:59:08 +02:00
David Barragán Merino
9df1e99c08 🔧 Remove the confirmation step for publishing docker images 2026-06-02 11:02:35 +02:00
Yamila Moreno
02c3d2c27c 🐳 Add mcp server to release workflow 2026-05-12 18:38:17 +02:00
Yamila Moreno
b38912f3cb 🔧 Add short tag to DocherHub release (#8864) 2026-04-16 18:22:22 +02:00
Andrey Antukh
62f3454607 🔧 Backport ci configuration changes from develop 2026-04-14 12:34:04 +02:00
Belén Albeza
8c1cf3623b
🔧 Update action checkout to v6 (#8861) 2026-04-01 11:29:55 +02:00
Yamila Moreno
04ce4c3233
🔧 Fix repository name in release.yml (#7731) 2025-11-13 11:42:33 +01:00
Yamila Moreno
3ec4c96b48 🚧 Fix docker images arch during release 2025-11-07 17:50:09 +01:00
David Barragán Merino
f795f20ef8 📎 Notify about failures in releasing and creating docker images 2025-10-21 13:16:04 +02:00
David Barragán Merino
07dedbd3bb 📎 Fix registry uri
Signed-off-by: David Barragán Merino <david.barragan@kaleidos.net>
2025-10-16 13:06:34 +02:00
David Barragán Merino
71fd6640af 👷 Automate publication of docker images in a new release 2025-10-08 17:15:10 +02:00
David Barragán Merino
09e9340ba6 💄 Fix a description and remove an unused event 2025-09-24 09:38:42 +02:00
David Barragán Merino
ef0aee0a09 📎 Automatically publish github release and docker images with final version tags 2025-09-23 23:25:52 +02:00
David Barragán Merino
fb3923924b 📎 Change the name of some action workflows 2025-09-22 09:58:26 +02:00
David Barragán Merino
fd37fdde93 📎 Add release action workflow 2025-09-16 18:06:06 +02:00