Jean-Philippe Evrard
c768c7c8d5
Merge pull request #1032 from kubereboot/dependabot/github_actions/github/codeql-action-3.27.5
...
build(deps): bump github/codeql-action from 3.27.4 to 3.27.5
2024-11-21 14:08:09 +01:00
dependabot[bot]
5530ab0db1
build(deps): bump github/codeql-action from 3.27.4 to 3.27.5
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.27.4 to 3.27.5.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/ea9e4e37992a54ee68a9622e985e60c8e8f12d9f...f09c1c0a94de965c15400f5634aa42fac8fb8f88 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2024-11-20 17:56:27 +00:00
dependabot[bot]
8f9af5c1dd
build(deps): bump aquasecurity/trivy-action from 0.28.0 to 0.29.0
...
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action ) from 0.28.0 to 0.29.0.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases )
- [Commits](https://github.com/aquasecurity/trivy-action/compare/915b19bbe73b92a6cf82a1bc12b087c9a19a5fe2...18f2510ee396bbf400402947b394f2dd8c87dbb0 )
---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2024-11-20 17:56:21 +00:00
dependabot[bot]
31551a2c23
build(deps): bump step-security/harden-runner from 2.10.1 to 2.10.2
...
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner ) from 2.10.1 to 2.10.2.
- [Release notes](https://github.com/step-security/harden-runner/releases )
- [Commits](https://github.com/step-security/harden-runner/compare/91182cccc01eb5e619899d80e4e971d6181294a7...0080882f6c36860b6ba35c610c98ce87d4e2f26f )
---
updated-dependencies:
- dependency-name: step-security/harden-runner
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2024-11-19 17:44:39 +00:00
dependabot[bot]
91ef335394
build(deps): bump docker/metadata-action from 5.5.1 to 5.6.1
...
Bumps [docker/metadata-action](https://github.com/docker/metadata-action ) from 5.5.1 to 5.6.1.
- [Release notes](https://github.com/docker/metadata-action/releases )
- [Commits](https://github.com/docker/metadata-action/compare/8e5442c4ef9f78752691e2d8f8d19755c6f78e81...369eb591f429131d6889c46b94e711f089e6ca96 )
---
updated-dependencies:
- dependency-name: docker/metadata-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2024-11-19 17:44:35 +00:00
dholbach
e5f01ce172
Merge pull request #1028 from kubereboot/dependabot/github_actions/github/codeql-action-3.27.4
...
build(deps): bump github/codeql-action from 3.27.3 to 3.27.4
2024-11-14 21:24:19 +01:00
dependabot[bot]
9a24d9ddab
build(deps): bump github/codeql-action from 3.27.3 to 3.27.4
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.27.3 to 3.27.4.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/396bb3e45325a47dd9ef434068033c6d5bb0d11a...ea9e4e37992a54ee68a9622e985e60c8e8f12d9f )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2024-11-14 17:55:42 +00:00
dholbach
56f2b97045
Merge pull request #1027 from kubereboot/dependabot/github_actions/github/codeql-action-3.27.3
...
build(deps): bump github/codeql-action from 3.27.1 to 3.27.3
2024-11-14 06:41:55 +01:00
dependabot[bot]
cbb1d5702b
build(deps): bump github/codeql-action from 3.27.1 to 3.27.3
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.27.1 to 3.27.3.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/4f3212b61783c3c68e8309a0f18a699764811cda...396bb3e45325a47dd9ef434068033c6d5bb0d11a )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2024-11-13 17:36:00 +00:00
dholbach
888964c17a
Merge pull request #1022 from kubereboot/dependabot/github_actions/github/codeql-action-3.27.1
...
build(deps): bump github/codeql-action from 3.27.0 to 3.27.1
2024-11-09 17:44:09 +01:00
dholbach
83eca94075
Merge pull request #1023 from kubereboot/dependabot/github_actions/actions/checkout-4.2.2
...
build(deps): bump actions/checkout from 4.1.1 to 4.2.2
2024-11-09 17:39:39 +01:00
dependabot[bot]
390fe1e742
build(deps): bump actions/checkout from 4.1.1 to 4.2.2
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 4.1.1 to 4.2.2.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v4.1.1...11bd71901bbe5b1630ceea73d27597364c9af683 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2024-11-08 17:27:48 +00:00
dependabot[bot]
785a8efdf4
build(deps): bump github/codeql-action from 3.27.0 to 3.27.1
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.27.0 to 3.27.1.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/662472033e021d55d94146f66f6058822b0b39fd...4f3212b61783c3c68e8309a0f18a699764811cda )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2024-11-08 17:27:44 +00:00
Jean-Philippe Evrard
5275bbd5a9
Merge pull request #1020 from step-security-bot/stepsecurity_remediation_1731015518
...
[StepSecurity] Apply security best practices
2024-11-07 23:36:08 +01:00
StepSecurity Bot
95e6055522
[StepSecurity] Apply security best practices
...
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io >
2024-11-07 21:38:39 +00:00
Jean-Philippe Evrard
a5b3faaa05
Merge pull request #1019 from evrardjp/release_1.16.2
...
chore: update release
1.16.2
2024-11-07 22:03:43 +01:00
Jean-Philippe Evrard
3da7d5b8f4
chore: update release
...
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2024-11-07 19:06:12 +01:00
Jean-Philippe Evrard
ec0ba4f1bd
Merge pull request #1018 from kubereboot/dependabot/github_actions/lycheeverse/lychee-action-2.1.0
...
build(deps): bump lycheeverse/lychee-action from 2.0.2 to 2.1.0
2024-11-07 18:51:15 +01:00
Jean-Philippe Evrard
3adeb5a384
Merge pull request #1016 from evrardjp/fix_small_memleak
2024-11-07 18:40:40 +01:00
dependabot[bot]
9b13117fd4
build(deps): bump lycheeverse/lychee-action from 2.0.2 to 2.1.0
...
Bumps [lycheeverse/lychee-action](https://github.com/lycheeverse/lychee-action ) from 2.0.2 to 2.1.0.
- [Release notes](https://github.com/lycheeverse/lychee-action/releases )
- [Commits](https://github.com/lycheeverse/lychee-action/compare/7cd0af4c74a61395d455af97419279d86aafaede...f81112d0d2814ded911bd23e3beaa9dda9093915 )
---
updated-dependencies:
- dependency-name: lycheeverse/lychee-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2024-11-07 17:20:13 +00:00
Jean-Philippe Evrard
e370b0bd4a
Remove reassignment in rebootasrequired loop
...
There is no need to continuously reallocate the check blockers.
They only need to be defined once.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2024-11-06 18:57:09 +01:00
Jean-Philippe Evrard
659e9fd5bf
Merge pull request #1015 from evrardjp/fix_goroutine_leak
...
Fix goroutine leak
2024-11-06 18:54:15 +01:00
Jean-Philippe Evrard
94e73465ad
Add stdout and stderr to log info
...
Without this, we are loosing features based on previous logrus
implementation. Now, we will log the stdout and stderr for
each call.
Next to this, we ensure the call of the log. methods will be
ready for the switch to get rid of logrus in the future.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2024-11-06 08:41:19 +01:00
Jean-Philippe Evrard
f81a302fa5
Merge pull request #1014 from evrardjp/improve_makefile
...
bootstrap-tools are required for kured bin
2024-11-05 23:18:59 +01:00
Jean-Philippe Evrard
f20a1ddd05
Fix goroutine leak
...
Without this patch, we use WriterLevel, which spawns
go routines. As we do it at every call of the util commands,
we spawn goroutines at every check.
This is a problem as it leads to memory management issues.
This fixes it by using a buffer for stdout and stderr, then
logging the results after the command was executed.
To make sure the logging happened at the same place, I inlined
the code from utils. This results in duplicated the code.
However, this is not a big problem as:
- It makes the code more readable
- The implementation between checkers and rebooters _ARE_
different -- One definitely NEEDS privileges, while the other
does not... Which could lead to later improvements.
Removing a "utils" package is not really a big deal (it
is kinda a win in itself, as it is an anti-pattern), as the
test coverage was kept.
Partial-Fix: #1004
Fixes : #1013
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2024-11-05 22:11:13 +01:00
Jean-Philippe Evrard
7c3184239a
bootstrap-tools are required for kured bin
...
kured linking needs the goreleaser command line, yet it does
not ensure it is present.
This fixes it by ensuring the bootstrap-tools are always
fetched first and used for all the make targets requiring them.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2024-11-05 17:24:42 +01:00
dependabot[bot] and lnx01
9fbd0a2cc8
build(deps): bump actions/upload-artifact from 3.2.1.pre.node20 to 4.4.3 ( #1012 )
...
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact ) from 3.2.1.pre.node20 to 4.4.3.
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/c24449f33cd45d4826c6702db7e49f7cdb9b551d...b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 )
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-11-01 10:55:20 -07:00
dependabot[bot] and lnx01
738564296a
build(deps): bump ossf/scorecard-action from 2.3.1 to 2.4.0 ( #1011 )
...
Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action ) from 2.3.1 to 2.4.0.
- [Release notes](https://github.com/ossf/scorecard-action/releases )
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md )
- [Commits](https://github.com/ossf/scorecard-action/compare/0864cf19026789058feabb7e87baa5f140aac736...62b2cac7ed8198b15735ed49ab1e5cf35480ba46 )
---
updated-dependencies:
- dependency-name: ossf/scorecard-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-10-31 11:28:40 -07:00
dependabot[bot] and lnx01
b47d43f268
build(deps): bump actions/upload-artifact ( #1010 )
...
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact ) from 97a0fba1372883ab732affbe8f94b823f91727db to c24449f33cd45d4826c6702db7e49f7cdb9b551d.
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/97a0fba1372883ab732affbe8f94b823f91727db...c24449f33cd45d4826c6702db7e49f7cdb9b551d )
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-10-31 11:28:07 -07:00
Jean-Philippe Evrard
9ac37661d2
Merge pull request #1007 from kubereboot/Add-OpenSSF-Scorecard
...
Create scorecard.yml
2024-10-30 23:03:58 +01:00
Jean-Philippe Evrard
fc8d979da4
Merge pull request #1006 from evrardjp/update_go_mod
...
Be explicit about toolchain version
2024-10-30 23:03:31 +01:00
Jean-Philippe Evrard
030ff4525e
Merge pull request #1005 from evrardjp/remove_security_exception
...
Remove security exception
2024-10-30 23:03:03 +01:00
Jean-Philippe Evrard
c62e67b27a
Merge pull request #1009 from kubereboot/update-email
...
Update email address for Hidde Beydals
2024-10-28 21:23:33 +01:00
Hidde Beydals
2a2ee20b32
Update email address for Hidde Beydals
...
Signed-off-by: Hidde Beydals <hiddeco@users.noreply.github.com >
2024-10-28 21:22:30 +01:00
Jean-Philippe Evrard
e6c06078ff
Create scorecard.yml
...
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2024-10-27 22:30:34 +01:00
Jean-Philippe Evrard
e110d575f0
Be explicit about toolchain version
...
As of Go 1.21, toolchain versions must use the 1.N.P syntax.
We were not explicit in our go.mod.
Without this, the openssf audit will fail to work.
This fixes it by doing a go get go@1.22 .8 toolchain@1.22 .8
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2024-10-27 22:26:19 +01:00
Jean-Philippe Evrard
f680091f02
Remove security exception
...
Now that we are building with latest 1.22, the exception should
not be used anymore.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2024-10-27 21:57:31 +01:00
Jean-Philippe Evrard
edb7460928
Merge pull request #997 from evrardjp/tidy_gomod
...
Cleanup gomod
2024-10-27 21:46:31 +01:00
Jean-Philippe Evrard
62f22e7060
Merge pull request #990 from evrardjp/first_refactors
...
Cleanup Part 1 - First refactors
2024-10-27 21:45:00 +01:00
dependabot[bot] and lnx01
eba33a7149
build(deps): bump github.com/prometheus/common from 0.60.0 to 0.60.1 ( #1003 )
...
Bumps [github.com/prometheus/common](https://github.com/prometheus/common ) from 0.60.0 to 0.60.1.
- [Release notes](https://github.com/prometheus/common/releases )
- [Changelog](https://github.com/prometheus/common/blob/main/RELEASE.md )
- [Commits](https://github.com/prometheus/common/compare/v0.60.0...v0.60.1 )
---
updated-dependencies:
- dependency-name: github.com/prometheus/common
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-10-25 15:04:48 -07:00
Jean-Philippe Evrard
d29cc2ae68
Cleanup dockerfile ( #996 )
...
Without this, docker buildx will complain about the
following issues:
- "RedundantTargetPlatform: Setting platform to predefined $TARGETPLATFORM in
FROM is redundant as this is the default behavior"
- "FromAsCasing: 'as' and 'FROM' keywords' casing do not match"
This fixes it.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2024-10-25 15:04:16 -07:00
Jean-Philippe Evrard
11acd1a86d
Clarify features for e2e test ( #995 )
...
Without this, ppl might be wondering how to use e2e test,
especially on slower machines.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2024-10-25 15:03:13 -07:00
Jean-Philippe Evrard
3a116be09d
Merge pull request #1002 from evrardjp/improve-release-doc
2024-10-23 13:11:50 +02:00
Jean-Philippe Evrard
e750f07de8
Improve release documentation
...
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2024-10-22 21:57:10 +02:00
Jean-Philippe Evrard
c77090d5fd
chore: update release
...
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
1.16.1
2024-10-22 21:13:28 +02:00
Jean-Philippe Evrard
f559a95304
Make the internal blockers implementation internal
...
This at the same time, removes the alert public package.
Alert was only used inside prometheus blocker, so it allows
to simplify the code.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2024-10-19 15:51:04 +02:00
Jean-Philippe Evrard
73f00ce445
Make all the internal validations ... internal
...
The main is doing flag validation through pflags, then
did further validation by involving the constructors.
With the recent refactor on the commit "Refactor constructors"
in this branch, we moved away from that pattern.
However, it means we reintroduced a log dependency into our
external API, and the external API now had extra validations
regardless of the type.
This is unnecessary, so I moved away from that pattern, and
moved back all the validation into a central place, internal,
which is only doing what kured would desire, without exposing
it to users. The users could still theoretically use the proper
constructors for each type, as they would validate just fine.
The only thing they would lose is the kured internal decision
of validation/precedence.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2024-10-19 15:51:04 +02:00
Jean-Philippe Evrard
626db87158
Add error to reboot interface
...
Without this, impossible to bubble up errors to main
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2024-10-19 15:51:04 +02:00
Jean-Philippe Evrard
67df0e935a
Remove deprecated PollWithContext
...
Replaced with PollUntilContextTimeout.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2024-10-19 15:51:04 +02:00
Jean-Philippe Evrard
231888e58a
Use RegexpValue in plags
...
This will remove double pointers, and be explicit about the
type we are using.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2024-10-19 15:51:04 +02:00