Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
36 commits
Select commit Hold shift + click to select a range
40157b9
build(deps-dev): bump ruff from 0.15.18 to 0.15.20
dependabot[bot] Jun 28, 2026
d0306db
Merge pull request #281 from blacklanternsecurity/dependabot/uv/dev/r…
liquidsec Jun 30, 2026
0a78636
build(deps-dev): bump ruff from 0.15.20 to 0.16.2 (#288)
dependabot[bot] Aug 20, 2026
e4c5814
build(deps-dev): bump maturin from 1.14.1 to 1.15.0
dependabot[bot] Aug 30, 2026
fd3818b
build(deps-dev): bump blasthttp from 0.9.0 to 0.10.0
dependabot[bot] Aug 30, 2026
84093c8
build(deps-dev): bump pydantic from 2.13.4 to 2.13.5
dependabot[bot] Sep 6, 2026
2f266f1
build(deps-dev): bump ruff from 0.16.2 to 0.16.8
dependabot[bot] Sep 20, 2026
9788201
build(deps): bump actions-rust-lang/setup-rust-toolchain
dependabot[bot] Sep 27, 2026
2550ab3
ci: pin the runner image and the branch-ref actions (#301)
singlerider Sep 29, 2026
f53fa3d
Merge pull request #292 from blacklanternsecurity/dependabot/uv/dev/b…
liquidsec Oct 1, 2026
81f0978
Merge pull request #300 from blacklanternsecurity/dependabot/uv/dev/r…
liquidsec Oct 1, 2026
277230d
Merge pull request #291 from blacklanternsecurity/dependabot/uv/dev/m…
liquidsec Oct 1, 2026
53b1e44
fix: attribute providers by containment, not ACL container
liquidsec Oct 1, 2026
01b9c7b
fix(lookup): attribute providers to the entries they declare
singlerider Oct 2, 2026
6f080b9
Merge pull request #296 from blacklanternsecurity/dependabot/uv/dev/p…
liquidsec Oct 2, 2026
f4dae8f
Merge pull request #299 from blacklanternsecurity/dependabot/github_a…
liquidsec Oct 2, 2026
2f52cb1
chore: bump version to 11.2.0
liquidsec Oct 2, 2026
1a5eaf8
docs: point signatures link at stable, not master
liquidsec Oct 2, 2026
47b5081
Merge fix/lookup-ancestor-attribution into fix/lookup-attribution
singlerider Oct 3, 2026
880617e
Merge remote-tracking branch 'upstream/dev' into fix/lookup-attribution
singlerider Oct 3, 2026
a5d1cdb
ci: publish on tag from Cargo.toml's version
singlerider Oct 3, 2026
3469dde
ci: no partial releases, and tests can't cancel publish
singlerider Oct 3, 2026
1cfad57
ci: tag-shape check, OIDC PyPI, release with SBOM, least privilege
singlerider Oct 3, 2026
03099b0
ci(publish): run PyPI upload in the pypi environment
singlerider Oct 3, 2026
16cffd1
refactor(lookup): drop unused ipnet and trim attribution comments
singlerider Oct 3, 2026
0ba01bc
ci: call the shared test, wheel, docker, and release workflows
singlerider Oct 3, 2026
a423ff2
docs: link the org release procedure
singlerider Oct 3, 2026
dca13b3
build(deps-dev): bump ruff from 0.16.8 to 0.16.9
dependabot[bot] Oct 4, 2026
826437f
build(deps): bump actions-rust-lang/setup-rust-toolchain
dependabot[bot] Oct 4, 2026
13939b1
Merge pull request #308 from blacklanternsecurity/dependabot/uv/dev/r…
liquidsec Oct 5, 2026
4e534f7
ci(dependabot): weekly grouped updates and shared auto-merge for mino…
singlerider Oct 6, 2026
cf6a310
test(lookup): replace insert-order test with inheritance chain test
singlerider Oct 6, 2026
285a601
Merge pull request #309 from blacklanternsecurity/dependabot/github_a…
liquidsec Oct 6, 2026
c827642
Merge pull request #304 from blacklanternsecurity/fix/lookup-attribution
liquidsec Oct 6, 2026
584c567
build(deps): bump pyo3 and pyo3-async-runtimes to 0.29 for Python 3.15
liquidsec Oct 6, 2026
397e398
Merge pull request #310 from blacklanternsecurity/fix/pyo3-python-3.15
liquidsec Oct 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
88 changes: 77 additions & 11 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,21 +1,87 @@
# To get started with Dependabot version updates, you'll need to specify which
# package ecosystems to update and where the package manifests are located.
# Please see the documentation for all configuration options:
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file

version: 2
updates:
- package-ecosystem: "cargo"
directory: "/"
target-branch: "dev"
schedule:
interval: "weekly"
groups:
cargo-minor-patch:
patterns:
- "*"
update-types:
- "minor"
- "patch"
cargo-major:
patterns:
- "*"
update-types:
- "major"
- package-ecosystem: "uv"
directory: "/"
target-branch: "dev"
schedule:
interval: "weekly"
groups:
uv-minor-patch:
patterns:
- "*"
update-types:
- "minor"
- "patch"
uv-major:
patterns:
- "*"
update-types:
- "major"
- package-ecosystem: "github-actions"
directory: "/"
target-branch: "dev"
open-pull-requests-limit: 10
- package-ecosystem: github-actions
directory: /
schedule:
interval: "weekly"
groups:
github-actions:
github-actions-minor-patch:
patterns:
- "*" # Group all Actions updates into a single larger pull request
- "*"
update-types:
- "minor"
- "patch"
github-actions-major:
patterns:
- "*"
update-types:
- "major"
- package-ecosystem: "docker"
directory: "/"
target-branch: "dev"
schedule:
interval: weekly
interval: "weekly"
groups:
docker-minor-patch:
patterns:
- "*"
update-types:
- "minor"
- "patch"
docker-major:
patterns:
- "*"
update-types:
- "major"
- package-ecosystem: "helm"
directory: "/helm"
target-branch: "dev"
schedule:
interval: "weekly"
groups:
helm-minor-patch:
patterns:
- "*"
update-types:
- "minor"
- "patch"
helm-major:
patterns:
- "*"
update-types:
- "major"
91 changes: 5 additions & 86 deletions .github/workflows/cla.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
name: "CLA Assistant"
name: CLA

on:
issue_comment:
types: [created]
Expand All @@ -10,88 +11,6 @@ permissions:
statuses: write

jobs:
CLAAssistant:
runs-on: ubuntu-latest
steps:
- name: Generate token from GitHub App
id: app-token
uses: actions/create-github-app-token@v3
with:
app-id: ${{ secrets.APP_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}
owner: blacklanternsecurity

- name: Check all committers against org and allowlist
id: cla-check
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
run: |
if [ "${{ github.event_name }}" = "pull_request_target" ]; then
PR_NUM="${{ github.event.pull_request.number }}"
else
PR_NUM="${{ github.event.issue.number }}"
fi

COMMITTERS=$(gh api "repos/${{ github.repository }}/pulls/$PR_NUM/commits" --paginate --jq '.[].author.login' | sort -u)
ALL_EXEMPT=true

for LOGIN in $COMMITTERS; do
# treat commits with no associated GitHub login as non-exempt
if [ -z "$LOGIN" ] || [ "$LOGIN" = "null" ]; then
echo "Unknown committer (no GitHub login) — not exempt"
ALL_EXEMPT=false
break
fi

EXEMPT=false

# check if account type is Bot (GitHub App accounts)
AUTHOR_TYPE=$(gh api "users/${LOGIN}" --jq '.type' 2>/dev/null || echo "Unknown")
if [ "$AUTHOR_TYPE" = "Bot" ]; then
echo "$LOGIN is a Bot account — exempt"
EXEMPT=true
fi

# check org membership
if [ "$EXEMPT" = "false" ]; then
if gh api "orgs/blacklanternsecurity/members/$LOGIN" > /dev/null 2>&1; then
echo "$LOGIN is an org member — exempt"
EXEMPT=true
fi
fi

if [ "$EXEMPT" = "false" ]; then
echo "$LOGIN is not exempt — CLA required"
ALL_EXEMPT=false
break
fi
done

echo "all_exempt=$ALL_EXEMPT" >> "$GITHUB_OUTPUT"

- name: Skip CLA when all committers are exempt
if: steps.cla-check.outputs.all_exempt == 'true' && github.event_name == 'pull_request_target'
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
gh api --method POST "repos/${{ github.repository }}/statuses/${{ github.event.pull_request.head.sha }}" \
-f state=success \
-f context="CLAAssistant" \
-f description="CLA check skipped — all committers are org members or bots"

- name: "CLA Assistant"
if: |
(steps.cla-check.outputs.all_exempt != 'true') &&
((github.event.comment.body == 'recheck' || github.event.comment.body == 'I have read the CLA Document and I hereby sign the CLA') || github.event_name == 'pull_request_target')
uses: contributor-assistant/github-action@v2.6.1
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PERSONAL_ACCESS_TOKEN: ${{ steps.app-token.outputs.token }}
with:
path-to-signatures: "signatures/version1/cla.json"
path-to-document: "https://github.com/blacklanternsecurity/CLA/blob/main/ICLA.md"
branch: "main"
allowlist: "dependabot[bot],github-actions[bot],renovate[bot]"
remote-organization-name: "blacklanternsecurity"
remote-repository-name: "CLA"
lock-pullrequest-aftermerge: "false"
cla:
uses: blacklanternsecurity/CLA/.github/workflows/cla-reusable.yml@4f85d3c525483f0f846ef4384a8ece24a3c74375 # 2026-09-29
secrets: inherit
16 changes: 7 additions & 9 deletions .github/workflows/daily-update.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,9 @@ on:
- cron: '0 6 * * *'
workflow_dispatch: # Allow manual trigger

permissions:
contents: read

# Prevent concurrent runs from racing to commit/merge
# cancel-in-progress: false means new runs wait instead of canceling in-progress ones
concurrency:
Expand All @@ -14,31 +17,26 @@ concurrency:

jobs:
update:
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
permissions:
contents: write

steps:
- name: Generate app token
id: app-token
uses: actions/create-github-app-token@v3
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
app-id: ${{ secrets.CLOUDCHECK_APP_ID }}
private-key: ${{ secrets.CLOUDCHECK_APP_PRIVATE_KEY }}

- name: Checkout stable branch
uses: actions/checkout@v7
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: stable
token: ${{ steps.app-token.outputs.token }}

- name: Set up Python
uses: actions/setup-python@v7
with:
python-version: "3.12"

- name: Set up uv
uses: astral-sh/setup-uv@v7
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0

- name: Install dependencies
run: uv sync
Expand Down
12 changes: 12 additions & 0 deletions .github/workflows/dependabot-auto-merge.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
name: Dependabot auto-merge
on: pull_request

permissions: {}

jobs:
auto-merge:
permissions:
contents: write
pull-requests: write
checks: read
uses: blacklanternsecurity/CLA/.github/workflows/dependabot-auto-merge.yml@e532142ee9e7322888f6edc80d9a89e2f8c0d96d # 2026-10-03
97 changes: 0 additions & 97 deletions .github/workflows/docker-tests.yml

This file was deleted.

33 changes: 0 additions & 33 deletions .github/workflows/pipeline-tests.yml

This file was deleted.

Loading
Loading