Bryan Frimin
660567f894
Fix permission error for CD
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-04-06 12:26:38 +02:00
Bryan Frimin
893d4f674e
Fix CD pipeline
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-04-06 12:08:41 +02:00
Bryan Frimin
acf5913d6c
Rollback to GHA runner
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-04-04 14:07:57 +02:00
Bryan Frimin
7e685a2e96
Rewrite CI/CD pipeline
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-04-03 20:14:38 +02:00
dependabot[bot]
e6b88e7eec
Bump the github-actions group with 12 updates
...
Bumps the github-actions group with 12 updates:
| Package | From | To |
| --- | --- | --- |
| [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action ) | `3.7.0` | `4.0.0` |
| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action ) | `3.12.0` | `4.0.0` |
| [anchore/sbom-action](https://github.com/anchore/sbom-action ) | `0.22.1` | `0.24.0` |
| [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action ) | `6.4.0` | `7.0.0` |
| [anchore/scan-action](https://github.com/anchore/scan-action ) | `7.3.1` | `7.4.0` |
| [actions/upload-artifact](https://github.com/actions/upload-artifact ) | `6` | `7` |
| [actions/download-artifact](https://github.com/actions/download-artifact ) | `6` | `8` |
| [docker/setup-compose-action](https://github.com/docker/setup-compose-action ) | `1.2.0` | `2.1.0` |
| [docker/login-action](https://github.com/docker/login-action ) | `3.7.0` | `4.0.0` |
| [actions/attest-sbom](https://github.com/actions/attest-sbom ) | `3` | `4` |
| [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance ) | `3` | `4` |
| [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog ) | `b78fbfd8eb982f4802e09a265fb2bc37b3040975` | `e48f9039c82786db50685e8ef7d980b209f06186` |
Updates `docker/setup-qemu-action` from 3.7.0 to 4.0.0
- [Release notes](https://github.com/docker/setup-qemu-action/releases )
- [Commits](c7c5346462...ce360397dd )
Updates `docker/setup-buildx-action` from 3.12.0 to 4.0.0
- [Release notes](https://github.com/docker/setup-buildx-action/releases )
- [Commits](8d2750c68a...4d04d5d948 )
Updates `anchore/sbom-action` from 0.22.1 to 0.24.0
- [Release notes](https://github.com/anchore/sbom-action/releases )
- [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md )
- [Commits](deef08a0db...e22c389904 )
Updates `goreleaser/goreleaser-action` from 6.4.0 to 7.0.0
- [Release notes](https://github.com/goreleaser/goreleaser-action/releases )
- [Commits](e435ccd777...ec59f474b9 )
Updates `anchore/scan-action` from 7.3.1 to 7.4.0
- [Release notes](https://github.com/anchore/scan-action/releases )
- [Changelog](https://github.com/anchore/scan-action/blob/main/RELEASE.md )
- [Commits](8d2fce0942...e1165082ff )
Updates `actions/upload-artifact` from 6 to 7
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/v6...v7 )
Updates `actions/download-artifact` from 6 to 8
- [Release notes](https://github.com/actions/download-artifact/releases )
- [Commits](https://github.com/actions/download-artifact/compare/v6...v8 )
Updates `docker/setup-compose-action` from 1.2.0 to 2.1.0
- [Release notes](https://github.com/docker/setup-compose-action/releases )
- [Commits](364cc21a5d...8cccb8c14b )
Updates `docker/login-action` from 3.7.0 to 4.0.0
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](c94ce9fb46...b45d80f862 )
Updates `actions/attest-sbom` from 3 to 4
- [Release notes](https://github.com/actions/attest-sbom/releases )
- [Changelog](https://github.com/actions/attest-sbom/blob/main/RELEASE.md )
- [Commits](https://github.com/actions/attest-sbom/compare/v3...v4 )
Updates `actions/attest-build-provenance` from 3 to 4
- [Release notes](https://github.com/actions/attest-build-provenance/releases )
- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md )
- [Commits](https://github.com/actions/attest-build-provenance/compare/v3...v4 )
Updates `trufflesecurity/trufflehog` from b78fbfd8eb982f4802e09a265fb2bc37b3040975 to e48f9039c82786db50685e8ef7d980b209f06186
- [Release notes](https://github.com/trufflesecurity/trufflehog/releases )
- [Commits](b78fbfd8eb...e48f9039c8 )
---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
dependency-version: 4.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: docker/setup-buildx-action
dependency-version: 4.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: anchore/sbom-action
dependency-version: 0.24.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: goreleaser/goreleaser-action
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: anchore/scan-action
dependency-version: 7.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: actions/upload-artifact
dependency-version: '7'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/download-artifact
dependency-version: '8'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: docker/setup-compose-action
dependency-version: 2.1.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: docker/login-action
dependency-version: 4.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/attest-sbom
dependency-version: '4'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/attest-build-provenance
dependency-version: '4'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: trufflesecurity/trufflehog
dependency-version: e48f9039c82786db50685e8ef7d980b209f06186
dependency-type: direct:production
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-02 18:37:23 +02:00
Bryan Frimin
bc51c910ae
Rename TruffleHog exclude paths file to plain text
...
The --exclude-paths flag expects a plain text file with one regex
per line, not a YAML file.
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-03-30 14:18:29 +02:00
Bryan Frimin
5237e57d27
Revert "Use inline trufflehog:ignore instead of exclude paths file"
...
This reverts commit f10ecb8210b1176311d9372d1108b91ce8290fd4.
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-03-30 14:18:29 +02:00
Bryan Frimin
7dcc3d21ac
Use inline trufflehog:ignore instead of exclude paths file
...
Inline comments are more targeted than excluding the entire file
from secret scanning. Remove the .trufflehog.yml exclude file and
the --exclude-paths flag from the workflow.
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-03-30 14:18:29 +02:00
Bryan Frimin
b60b21aad0
Exclude guardrail test file from TruffleHog secret scanning
...
The sensitive_data_test.go file contains dummy connection strings
(postgres://, mongodb://, amqp://) used as test fixtures for the data
leak guardrail. These trigger false positives in TruffleHog.
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-03-30 14:18:29 +02:00
Sacha Al Himdani
72a48ff6b1
Run n8n-node lint on pull requests using n8n-node CLI
...
The PR lint path was running `npx eslint .` for the n8n-node package,
which uses a different config than `npx n8n-node lint` used on push.
This caused lint to pass on PRs but fail on push to main.
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2026-03-27 14:24:53 +01:00
Sacha Al Himdani
c18f0b0748
Bump aquasecurity/trivy-action from 0.33.1 to 0.35.0
...
Fixes GHSA-69fq-xp46-6x23 (Critical) and GHSA-9p44-j4g5-cfx5 (Medium).
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2026-03-25 08:54:09 +01:00
Bryan Frimin
138f24ef59
Add Homebrew tap publishing for prb CLI
...
Configure GoReleaser to publish the prb CLI to the getprobo/homebrew-tap repository on each release. Separate the prb archive from the main probod archive and add the necessary GitHub token to the release workflow.
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-03-20 14:33:35 +01:00
Bryan Frimin
c74e5cc123
Add go fmt and go fix checks to lint
...
Adds go-fmt and go-fix Makefile targets that fail when gofmt or go fix
suggest changes. Both are wired into the lint target and used in CI.
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2026-03-19 16:37:51 +01:00
Bryan Frimin
7ffb2d5e94
Add document viewer with proper 404 handling for trust center
...
Move document download/view to a dedicated viewer page with PDF preview,
access request flow, and a proper 404 error boundary when documents are
not found. The backend now returns NOT_FOUND instead of INTERNAL for
missing documents and reports.
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-03-16 19:13:21 +01:00
Bryan Frimin
7ed9c6c2e6
Add go fmt and go fix checks to lint
...
Adds go-fmt and go-fix Makefile targets that fail when gofmt or go fix
suggest changes. Both are wired into the lint target and used in CI.
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-03-16 17:32:25 +01:00
Bryan Frimin
807213d384
Stop tracking generated files
...
Run make generate in CI lint and test jobs since generated files are
now gitignored. Also include Relay codegen for frontend apps in the
generate target.
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-03-16 16:19:47 +01:00
Bryan Frimin
3e3138f764
Cache Go modules explicitly with go mod download
...
Add go mod download step after setup-go in all CI jobs to ensure the
module cache is populated as a discrete step. This makes cache hits visible
in logs and prevents module downloads from being interleaved with build
operations, improving cache effectiveness.
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-03-16 15:54:54 +01:00
Bryan Frimin
5c22789624
Add reviewdog to post lint errors as PR comments
...
Use reviewdog in the CI lint job so golangci-lint and eslint
failures appear as inline comments on pull request files instead
of only in job logs.
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-03-16 00:41:22 +01:00
mendral-app[bot]
1921445a73
ci: add shared build job to eliminate redundant make build in test and lint
...
Extract make build into a dedicated build job that uploads artifacts
(bin/probod, frontend dist, emails dist). Both test and lint jobs now
download these artifacts instead of rebuilding from scratch.
This eliminates ~172 compute minutes/week of redundant builds while
keeping wall-clock time neutral (test and lint were spending their
first ~2min building anyway).
2026-03-11 13:43:11 +01:00
mendral-app[bot]
76e1c17a24
ci: remove redundant grype install from release-snapshot workflow
...
The manual grype install (cache + curl-pipe-sh + PATH export) is redundant
because anchore/scan-action already bundles grype internally. Removing it
also eliminates a supply chain risk: the install script was fetched from
the mutable @main branch of anchore/grype via curl | sh, in a job with
packages:write and id-token:write permissions.
2026-03-11 05:28:01 -07:00
Bryan Frimin
38b12fa278
Upgrade go version
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-03-09 14:52:23 +01:00
Sacha Al Himdani
e173b26acd
Update go and open telemetry
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2026-03-02 09:39:10 +01:00
Bryan Frimin
9b0226ad3c
Upgrade codesign installer
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-02-16 17:53:22 +01:00
Bryan Frimin
76dc874ed6
Fix double install codesign
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-02-16 17:46:38 +01:00
Bryan Frimin
43b44b06bf
Set fixed version of codesign + upgrade to docker v2
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-02-16 17:41:43 +01:00
Bryan Frimin
c9de03ec43
Fix cosign cache race condition
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-02-16 17:26:35 +01:00
Bryan Frimin
d2dbb6f714
Use bigger github hosted runner
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-02-13 16:20:31 +01:00
Bryan Frimin
015ebe43dc
Use sbom file for grype
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-02-11 11:56:18 +01:00
Émile Ré
4c28792944
Upgrade go to 1.25.7
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-02-09 10:55:58 +04:00
mendral-app[bot]
09d73cf413
chore: pin all third-party actions to SHA digests
...
Pin third-party GitHub Actions to immutable SHA digests to prevent
supply chain attacks via tag force-pushing or branch updates.
Actions pinned:
- trufflesecurity/trufflehog (was @main, now SHA)
- sigstore/cosign-installer@v3.8.1
- docker/setup-buildx-action@v3.12 .0
- docker/setup-qemu-action@v3.7.0
- docker/login-action@v3.7.0
- goreleaser/goreleaser-action@v6.4.0
- aquasecurity/trivy-action@0.33 .1
- github/codeql-action/upload-sarif@v4.32 .1
- golangci/golangci-lint-action@v9.2.0
- docker/setup-compose-action@v1.2.0
Version comments added for maintainability.
2026-02-05 08:28:22 +01:00
Émile Ré
459ee41bd0
Skip apps building on api e2e tests
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-02-04 18:32:53 +04:00
Bryan Frimin
31f2cde8d0
Fix missing golintci binary
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-02-02 19:06:36 +01:00
Bryan Frimin
f7f2d704f2
Update github action lint command
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-02-02 18:45:37 +01:00
dependabot[bot]
b88a6ba012
Bump the github-actions group with 10 updates
...
Bumps the github-actions group with 10 updates:
| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout ) | `4` | `6` |
| [actions/setup-go](https://github.com/actions/setup-go ) | `5` | `6` |
| [actions/setup-node](https://github.com/actions/setup-node ) | `4` | `6` |
| [actions/cache](https://github.com/actions/cache ) | `4` | `5` |
| [anchore/sbom-action](https://github.com/anchore/sbom-action ) | `0.20.5` | `0.22.1` |
| [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action ) | `0.28.0` | `0.33.1` |
| [anchore/scan-action](https://github.com/anchore/scan-action ) | `6.5.1` | `7.3.1` |
| [actions/upload-artifact](https://github.com/actions/upload-artifact ) | `4` | `6` |
| [actions/attest-sbom](https://github.com/actions/attest-sbom ) | `1` | `3` |
| [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance ) | `1` | `3` |
Updates `actions/checkout` from 4 to 6
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v4...v6 )
Updates `actions/setup-go` from 5 to 6
- [Release notes](https://github.com/actions/setup-go/releases )
- [Commits](https://github.com/actions/setup-go/compare/v5...v6 )
Updates `actions/setup-node` from 4 to 6
- [Release notes](https://github.com/actions/setup-node/releases )
- [Commits](https://github.com/actions/setup-node/compare/v4...v6 )
Updates `actions/cache` from 4 to 5
- [Release notes](https://github.com/actions/cache/releases )
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md )
- [Commits](https://github.com/actions/cache/compare/v4...v5 )
Updates `anchore/sbom-action` from 0.20.5 to 0.22.1
- [Release notes](https://github.com/anchore/sbom-action/releases )
- [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md )
- [Commits](da167eac91...deef08a0db )
Updates `aquasecurity/trivy-action` from 0.28.0 to 0.33.1
- [Release notes](https://github.com/aquasecurity/trivy-action/releases )
- [Commits](https://github.com/aquasecurity/trivy-action/compare/0.28.0...0.33.1 )
Updates `anchore/scan-action` from 6.5.1 to 7.3.1
- [Release notes](https://github.com/anchore/scan-action/releases )
- [Changelog](https://github.com/anchore/scan-action/blob/main/RELEASE.md )
- [Commits](1638637db6...8d2fce0942 )
Updates `actions/upload-artifact` from 4 to 6
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/v4...v6 )
Updates `actions/attest-sbom` from 1 to 3
- [Release notes](https://github.com/actions/attest-sbom/releases )
- [Changelog](https://github.com/actions/attest-sbom/blob/main/RELEASE.md )
- [Commits](https://github.com/actions/attest-sbom/compare/v1...v3 )
Updates `actions/attest-build-provenance` from 1 to 3
- [Release notes](https://github.com/actions/attest-build-provenance/releases )
- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md )
- [Commits](https://github.com/actions/attest-build-provenance/compare/v1...v3 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/setup-go
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/setup-node
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/cache
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: anchore/sbom-action
dependency-version: 0.22.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: aquasecurity/trivy-action
dependency-version: 0.33.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: anchore/scan-action
dependency-version: 7.3.1
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/upload-artifact
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/attest-sbom
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/attest-build-provenance
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-01 21:14:12 +00:00
Émile Ré
58838e1420
Upgrade go to 1.25.6
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-01-29 11:59:12 +04:00
Émile Ré
975cccdc3a
Fix dependabot.yaml is not a CI workflow
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-01-29 08:55:13 +04:00
mendral-app[bot]
db27c6763f
fix: add grype binary caching and retry logic to release-snapshot job
...
- Cache grype binary using actions/cache to avoid repeated downloads
- Add retry logic (3 attempts with exponential backoff) for grype installation
- Pre-install grype before scan-action to ensure it's available
This addresses the HTTP 503/504 timeout errors when downloading grype from
GitHub releases, which caused 6 failures on the main branch in the past 14 days
(90.32% success rate vs 99% target).
2026-01-26 17:11:04 -08:00
Bryan Frimin
9b84206d56
Add Dependabot configuration for all dependencies
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-01-26 17:03:04 -08:00
mendral-app[bot]
1b0fffe99e
ci(release): enable Go module caching
...
Add cache: true to actions/setup-go@v5 in the Release workflow to
cache Go modules between runs. This reduces the GoReleaser step
duration from 5-18 minutes to 1-3 minutes by avoiding repeated
module downloads.
2026-01-26 08:49:41 -08:00
Émile Ré
d1f6006a17
Rename e2e test results artifact
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-01-26 12:08:55 +04:00
Émile Ré
f32b7d60f7
Always upload test results + fix cgo enabling for tests
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-01-26 12:02:46 +04:00
Émile Ré
0c73e28a31
Add junit results to e2e tests too
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-01-26 11:53:59 +04:00
Émile Ré
e1989e002f
Add gotestsum as a tool and use junit format to get test analysis
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-01-26 11:34:05 +04:00
Émile Ré
188ae13d58
Move linting in dedicated CI job
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-01-23 13:17:46 +04:00
Émile Ré
4d80dccbbf
Fix bot review
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-01-22 21:06:19 +04:00
Émile Ré
36cd0cae95
Update node to LTS and npm to avoid issue with optional dependencies on natives
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-01-22 17:47:44 +04:00
mendral-app[bot]
f55d4984ec
Enable Go module and npm caching in make workflow to reduce CI execution time
2026-01-05 13:58:41 +01:00
mendral-app[bot]
4a377e4aff
Suppress mkcert Firefox/Chrome warning in E2E tests
2026-01-05 11:21:52 +01:00
mendral-app[bot]
b438732bf7
Cache Trivy database to prevent HTTP 504 download failures
2026-01-02 01:15:43 -08:00
Bryan Frimin
ee08aeb8bf
Disable trivy license scanning
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2025-12-24 08:55:27 +01:00