From a86cfdb92aa083de5294580b4adabd35ba6cea13 Mon Sep 17 00:00:00 2001 From: TheMeinerLP Date: Fri, 21 Aug 2026 19:18:46 +0200 Subject: [PATCH 1/3] chore(ci): adopt shared workflows and central Renovate preset - renovate.json -> central preset (stardust-maintainers) - security.yml (Trivy + CycloneDX SBOM) --- .github/workflows/security.yml | 55 ++++++++++++++++++++++++++++++++++ renovate.json | 5 ++-- 2 files changed, 57 insertions(+), 3 deletions(-) create mode 100644 .github/workflows/security.yml diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml new file mode 100644 index 00000000..ed23f7fd --- /dev/null +++ b/.github/workflows/security.yml @@ -0,0 +1,55 @@ +name: Security + +# Trivy vulnerability gate plus a CycloneDX SBOM of the repository. Self-contained +# on purpose: it needs no build tool and no registry credentials, so it is the +# baseline security gate for every repository regardless of language. +on: + pull_request: + push: + branches: [main] + schedule: + - cron: "50 4 * * 1" + workflow_dispatch: +permissions: + contents: read + security-events: write + +jobs: + trivy: + name: Trivy scan + uses: OneLiteFeatherNET/workflows/.github/workflows/security-scan.yml@v2.8.1 + with: + scan-type: "fs" + scanners: "vuln,secret" + severity: "CRITICAL,HIGH" + # Report-only for now, so adopting this does not turn CI red on day one. + fail-on-findings: false + upload-sarif: true + secrets: inherit + + sbom: + name: CycloneDX SBOM + runs-on: ubuntu-latest + permissions: + contents: read + steps: + - name: Checkout + uses: actions/checkout@v6 + + - name: Generate SBOM + uses: aquasecurity/trivy-action@v0.36.0 + with: + scan-type: fs + scan-ref: . + format: cyclonedx + output: bom.json + # An SBOM is an inventory, not a finding list - never fail on it. + exit-code: '0' + + - name: Upload SBOM + uses: actions/upload-artifact@v4 + with: + name: sbom-cyclonedx + path: bom.json + if-no-files-found: error + retention-days: 90 diff --git a/renovate.json b/renovate.json index 2e278f0f..3edb60a4 100644 --- a/renovate.json +++ b/renovate.json @@ -1,7 +1,6 @@ { "$schema": "https://docs.renovatebot.com/renovate-schema.json", "extends": [ - "github>OneLiteFeatherNET/renovate:default(OneLiteFeatherNET/stardust-maintainers)", - "github>OneLiteFeatherNET/renovate:paper" + "github>OneLiteFeatherNET/renovate:default(OneLiteFeatherNET/stardust-maintainers)" ] -} \ No newline at end of file +} From c1b1537a2285b404f138143b92972c64d3929fe5 Mon Sep 17 00:00:00 2001 From: TheMeinerLP Date: Fri, 21 Aug 2026 20:14:34 +0200 Subject: [PATCH 2/3] chore(ci): add release-please, PR linting and release SBOMs - pr-lint.yml - commitlint.config.mjs - SBOM job appended to release-please.yml --- .github/workflows/pr-lint.yml | 17 ++++++++++++++++ .github/workflows/release-please.yml | 29 +++++++++++++++++++++++++++- commitlint.config.mjs | 3 +++ 3 files changed, 48 insertions(+), 1 deletion(-) create mode 100644 .github/workflows/pr-lint.yml create mode 100644 commitlint.config.mjs diff --git a/.github/workflows/pr-lint.yml b/.github/workflows/pr-lint.yml new file mode 100644 index 00000000..759b37b8 --- /dev/null +++ b/.github/workflows/pr-lint.yml @@ -0,0 +1,17 @@ +name: PR Lint + +# Conventional Commits on the PR title and every commit on the branch. +# release-please parses those commit types to decide the version bump and to +# build the changelog - a non-conventional commit silently produces neither. +on: + pull_request: + types: [opened, edited, synchronize, reopened] + +permissions: + contents: read + pull-requests: read + +jobs: + lint: + uses: OneLiteFeatherNET/workflows/.github/workflows/pr-lint.yml@v2.8.1 + secrets: inherit diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 562f75a1..6073483c 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -28,4 +28,31 @@ jobs: with: java-version: "25.0.3" java-distribution: "temurin" - secrets: inherit \ No newline at end of file + secrets: inherit + sbom: + name: Attach SBOM to release + needs: release-please + if: needs.release-please.outputs.release_created == 'true' + runs-on: ubuntu-latest + permissions: + contents: write + steps: + - name: Checkout + uses: actions/checkout@v6 + with: + ref: ${{ needs.release-please.outputs.tag_name }} + + - name: Generate CycloneDX SBOM + uses: aquasecurity/trivy-action@v0.36.0 + with: + scan-type: fs + scan-ref: . + format: cyclonedx + output: bom.json + exit-code: '0' + + - name: Attach SBOM to the release + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + TAG: ${{ needs.release-please.outputs.tag_name }} + run: gh release upload "$TAG" bom.json --clobber diff --git a/commitlint.config.mjs b/commitlint.config.mjs new file mode 100644 index 00000000..0616fb93 --- /dev/null +++ b/commitlint.config.mjs @@ -0,0 +1,3 @@ +export default { + extends: ['@commitlint/config-conventional'], +}; From dedc9e241702590b5bd2c2fbf864db9142d04493 Mon Sep 17 00:00:00 2001 From: TheMeinerLP Date: Fri, 21 Aug 2026 21:14:21 +0200 Subject: [PATCH 3/3] fix(ci): restore Renovate platform presets and anchor the version in build.gradle.kts - renovate flavor restored: paper - version line introduced (the project had none); removed the now-unused version from gradle.properties; extra-files now points at build.gradle.kts --- build.gradle.kts | 2 ++ gradle.properties | 1 - release-please-config.json | 5 ++++- renovate.json | 3 ++- 4 files changed, 8 insertions(+), 3 deletions(-) diff --git a/build.gradle.kts b/build.gradle.kts index 0dab3e27..13cfc899 100644 --- a/build.gradle.kts +++ b/build.gradle.kts @@ -9,6 +9,8 @@ plugins { jacoco } +version = "1.15.2" // x-release-please-version + dependencies { compileOnly(libs.paper) diff --git a/gradle.properties b/gradle.properties index 406dd275..dfbc340e 100644 --- a/gradle.properties +++ b/gradle.properties @@ -4,5 +4,4 @@ org.gradle.unsafe.configuration-cache=true org.gradle.caching=true org.gradle.jvmargs=-Xmx2048M -version = 1.15.2 # x-release-please-version group = net.onelitefeather \ No newline at end of file diff --git a/release-please-config.json b/release-please-config.json index 05a36769..5d9d7db9 100644 --- a/release-please-config.json +++ b/release-please-config.json @@ -10,7 +10,10 @@ "package-name": "stardust", "changelog-path": "CHANGELOG.md", "extra-files": [ - "gradle.properties" + { + "type": "generic", + "path": "build.gradle.kts" + } ] } } diff --git a/renovate.json b/renovate.json index 3edb60a4..424efa76 100644 --- a/renovate.json +++ b/renovate.json @@ -1,6 +1,7 @@ { "$schema": "https://docs.renovatebot.com/renovate-schema.json", "extends": [ - "github>OneLiteFeatherNET/renovate:default(OneLiteFeatherNET/stardust-maintainers)" + "github>OneLiteFeatherNET/renovate:default(OneLiteFeatherNET/stardust-maintainers)", + "github>OneLiteFeatherNET/renovate:paper" ] }