diff --git a/.gitea/workflows/dependency-audit.yml b/.gitea/workflows/dependency-audit.yml index c2ccbe5..0ed8519 100644 --- a/.gitea/workflows/dependency-audit.yml +++ b/.gitea/workflows/dependency-audit.yml @@ -21,23 +21,13 @@ jobs: - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 with: node-version: "22" - - name: Configure SSH for release dependencies - env: - GOVOPLAN_RELEASE_SSH_KEY_B64: ${{ secrets.GOVOPLAN_RELEASE_SSH_KEY_B64 }} + - name: Use anonymous HTTPS for public GovOPlaN repositories run: | - mkdir -p ~/.ssh - chmod 700 ~/.ssh - if [ -z "${GOVOPLAN_RELEASE_SSH_KEY_B64:-}" ]; then - echo "GOVOPLAN_RELEASE_SSH_KEY_B64 secret is required for git+ssh release dependencies." - exit 1 - fi - printf '%s' "$GOVOPLAN_RELEASE_SSH_KEY_B64" | base64 -d > ~/.ssh/id_ed25519 - chmod 600 ~/.ssh/id_ed25519 - echo 'git.add-ideas.de ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDe48IOof2fJS1dTbJtLWQnWnr+JorZXKIFdOAM9ct8G' > ~/.ssh/known_hosts - chmod 600 ~/.ssh/known_hosts + git config --global --add url."https://git.add-ideas.de/add-ideas/govoplan".insteadOf "git@git.add-ideas.de:add-ideas/govoplan" + git config --global --add url."https://git.add-ideas.de/add-ideas/govoplan".insteadOf "ssh://git@git.add-ideas.de/add-ideas/govoplan" - name: Bootstrap GovOPlaN repositories working-directory: govoplan - run: python tools/repo/bootstrap-repositories.py --parent .. + run: python tools/repo/bootstrap-repositories.py --parent .. --transport public-https --exclude-repo addideas-govoplan-website - name: Install backend dev audit dependencies working-directory: govoplan run: | diff --git a/.gitea/workflows/module-matrix.yml b/.gitea/workflows/module-matrix.yml index a8b6e82..15337db 100644 --- a/.gitea/workflows/module-matrix.yml +++ b/.gitea/workflows/module-matrix.yml @@ -17,23 +17,13 @@ jobs: - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 with: node-version: "22" - - name: Configure SSH for release dependencies - env: - GOVOPLAN_RELEASE_SSH_KEY_B64: ${{ secrets.GOVOPLAN_RELEASE_SSH_KEY_B64 }} + - name: Use anonymous HTTPS for public GovOPlaN repositories run: | - mkdir -p ~/.ssh - chmod 700 ~/.ssh - if [ -z "${GOVOPLAN_RELEASE_SSH_KEY_B64:-}" ]; then - echo "GOVOPLAN_RELEASE_SSH_KEY_B64 secret is required for git+ssh release dependencies." - exit 1 - fi - printf '%s' "$GOVOPLAN_RELEASE_SSH_KEY_B64" | base64 -d > ~/.ssh/id_ed25519 - chmod 600 ~/.ssh/id_ed25519 - echo 'git.add-ideas.de ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDe48IOof2fJS1dTbJtLWQnWnr+JorZXKIFdOAM9ct8G' > ~/.ssh/known_hosts - chmod 600 ~/.ssh/known_hosts + git config --global --add url."https://git.add-ideas.de/add-ideas/govoplan".insteadOf "git@git.add-ideas.de:add-ideas/govoplan" + git config --global --add url."https://git.add-ideas.de/add-ideas/govoplan".insteadOf "ssh://git@git.add-ideas.de/add-ideas/govoplan" - name: Bootstrap GovOPlaN repositories working-directory: govoplan - run: python tools/repo/bootstrap-repositories.py --parent .. + run: python tools/repo/bootstrap-repositories.py --parent .. --transport public-https --exclude-repo addideas-govoplan-website - name: Install backend release dependencies working-directory: govoplan run: | diff --git a/.gitea/workflows/release-integration.yml b/.gitea/workflows/release-integration.yml index 1e33c60..ae92e01 100644 --- a/.gitea/workflows/release-integration.yml +++ b/.gitea/workflows/release-integration.yml @@ -16,23 +16,13 @@ jobs: - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 with: node-version: "22" - - name: Configure SSH for release dependencies - env: - GOVOPLAN_RELEASE_SSH_KEY_B64: ${{ secrets.GOVOPLAN_RELEASE_SSH_KEY_B64 }} + - name: Use anonymous HTTPS for public GovOPlaN repositories run: | - mkdir -p ~/.ssh - chmod 700 ~/.ssh - if [ -z "${GOVOPLAN_RELEASE_SSH_KEY_B64:-}" ]; then - echo "GOVOPLAN_RELEASE_SSH_KEY_B64 secret is required for git+ssh release dependencies." - exit 1 - fi - printf '%s' "$GOVOPLAN_RELEASE_SSH_KEY_B64" | base64 -d > ~/.ssh/id_ed25519 - chmod 600 ~/.ssh/id_ed25519 - echo 'git.add-ideas.de ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDe48IOof2fJS1dTbJtLWQnWnr+JorZXKIFdOAM9ct8G' > ~/.ssh/known_hosts - chmod 600 ~/.ssh/known_hosts + git config --global --add url."https://git.add-ideas.de/add-ideas/govoplan".insteadOf "git@git.add-ideas.de:add-ideas/govoplan" + git config --global --add url."https://git.add-ideas.de/add-ideas/govoplan".insteadOf "ssh://git@git.add-ideas.de/add-ideas/govoplan" - name: Bootstrap GovOPlaN repositories working-directory: govoplan - run: python tools/repo/bootstrap-repositories.py --parent .. + run: python tools/repo/bootstrap-repositories.py --parent .. --transport public-https --exclude-repo addideas-govoplan-website - name: Install backend release integration dependencies working-directory: govoplan run: | diff --git a/.gitea/workflows/security-audit.yml b/.gitea/workflows/security-audit.yml index 1c09678..5806ca3 100644 --- a/.gitea/workflows/security-audit.yml +++ b/.gitea/workflows/security-audit.yml @@ -1,7 +1,6 @@ name: Security Audit on: - pull_request: push: branches: - main @@ -21,6 +20,10 @@ jobs: - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 with: path: govoplan + - name: Use anonymous HTTPS for public GovOPlaN repositories + run: | + git config --global --add url."https://git.add-ideas.de/add-ideas/govoplan".insteadOf "git@git.add-ideas.de:add-ideas/govoplan" + git config --global --add url."https://git.add-ideas.de/add-ideas/govoplan".insteadOf "ssh://git@git.add-ideas.de/add-ideas/govoplan" - name: Configure SSH for repository bootstrap env: GOVOPLAN_RELEASE_SSH_KEY_B64: ${{ secrets.GOVOPLAN_RELEASE_SSH_KEY_B64 }} @@ -37,8 +40,8 @@ jobs: chmod 600 ~/.ssh/known_hosts - name: Bootstrap GovOPlaN repositories working-directory: govoplan - run: python tools/repo/bootstrap-repositories.py --parent .. - - name: Run security audit + run: python tools/repo/bootstrap-repositories.py --parent .. --transport public-https + - name: Run whole-system security audit working-directory: govoplan run: tools/checks/security-audit/run.sh --mode "$SECURITY_AUDIT_MODE" --scope "$SECURITY_AUDIT_SCOPE" --reports-dir audit-reports - name: Upload audit reports diff --git a/docs/SECURITY_AUDIT.md b/docs/SECURITY_AUDIT.md index 6071c0d..db0fe7b 100644 --- a/docs/SECURITY_AUDIT.md +++ b/docs/SECURITY_AUDIT.md @@ -162,7 +162,12 @@ clusters that cross module ownership or make behavior harder to change safely. The regular `Security Audit` workflow reuses the fingerprinted toolbox image when the Docker daemon is persistent, which is the normal case for the -self-hosted Gitea runner using the host Docker socket. The separate +self-hosted Gitea runner using the host Docker socket. Trusted push, schedule, +and manual runs scan all registered repositories; authenticated SSH is used +only for the private website repository. Pull-request audit runs stay disabled +while the audit runner exposes its host Docker socket: PR-controlled audit code +must run on a disposable or rootless runner without host-socket access. The +separate `Security Audit Toolbox Update` workflow runs weekly with `SECURITY_AUDIT_UPDATE=1`; it pulls current base images and re-resolves the allowed tool version ranges into a refreshed local image. diff --git a/tools/checks/security-audit/run.sh b/tools/checks/security-audit/run.sh old mode 100644 new mode 100755