diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index da7d5f073..03c64b965 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -184,15 +184,16 @@ jobs: # real image, boots it, and asserts both a 200 and the security headers # added to docker-nginx.conf for #95. # - # `continue-on-error: true` — informational for now. The shared act_runner - # may not expose a Docker daemon to job containers (same class of problem - # as the unreachable cache server noted above); flip this off once it's - # confirmed the runner can actually run `docker build`/`docker run` here. + # Gated on the repo/org Actions VARIABLE `CI_HAS_DOCKER` == "true": run #1880 + # proved the shared act_runner has no `docker` binary in job containers, and + # Gitea does not honour job-level continue-on-error for the run conclusion, + # so an unconditional job just paints every run red. Set the variable once a + # Docker-capable runner (or DinD) is attached; until then the job is skipped. docker: name: Docker image build & smoke test needs: build + if: ${{ vars.CI_HAS_DOCKER == 'true' }} runs-on: ubuntu-latest - continue-on-error: true steps: - name: Checkout uses: actions/checkout@v4 @@ -240,13 +241,12 @@ jobs: # dist/ is rebuilt in-job because actions/upload-artifact@v4 does not work # on this Gitea runner (LOTUS_TODO), so `needs: build` only gates on the # main job having passed, not on its artifact. - # continue-on-error: `playwright install --with-deps` needs apt on the - # runner image; promote to hard once green on the runner. + # Hard gate: proven green on the runner in run #1880 (chromium + deps + # install fine there). The E2EE tier self-skips without the E2E_* secrets. e2e: name: Playwright smoke (e2e) needs: build runs-on: ubuntu-latest - continue-on-error: true steps: - name: Checkout uses: actions/checkout@v4 diff --git a/.gitea/workflows/renovate.yml b/.gitea/workflows/renovate.yml index 570cd2f08..ccbf631d7 100644 --- a/.gitea/workflows/renovate.yml +++ b/.gitea/workflows/renovate.yml @@ -17,7 +17,12 @@ jobs: renovate: name: Renovate runs-on: ubuntu-latest - continue-on-error: true # informational until RENOVATE_TOKEN is confirmed present + # Gated on the Actions VARIABLE `RENOVATE_ENABLED` == "true" (set it together + # with the RENOVATE_TOKEN secret). Gitea ignores job-level continue-on-error + # for the run conclusion, so without the gate every weekly run would be red + # until the token exists. Also needs a Docker-capable runner (uses the + # renovate/renovate image) — see CI_HAS_DOCKER in ci.yml. + if: ${{ vars.RENOVATE_ENABLED == 'true' }} steps: - name: Run Renovate uses: docker://renovate/renovate:44 diff --git a/.gitleaks.toml b/.gitleaks.toml index 9f4c6e985..4b2c445c1 100644 --- a/.gitleaks.toml +++ b/.gitleaks.toml @@ -16,4 +16,21 @@ regexes = [ paths = [ '''config\.json''', '''\.npmrc''', + # Build output and vendored bundles are not source — CI scans a fresh + # checkout, but a local run after `npm run build` would trip on minified + # matrix-js-sdk crypto identifiers (claimedEd25519Key etc.). + '''^dist/''', + '''^node_modules/''', + '''^public/element-call/''', +] + +# localStorage / IndexedDB key NAMES (e.g. `STORAGE_KEY = 'cinny_recent_gifs_v1'`) +# match generic-api-key purely because the variable is called *_KEY. They are +# namespaced identifiers, not credentials. +[[rules]] +id = "generic-api-key" +[rules.allowlist] +regexTarget = "line" +regexes = [ + '''(STORAGE|CACHE|IDB|DB|LS)_KEY\s*=\s*['"](cinny|lotus)[-_][a-z0-9_-]+['"]''', ]