ci: fix run #1880 — gitleaks false positives, gate docker/renovate on variables, e2e hard
CI / Build & Quality Checks (push) Successful in 1m39s
CI / Docker image build & smoke test (push) Skipped
CI / Secret scan (gitleaks) (push) Successful in 8s
CI / Trigger Desktop Build (push) Successful in 12s
CI / Playwright smoke (e2e) (push) Successful in 1m59s

- gitleaks flagged `STORAGE_KEY = 'cinny_recent_gifs_v1'` (a localStorage
  key name) as a generic API key. Allowlist namespaced cinny_/lotus- key
  names on *_KEY assignment lines, and skip dist/, node_modules/ and the
  vendored Element Call bundle (minified matrix-js-sdk crypto identifiers
  trip the same rule locally after a build). Verified: 0 findings on this
  tree with and without dist/ present.
- The runner has no `docker` binary and Gitea ignores job-level
  continue-on-error for the run conclusion, so the docker job painted the
  run red. It now runs only when the Actions variable CI_HAS_DOCKER is
  "true"; the weekly renovate job likewise only when RENOVATE_ENABLED is
  "true" (set alongside the RENOVATE_TOKEN secret).
- The Playwright e2e job passed on the runner, so it's a hard gate now.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
This commit is contained in:
2026-09-13 01:43:56 -04:00
co-authored by Claude Opus 5
parent ba0cc3e4b4
commit 2f47fa32ee
3 changed files with 31 additions and 9 deletions
+8 -8
View File
@@ -184,15 +184,16 @@ jobs:
# real image, boots it, and asserts both a 200 and the security headers # real image, boots it, and asserts both a 200 and the security headers
# added to docker-nginx.conf for #95. # added to docker-nginx.conf for #95.
# #
# `continue-on-error: true` — informational for now. The shared act_runner # Gated on the repo/org Actions VARIABLE `CI_HAS_DOCKER` == "true": run #1880
# may not expose a Docker daemon to job containers (same class of problem # proved the shared act_runner has no `docker` binary in job containers, and
# as the unreachable cache server noted above); flip this off once it's # Gitea does not honour job-level continue-on-error for the run conclusion,
# confirmed the runner can actually run `docker build`/`docker run` here. # so an unconditional job just paints every run red. Set the variable once a
# Docker-capable runner (or DinD) is attached; until then the job is skipped.
docker: docker:
name: Docker image build & smoke test name: Docker image build & smoke test
needs: build needs: build
if: ${{ vars.CI_HAS_DOCKER == 'true' }}
runs-on: ubuntu-latest runs-on: ubuntu-latest
continue-on-error: true
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: actions/checkout@v4
@@ -240,13 +241,12 @@ jobs:
# dist/ is rebuilt in-job because actions/upload-artifact@v4 does not work # dist/ is rebuilt in-job because actions/upload-artifact@v4 does not work
# on this Gitea runner (LOTUS_TODO), so `needs: build` only gates on the # on this Gitea runner (LOTUS_TODO), so `needs: build` only gates on the
# main job having passed, not on its artifact. # main job having passed, not on its artifact.
# continue-on-error: `playwright install --with-deps` needs apt on the # Hard gate: proven green on the runner in run #1880 (chromium + deps
# runner image; promote to hard once green on the runner. # install fine there). The E2EE tier self-skips without the E2E_* secrets.
e2e: e2e:
name: Playwright smoke (e2e) name: Playwright smoke (e2e)
needs: build needs: build
runs-on: ubuntu-latest runs-on: ubuntu-latest
continue-on-error: true
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: actions/checkout@v4
+6 -1
View File
@@ -17,7 +17,12 @@ jobs:
renovate: renovate:
name: Renovate name: Renovate
runs-on: ubuntu-latest runs-on: ubuntu-latest
continue-on-error: true # informational until RENOVATE_TOKEN is confirmed present # Gated on the Actions VARIABLE `RENOVATE_ENABLED` == "true" (set it together
# with the RENOVATE_TOKEN secret). Gitea ignores job-level continue-on-error
# for the run conclusion, so without the gate every weekly run would be red
# until the token exists. Also needs a Docker-capable runner (uses the
# renovate/renovate image) — see CI_HAS_DOCKER in ci.yml.
if: ${{ vars.RENOVATE_ENABLED == 'true' }}
steps: steps:
- name: Run Renovate - name: Run Renovate
uses: docker://renovate/renovate:44 uses: docker://renovate/renovate:44
+17
View File
@@ -16,4 +16,21 @@ regexes = [
paths = [ paths = [
'''config\.json''', '''config\.json''',
'''\.npmrc''', '''\.npmrc''',
# Build output and vendored bundles are not source — CI scans a fresh
# checkout, but a local run after `npm run build` would trip on minified
# matrix-js-sdk crypto identifiers (claimedEd25519Key etc.).
'''^dist/''',
'''^node_modules/''',
'''^public/element-call/''',
]
# localStorage / IndexedDB key NAMES (e.g. `STORAGE_KEY = 'cinny_recent_gifs_v1'`)
# match generic-api-key purely because the variable is called *_KEY. They are
# namespaced identifiers, not credentials.
[[rules]]
id = "generic-api-key"
[rules.allowlist]
regexTarget = "line"
regexes = [
'''(STORAGE|CACHE|IDB|DB|LS)_KEY\s*=\s*['"](cinny|lotus)[-_][a-z0-9_-]+['"]''',
] ]