Commit Graph

86 Commits

Author SHA1 Message Date
dependabot[bot] 0efaa0534e build(deps): bump aquasecurity/trivy-action from 0.4.1 to 0.5.0 (#4811)
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) from 0.4.1 to 0.5.0.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases)
- [Commits](https://github.com/aquasecurity/trivy-action/compare/0.4.1...0.5.0)

---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-06-23 16:38:59 +02:00
Juan Antonio Osorio f41f84d1f9 ci: Use Trivy for vulnerability scans (#4804)
This uses Trivy to scan both the Git repo, as well as the generated
container image for vulnerabilities. It leverages Trivy's GitHub action
[1]. Currently, it's set to alert on `CRITICAL` and `HIGH`
vulnerabilities only.

[1] https://github.com/aquasecurity/trivy-action

This adds a section in the developer docs, as well as comments on the GitHub workflows.

Signed-off-by: Juan Antonio Osorio <juan.osoriorobles@eu.equinix.com>
2022-06-23 08:17:28 +02:00
Peter ONeill 45343c88c4 Updating the feature request questions (#4784)
Signed-off-by: Peter ONeill <peteroneilljr@gmail.com>
2022-06-20 11:04:02 +02:00
Stephan Renatus 9a6bdaf9c4 ci/npm-opa-wasm: remove (#4758)
To be brought back eventually; for now, it is just randomly failing.

We haven't been touching the Wasm interface in a while, so this test
isn't urgently needed these days.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-06-09 11:46:51 +02:00
Stephan Renatus b271372338 build: add v0.41.0 builtin_metadata manually, pin npm-opa-wasm in CI (#4753)
* builtin_metadata: add v0.41.0 manually

We'll figure out how to do this in the release process, but for now, this
is enough to not have the builtin_metadata.json change appear in each PR.

* ci: pin last release of npm-opa-wasm

This is temporary; I don't want to deal with this right now.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-06-08 10:28:24 +02:00
dependabot[bot] 4b2e980c86 build(deps): bump docker/setup-buildx-action from 1 to 2 (#4669)
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 1 to 2.
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](https://github.com/docker/setup-buildx-action/compare/v1...v2)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-05-06 14:07:10 +02:00
dependabot[bot] 858acdbf6f build(deps): bump docker/setup-qemu-action from 1 to 2 (#4668) 2022-05-06 11:37:41 +00:00
dependabot[bot] f27360c0b9 build(deps): bump github/codeql-action from 1 to 2 (#4621)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 1 to 2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/v1...v2)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-04-26 13:31:42 +02:00
Naveen a2595c1e4f workflow: no content permissions for GitHub action 'post-release' (#4579)
Restrict the GitHub token permissions only to the required ones; this way, even if the attackers will succeed in compromising your workflow, they won’t be able to do much.

See also:
https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions
https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs
https://securitylab.github.com/research/github-actions-preventing-pwn-requests/

NOTE(sr): This is a first step, there are probably more opportunities for restricting permissions
in our workflows.

Signed-off-by: naveensrinivasan <172697+naveensrinivasan@users.noreply.github.com>
2022-04-20 09:15:50 +02:00
dependabot[bot] 6c2aad0fff build(deps): bump actions/download-artifact from 2 to 3 (#4575) 2022-04-11 12:07:03 +00:00
dependabot[bot] c9606c07a4 build(deps): bump actions/setup-go from 2 to 3 (#4574) 2022-04-11 11:54:09 +00:00
dependabot[bot] d618ba3142 build(deps): bump actions/upload-artifact from 2 to 3 (#4573) 2022-04-11 11:40:44 +00:00
Stephan Renatus a940cb636e ci: misc test-related fixes (#4549)
* topdown: fix TestRego: run for all go versions, excluding the x509 error

That error has a different message on go1.16.

The previous attempt to exclude them from running caused _all tests_
to not be run.

* topdown_test/TestTopDownQueryCancellationEvery: up wait time for macos flakey tests

We've often seen this fail with "0 notes". Waiting for 10x the time
we previous waited for still seems to do the trick but should
hopefully remove the amount of failures we see in CE because of
slow macos runners.

* ci: don't run wasm build again in compat builds

The build is docker-based, and doesn't differ at all if run from a
different version of golang. So instead of re-building it in the
separate matrix jobs, we'll use the artifacts downloaded from the
artifact build job.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-04-05 13:57:04 +02:00
Stephan Renatus 6673f3e81a ci: fix rego check (#4532)
* build/policies: format using 0.39.0
* workflow/pull-request: use edge opa for rego PR checks

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-04-01 09:31:13 +02:00
Stephan Renatus 14c2906afb ci: remove go-fuzz, use native go 1.18 fuzzer
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-03-28 07:24:21 +02:00
Stephan Renatus d2914c0d54 build: bump golang: 1.17 -> 1.18
No change to go.mod's `go` stanza, so no changes in code compatibility.

However, it's used for building our docker images and release
binaries, and for fuzz testing in our nightly workflow.

Some test-related changes with the dns lookup built-in function's
error handling; and the hardcoded signature. Running

    go test ./topdown -run TestTopdownJWTEncodeSignECWithSeedReturnsSameSignature -count 10000

makes me believe that for whatever reason the signature changed,
it's at least stable.

topdown/http_test: Test-only change to accomodate this change in Go (https://go.dev/doc/go1.18):

    Certificate.Verify now uses platform APIs to verify certificate
    validity on macOS and iOS when it is called with a nil
    VerifyOpts.Roots or when using the root pool returned from
    SystemCertPool.

We're keeping the old message for go <= 1.17; in a silly-simple way.

Also:

* ci: build and test two old golang version on macos|linux

  We'll drop golang 1.15, keep one unsupported version (1.16).

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-03-28 07:24:21 +02:00
Anders Eknert b023fd1607 cicd: verify logo name matches integration (#4441)
Signed-off-by: Anders Eknert <anders@eknert.com>
2022-03-17 07:06:56 +01:00
Anders Eknert d2684b995c Use gid=1000 in -rootless images (#4407)
Fixes #4380

Signed-off-by: Anders Eknert <anders@eknert.com>
2022-03-04 13:19:48 +01:00
dependabot[bot] cd36c744f4 build(deps): bump actions/checkout from 2 to 3 (#4395) 2022-03-02 11:36:40 +00:00
Stephan Renatus c4ab4b35c9 ast/parser: parse 'with' on 'some x in xs' expression (#4371)
Fixes #4226.

Also
* adds a YAML test to ensure that this works fine end-to-end.
* ci(pull-request): show input on failure

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-02-22 13:43:02 +01:00
Stephan Renatus 5e2da14efd build: use proper action token secret name (#4299)
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-01-28 14:00:23 +01:00
Stephan Renatus 26610645a0 build: work around issues (#4298)
* Makefile: temporary disable "delete" for edge bucket sync

This is a bandaid to be reverted when we've fixed the IAM policy
protecting the bucket to allow for deletions.

* workflow: re-enable token in checkout

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-01-28 13:53:03 +01:00
Stephan Renatus 19d6bc4026 build: don't build and push non-static edge arm64 binaries (#4293)
* build: don't push arm64 binaries to edge releases

They're not built for a release, but we'd still be publishing
them to the edge S3 bucket post-merge.

* build: silence 'aws s3 sync' output

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-01-27 11:59:32 +01:00
Stephan Renatus ba27caa1af build: only build/publish/test static binaries/images for linux/arm64 (#4282)
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-01-27 09:46:59 +01:00
Nick Graef db4d9872cc ci: publish multi-arch image manifest lists (#4254)
This change adds linux/arm64 binaries to the release. It also publishes an arm64
container image for all variants (standard, debug, rootless, static) and releases
(dev, edge, latest).

The build and push process uses buildx in order to push the individual
images by digest (i.e. untagged) and reference them in a single, tagged manifest
list. This avoids cluttering Docker Hub's tag list with `<tag>-<arch>` tags.

Fixes #2233

Signed-off-by: Nick Graef <1031317+ngraef@users.noreply.github.com>
2022-01-24 19:00:09 +01:00
Anders Eknert 54f79cee8f Change setup-opa action to new location
Signed-off-by: Anders Eknert <anders@eknert.com>
2022-01-21 15:27:50 -08:00
Anders Eknert 53b4b9ee5f Commit generated code/docs in same job (#4248)
Signed-off-by: Anders Eknert <anders@eknert.com>
2022-01-19 13:57:16 +01:00
Anders Eknert f272af65f6 Add CLI section to docs (#4241)
Fixes #3915

Signed-off-by: Anders Eknert <anders@eknert.com>
2022-01-19 13:00:09 +01:00
Anders Eknert fff9856bb7 Add Dapr integration (#4229)
Also included some improvements to the Rego checks:

* Pass GITHUB_TOKEN to policy to not exceed API quota
* Ensure required attributes included in integration
* Ensure commited .json files are valid JSON

Signed-off-by: Anders Eknert <anders@eknert.com>
2022-01-14 11:46:50 +01:00
Peter ONeill 95bcca1604 add community support template (#4208)
This template creates a link to the Feedback discussions board.

Signed-off-by: Peter ONeill <peteroneilljr@gmail.com>
2022-01-13 11:13:43 +01:00
Anders Eknert d3fbd53578 Build darwin/arm64 in post tag workflow (#4182)
Signed-off-by: Anders Eknert <anders@eknert.com>
2022-01-04 19:22:53 +01:00
Anders Eknert 0ddf1dbb94 Add Open Service Mesh to ecosystem (#4171)
Also:
* Add some links to Kubernetes authorization item
* Add SPIFFE/SPIRE blog
* Extend Rego tests to verify added/modified YAML files as valid

The last point was intended to be for the integrations.yaml file
only, but thinking more about it made sense not to limit the check
to a single file.

Signed-off-by: Anders Eknert <anders@eknert.com>
2021-12-30 20:25:32 +01:00
Anders Eknert 48b8be309e Check PR for mistakes in ecosystem page change (#4164)
Since both contributors and reviewers (i.e. me!) seem
to easily miss the correct location of the logo for a new
integration - add checks that will fail the PR when this
happens.

This is admittedly mostly for fun, but I figured it would
be pretty cool to explore whether we could integrate Rego
policies into our own build pipeline. There are definitely
more things to explore using the GitHub API as a datasource
for build pipeline policies, but this is at least a start.

Signed-off-by: Anders Eknert <anders@eknert.com>
2021-12-23 12:00:44 +01:00
Anders Eknert c56bc2f8f3 release: add Darwin ARM64 release target (#4060)
Somewhat experimental, but now that pretty much all new macs
run with the ARM64 architecture it would be nice to add it as
a target to our releases. Since there is currently no runner
for GitHub Actions (https://github.com/actions/runner/issues/805)
we can't yet run the binary smoke test for this architecture,
but I'm tracking the issue and hoping that can be resolved soon.

Feel free to dismiss this if you think this should wait until later.

Signed-off-by: Anders Eknert <anders@eknert.com>
2021-12-01 11:05:45 +01:00
Stephan Renatus d7448b5252 workflow: move go-mod-proxy check into nightly tests (#4056)
It seldomly matters for PRs, since only a tiny subset of them alters
dependencies. Having the check run in nightlies, where a failure does
not block a PR, but we still notice it through the notifications,
seems like a good trade-off.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2021-11-26 10:25:03 +01:00
Ashutosh Narkar 95c25b4b4e .github: Add stale bot to mark issues & PRs after a period of inactivity
Signed-off-by: Ashutosh Narkar <anarkar4387@gmail.com>
2021-11-22 09:53:59 -08:00
Peter ONeill 2dd62d92a0 Add adopters template (#4038)
Add adopters template

Signed-off-by: Peter ONeill <peteroneilljr@gmail.com>
2021-11-19 07:02:31 +01:00
Peter ONeill 9da74306d3 Updated contributing guide links (#4026)
Signed-off-by: Peter ONeill <peteroneilljr@gmail.com>
2021-11-18 08:23:00 +01:00
Peter ONeill 3d28e67b1c github: add templates for issues (#4006)
Creating templates for Bug Reports and Feature Requests

Signed-off-by: Peter ONeill <peteroneilljr@gmail.com>
2021-11-17 09:47:48 +01:00
Stephan Renatus 8a1aab376f ast+topdown: add net.lookup_ip_addr built-in function (#3995)
Since the golang stdlib function doesn't do any caching, we add the result
to the BuiltinContext.Cache so it's cached, and consistent, within a single
policy evaluation.

There is no decision made here about using netgo or netcgo: we're following
suit wrt how golang expects you to do it: From my understanding, using the
OS means for DNS resolution is the preferred way: it gives you per-host
caching, and it allows the user to affect how DNS resolution works in many
ways.

This means the same logic that applies to all other places where we resolve
domain names into addresses (notably `http.send`) applies to this built-in,
too.

Also:

* workflow/pull_request: don't fail-fast for matrix jobs

Even if one platform fails it would be interesting to see what happens
on the others.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2021-11-16 07:39:14 +01:00
Torin Sandall d687e0efb3 ci/codeql: Fix indentation issue
Signed-off-by: Torin Sandall <torinsandall@gmail.com>
2021-11-10 10:55:02 -08:00
Torin Sandall 8e217297c6 ci/codeql: Override autobuild and run make build instead
This way we do not have to run the entire test and benchmark suite
that takes about 25m in total.

Signed-off-by: Torin Sandall <torinsandall@gmail.com>
2021-11-10 10:48:30 -08:00
Torin Sandall 2f7a9e2dab ci: Tweak the post-tag workflow
* Do not run ci-release-tag target--the tests have already been run
  pre-merge and post-merge so there is little reason to run them again
  post-tag. The only thing this would do is find non-deterministic
  test failures--which begs the question: what do we do with the
  release? We already run tests pre-merge, post-merge, and nightly so
  it's unlikely that post-tag will help improve quality.

* Use the RELEASE_DIR from the makefile for the `hub release` asset
  parameter rather than assuming the TAG <=> RELEASE_DIR (this is not
  always true if tagging an arbitrary commit.) This enables us to cut
  release candidates without commiting changes to the repo.

Signed-off-by: Torin Sandall <torinsandall@gmail.com>
2021-11-05 16:33:41 -07:00
Torin Sandall b197376f27 ci: Add post release job to kick the netlify deploy (#3972)
Signed-off-by: Torin Sandall <torinsandall@gmail.com>
2021-11-05 07:34:20 +01:00
Stephan Renatus c23bf8d451 fuzz: add golang-native fuzzing to nightly tests (#3940)
This installs gotip (the lastest build) and uses its (beta) fuzzing feature in
the nightly tests.

We can remove the previous setup at a later date.

The "seed corpus" was converted from the previous fuzzer's using this script:

    package main

    import (
    	"bytes"
    	"fmt"
    	"io/ioutil"
    	"log"
    	"path/filepath"
    )

    const oldCorpusDir = "build/fuzzer/corpus/"
    const newCorpusDir = "ast/testdata/fuzz/FuzzParseStatementsAndCompileModules"

    func main() {
    	files, err := ioutil.ReadDir(oldCorpusDir)
    	if err != nil {
    		log.Fatal(err)
    	}
    	for _, f := range files {
    		c, err := ioutil.ReadFile(filepath.Join(oldCorpusDir, f.Name()))
    		if err != nil {
    			log.Fatal(err)
    		}
    		buf := bytes.Buffer{}
    		buf.WriteString("go test fuzz v1\n")
    		fmt.Fprintf(&buf, "string(%q)\n", string(c))
    		err = ioutil.WriteFile(filepath.Join(newCorpusDir, f.Name()), buf.Bytes(), 0644)
    		if err != nil {
    			log.Fatal(err)
    		}
    	}
    }

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2021-10-29 13:50:47 +02:00
Stephan Renatus 0aaf70ac21 workflow/nightly: dump all crashers to stdout
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2021-10-27 11:45:56 -07:00
Stephan Renatus 8b52a08b74 ci: check go proxy mod checksums (#3810)
This extra check is meant to catch go module proxy checksum mismatches,
like the one we've released 0.32.1 to fix, earlier.

It causes the go mod tooling to fetch all modules from their external sources,
most likely all github references, and compares the contents' checksums with
what we have in go.sum. It deliberately bypasses the "sumdb" service that is
part of the golang infrastructure.

The event of a mismatch would happen if a git tag was published, and later
changed, and the golang infrastructure's module proxy (and sumdb service)
had picked up the first tag. This is rather unlikely, and this test is thus a bit
over-cautious. The idea is that if it becomes invisible, it's fine to keep, and
gives us a bit of extra safety. However, if it becomes annoying (it's a giant
network dependency in our CI runs), it's not critical enough to be kept and
is OK to disable again.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2021-09-21 09:29:13 +02:00
Stephan Renatus 626e62780b dependabot: let it update all go + GHA dependencies (#3802)
* dependabot: let it update all go dependencies
* dependabot: also manage github actions

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2021-09-17 11:57:05 +02:00
Stephan Renatus 03020183df workflow/pull_request: run tests on macos (#3795)
This splits off the generate call, so that we can have the wasm bits (and capabilities.json) from the PR used in the PR checks.

The Perf check still is the one taking longest, even with the added matrix build job and the jobs depending on it. The test matrix job was split off to run those in parallel, the binary smoke tests for example can already proceed.

To simplify things, we're relying on the setup-go action for both the linux and the darwin unit tests. (We could also use it for the builds of linux and windows binaries... but there, I'm more concerned about a clean build env and reproducibility.)

Fixes #3176.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2021-09-16 09:27:31 +02:00
Stephan Renatus 4a4185d799 ci: ensure we can build with different go versions
We only check the build, not the tests.
And we only check the latest release of the 1.15 and 1.16 series.
since 1.17 is what we build and test with anyways.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2021-08-30 16:56:53 -07:00