Skip to content

Commit 5a0537e

Browse files
ClupaimaplefoxgitronitkhokharrLuvya150jmirchh75
committed
chore: T2 2026 platform, CI and dependency updates
Brings the T2 2026 platform work from ontrack-features-t2-2026 11.0.x (reviewed and merged work) onto thoth-tech 11.0.x. Co-authored-by: maplefoxgit <s223932052@deakin.edu.au> Co-authored-by: Ronit Khokhar <ronitkhokharr@gmail.com> Co-authored-by: Maple Fox <s223932052@deakin.edu.au> Co-authored-by: luvya9203 <luvya.men@gmail.com> Co-authored-by: jmirchh75 <jmirch@live.com> Co-authored-by: mudith-perera <makawitagemudith@gmail.com> Co-authored-by: JOSHUA ERICKSON <jerickson@deakin.edu.au> Co-authored-by: Eloise Ridder-Strickland <eloise.ridderstrickland@gmail.com> Co-authored-by: blankb0t <benee0394@gmail.com>
1 parent dc76a5a commit 5a0537e

86 files changed

Lines changed: 5796 additions & 1224 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.dockerignore‎

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,32 @@
11
Dockerfile
22
.git
3+
.github
4+
.docker
5+
.bundle
6+
.env
7+
.env.*
8+
!.env.example
9+
.npmrc
10+
.gem/credentials
11+
.ssh
12+
.aws
13+
.config/gcloud
314
build
15+
coverage
416
dist
17+
log
518
node_modules
19+
tmp
620
vendor
721
student-work
22+
config/master.key
23+
config/credentials
24+
config/credentials.yml.enc
25+
**/*.key
26+
**/*.pem
27+
**/*.p12
28+
**/*.pfx
29+
**/*.jks
30+
**/*.keystore
31+
test
32+
test_files

‎.env.example‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
# Optional values for development through the legacy root docker-compose.yml.
2+
# Copy to .env. Database authentication remains the safe default. Never commit
3+
# an institution credential or reuse a production registration.
4+
DF_AUTH_METHOD=database
5+
DF_AAF_ISSUER_URL=
6+
DF_AAF_AUDIENCE_URL=http://localhost:3000
7+
DF_AAF_CALLBACK_URL=http://localhost:3000/api/auth/jwt
8+
DF_AAF_IDENTITY_PROVIDER_URL=
9+
DF_AAF_UNIQUE_URL=
10+
DF_AAF_AUTH_SIGNOUT_URL=
11+
DF_SECRET_KEY_AAF=

‎.github/dependabot.yml‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
# Set update schedule for GitHub Actions and Ruby dependencies
2+
3+
version: 2
4+
updates:
5+
- package-ecosystem: "github-actions"
6+
directory: "/"
7+
schedule:
8+
# Check for updates to GitHub Actions every week
9+
interval: "weekly"
10+
- package-ecosystem: "bundler"
11+
directory: "/"
12+
schedule:
13+
# Check for updates to Ruby gems every week
14+
interval: "weekly"

‎.github/workflows/codeql.yml‎

Lines changed: 16 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -13,16 +13,23 @@ name: "CodeQL"
1313

1414
on:
1515
push:
16-
branches: ["development"]
17-
pull_request:
18-
# The branches below must be a subset of the branches above
19-
branches: ["development"]
16+
branches: ["11.0.x", "development"]
17+
# CodeQL is a required check, so it must report for pull requests targeting
18+
# any protected shared branch rather than only the branches listed above.
19+
pull_request: {}
2020
schedule:
2121
- cron: "45 20 * * 3"
2222

23+
# A push to an open pull request would otherwise start a second analysis while
24+
# the first is still running. Cancel the superseded run so only the newest head
25+
# of each ref is analysed.
26+
concurrency:
27+
group: codeql-${{ github.ref }}
28+
cancel-in-progress: true
29+
2330
jobs:
2431
analyze:
25-
name: Analyze
32+
name: CodeQL
2633
runs-on: ubuntu-latest
2734
permissions:
2835
actions: read
@@ -38,11 +45,11 @@ jobs:
3845

3946
steps:
4047
- name: Checkout repository
41-
uses: actions/checkout@v4
48+
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
4249

4350
# Initializes the CodeQL tools for scanning.
4451
- name: Initialize CodeQL
45-
uses: github/codeql-action/init@v3
52+
uses: github/codeql-action/init@6d786de4d6f3531a740e445b53a42b622bbbace8 # v3
4653
with:
4754
languages: ${{ matrix.language }}
4855
# If you wish to specify custom queries, you can do so here or in a config file.
@@ -55,7 +62,7 @@ jobs:
5562
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
5663
# If this step fails, then you should remove it and run the build manually (see below)
5764
- name: Autobuild
58-
uses: github/codeql-action/autobuild@v3
65+
uses: github/codeql-action/autobuild@6d786de4d6f3531a740e445b53a42b622bbbace8 # v3
5966

6067
# ℹ️ Command-line programs to run using the OS shell.
6168
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
@@ -68,4 +75,4 @@ jobs:
6875
# ./location_of_script_within_repo/buildscript.sh
6976

7077
- name: Perform CodeQL Analysis
71-
uses: github/codeql-action/analyze@v3
78+
uses: github/codeql-action/analyze@6d786de4d6f3531a740e445b53a42b622bbbace8 # v3

‎.github/workflows/deployment.yml‎

Lines changed: 30 additions & 45 deletions
Original file line numberDiff line numberDiff line change
@@ -1,45 +1,36 @@
1-
name: create-doubtfire-deployment
1+
name: Legacy image validation (non-publishing)
22
on:
3-
push:
4-
tags:
5-
- "v*"
6-
# branches:
7-
# - '*.x'
8-
# - 'development'
9-
# - 'main'
10-
deployment:
113
workflow_dispatch:
4+
5+
permissions:
6+
contents: read
7+
128
jobs:
139
docker-deploy-development-image:
1410
if: github.repository_owner == 'doubtfire-lms'
1511
environment: doubtfire
1612
runs-on: ubuntu-latest
1713
steps:
1814
- name: Checkout code
19-
uses: actions/checkout@v4
15+
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
2016
- name: Set up Docker Buildx
21-
uses: docker/setup-buildx-action@v3
22-
- name: Login to DockerHub
23-
uses: docker/login-action@v3
24-
if: github.event_name != 'pull_request'
25-
with:
26-
username: ${{ secrets.DOCKERHUB_USERNAME }}
27-
password: ${{ secrets.DOCKERHUB_TOKEN }}
17+
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
2818
- name: Setup meta for development image
2919
id: docker_meta
30-
uses: docker/metadata-action@v5
20+
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5
3121
with:
3222
images: lmsdoubtfire/doubtfire-api
3323
tags: |
3424
type=semver,pattern={{major}}.{{minor}}.x-dev
25+
type=sha,prefix=manual-
3526
- name: Build and push api server
3627
id: docker_build
37-
uses: docker/build-push-action@v5
28+
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6
3829
with:
3930
context: .
40-
push: ${{ github.event_name != 'pull_request' }}
31+
push: false
4132
tags: ${{ steps.docker_meta.outputs.tags }}
42-
labels: ${{ steps.meta.outputs.labels }}
33+
labels: ${{ steps.docker_meta.outputs.labels }}
4334
- name: Image digest
4435
run: echo ${{ steps.docker_build.outputs.digest }}
4536
docker-api-server:
@@ -48,18 +39,12 @@ jobs:
4839
runs-on: ubuntu-latest
4940
steps:
5041
- name: Checkout code
51-
uses: actions/checkout@v4
42+
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
5243
- name: Set up Docker Buildx
53-
uses: docker/setup-buildx-action@v3
54-
- name: Login to DockerHub
55-
uses: docker/login-action@v3
56-
if: github.event_name != 'pull_request'
57-
with:
58-
username: ${{ secrets.DOCKERHUB_USERNAME }}
59-
password: ${{ secrets.DOCKERHUB_TOKEN }}
44+
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
6045
- name: Setup meta for api server
6146
id: docker_meta
62-
uses: docker/metadata-action@v5
47+
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5
6348
with:
6449
images: lmsdoubtfire/apiServer
6550
tags: |
@@ -68,15 +53,18 @@ jobs:
6853
type=semver,pattern=prod-{{version}}
6954
type=semver,pattern=prod-{{major}}.{{minor}}
7055
type=semver,pattern=prod-{{major}}
56+
type=sha,prefix=manual-
7157
- name: Build and push api server
7258
id: docker_build
73-
uses: docker/build-push-action@v5
59+
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6
7460
with:
7561
file: deployApi.Dockerfile
7662
context: .
77-
push: ${{ github.event_name != 'pull_request' }}
63+
push: false
7864
tags: ${{ steps.docker_meta.outputs.tags }}
79-
labels: ${{ steps.meta.outputs.labels }}
65+
labels: ${{ steps.docker_meta.outputs.labels }}
66+
sbom: true
67+
provenance: mode=max
8068
- name: Image digest
8169
run: echo ${{ steps.docker_build.outputs.digest }}
8270
docker-app-server:
@@ -85,18 +73,12 @@ jobs:
8573
runs-on: ubuntu-latest
8674
steps:
8775
- name: Checkout code
88-
uses: actions/checkout@v4
76+
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
8977
- name: Set up Docker Buildx
90-
uses: docker/setup-buildx-action@v3
91-
- name: Login to DockerHub
92-
uses: docker/login-action@v3
93-
if: github.event_name != 'pull_request'
94-
with:
95-
username: ${{ secrets.DOCKERHUB_USERNAME }}
96-
password: ${{ secrets.DOCKERHUB_TOKEN }}
78+
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
9779
- name: Setup meta for app server
9880
id: docker_meta
99-
uses: docker/metadata-action@v5
81+
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5
10082
with:
10183
images: lmsdoubtfire/appServer
10284
tags: |
@@ -105,14 +87,17 @@ jobs:
10587
type=semver,pattern=prod-{{version}}
10688
type=semver,pattern=prod-{{major}}.{{minor}}
10789
type=semver,pattern=prod-{{major}}
90+
type=sha,prefix=manual-
10891
- name: Build and push app server
10992
id: docker_build
110-
uses: docker/build-push-action@v5
93+
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6
11194
with:
11295
file: deployAppSvr.Dockerfile
11396
context: .
11497
tags: ${{ steps.docker_meta.outputs.tags }}
115-
labels: ${{ steps.meta.outputs.labels }}
116-
push: ${{ github.event_name != 'pull_request' }}
98+
labels: ${{ steps.docker_meta.outputs.labels }}
99+
push: false
100+
sbom: true
101+
provenance: mode=max
117102
- name: Image digest
118103
run: echo ${{ steps.docker_build.outputs.digest }}
Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
name: Production image builds
2+
3+
on:
4+
pull_request:
5+
push:
6+
branches:
7+
- "*.x"
8+
workflow_dispatch:
9+
10+
permissions:
11+
contents: read
12+
13+
concurrency:
14+
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
15+
cancel-in-progress: true
16+
17+
jobs:
18+
build:
19+
name: Build ${{ matrix.name }}
20+
runs-on: ubuntu-latest
21+
timeout-minutes: 60
22+
strategy:
23+
fail-fast: false
24+
matrix:
25+
include:
26+
- name: API
27+
dockerfile: deployApi.Dockerfile
28+
cache_scope: production-api
29+
- name: app worker
30+
dockerfile: deployAppSvr.Dockerfile
31+
cache_scope: production-app
32+
- name: TeX Live helper
33+
dockerfile: texlive.Dockerfile
34+
cache_scope: production-texlive
35+
- name: JPlag helper
36+
dockerfile: jplag.Dockerfile
37+
cache_scope: production-jplag
38+
39+
steps:
40+
- name: Check out source
41+
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
42+
43+
- name: Set up Docker Buildx
44+
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
45+
46+
- name: Build production image without publishing
47+
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6
48+
with:
49+
context: .
50+
file: ${{ matrix.dockerfile }}
51+
platforms: linux/amd64
52+
push: false
53+
sbom: true
54+
provenance: mode=max
55+
cache-from: type=gha,scope=${{ matrix.cache_scope }}
56+
cache-to: type=gha,mode=max,scope=${{ matrix.cache_scope }}

0 commit comments

Comments
 (0)