fix: diagnostic semgrep-core dans le job security - CPU, disque et exec brute traces BUG-091
CI / lint (push) Successful in 2m31s
CI / security (push) Failing after 2m16s
CI / test (push) Failing after 4m21s
CI / build (push) Skipped
CI / e2e (push) Skipped

This commit is contained in:
2026-09-29 09:21:25 -04:00
parent d6d081c0e9
commit dbf935bec0
10 changed files with 45 additions and 15 deletions
+28 -2
View File
@@ -141,9 +141,11 @@ jobs:
# fixe tomli~=2.0.1 (pip-audit 2.10+ exige >=2.2.1) et
# pyjwt~=2.12.0 (PYSEC-2026-178) — le plancher pyjwt>=2.13.0 de
# requirements.txt resterait insatisfaisable s'il était co-installé.
# 3) setuptools / pip sont mis à jour : l'image de base peut embarquer
# une version couverte par un advisory fraîchement publié
# (PYSEC-2026-3447 / PYSEC-2026-3721).
# NOTE runner Gitea Act (BUG-083) : aucun `#` dans le `run:`.
run: |
# setuptools récent : l'image de base peut embarquer une version
# couverte par un advisory fraîchement publié (PYSEC-2026-3447).
pip install -U pip setuptools
pip install bandit pip-audit
pip install -r backend/requirements.txt
@@ -156,6 +158,30 @@ jobs:
# vrais positifs restants portent un `# nosec` justifié inline.
run: bandit -r backend/ --skip B101,B105,B110,B310
- name: Diagnostic semgrep-core (BUG-091)
# Le core est un exécutable natif : sur un CPU trop ancien il sort en
# 127 sans message exploitable. On trace CPU, taille/permissions du
# core et exécution brute pour distinguer un refus ISA/libc d'un
# simple fichier absent ou non exécutable.
# NOTE runner Gitea Act (BUG-083) : aucun `#` dans le `run:`.
run: |
echo "== CPU =="
grep -m1 "model name" /proc/cpuinfo || echo "cpuinfo illisible"
echo -n "flags attendues : "
for f in sse4_2 popcnt avx avx2; do
if grep -qm1 " $f " /proc/cpuinfo; then echo -n "$f "; fi
done
echo
echo "== disque =="
df -h /tmp | tail -1 || true
echo "== core =="
CORE=$(/tmp/semgrep-venv/bin/python -c "import semgrep,os;print(os.path.join(os.path.dirname(semgrep.__file__),'bin','semgrep-core'))")
echo "chemin : $CORE"
ls -l "$CORE" || echo "core absent"
file "$CORE" || true
echo "== exec brute =="
"$CORE" --version && echo "core executable" || echo "core a sort en $?"
- name: Semgrep (SAST local, bloquant — #87)
# Règles 100 % locales (semgrep-rules/, 8 règles) : aucun
# téléchargement de registre (runner au réseau fragile).
+5 -1
View File
@@ -6,7 +6,7 @@ Format basé sur [Keep a Changelog](https://keepachangelog.com/fr/1.1.0/),
et [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
> **En cours de développement** : les changements à venir sont listés dans la section
> [Unreleased](#unreleased). La dernière version livrée est **2.39.3**.
> [Unreleased](#unreleased). La dernière version livrée est **2.39.4**.
---
@@ -14,6 +14,10 @@ et [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
---
## [2.39.4] — 2026-09-29
---
## [2.39.3] — 2026-09-28
---
+3 -3
View File
@@ -4,7 +4,7 @@
**Porte d'entrée web ultra-léger pour vos vaults Obsidian** — Accédez, naviguez et recherchez dans toutes vos notes Obsidian depuis n'importe quel appareil via une interface web moderne et responsive.
[![Version](https://img.shields.io/badge/Version-2.39.3-blue.svg)]()
[![Version](https://img.shields.io/badge/Version-2.39.4-blue.svg)]()
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)
[![Docker](https://img.shields.io/badge/Docker-Ready-blue.svg)](https://www.docker.com/)
[![Python](https://img.shields.io/badge/Python-3.11+-green.svg)](https://www.python.org/)
@@ -976,8 +976,8 @@ Ce projet est sous licence **MIT** — voir le fichier [LICENSE](LICENSE) pour l
## 📝 Changelog
Consultez le [CHANGELOG.md](./CHANGELOG.md) pour l'historique complet de toutes les versions (v1.0.0 → v2.39.3).
Consultez le [CHANGELOG.md](./CHANGELOG.md) pour l'historique complet de toutes les versions (v1.0.0 → v2.39.4).
---
*Projet : ObsiGate | Version : 2.39.3 | Dernière mise à jour : Septembre 2026*
*Projet : ObsiGate | Version : 2.39.4 | Dernière mise à jour : Septembre 2026*
+3 -3
View File
@@ -2,7 +2,7 @@
**Ultra-light web gateway for your Obsidian vaults** — Access, browse, and search all your Obsidian notes from any device via a modern, responsive web interface.
[![Version](https://img.shields.io/badge/Version-2.39.3-blue.svg)]()
[![Version](https://img.shields.io/badge/Version-2.39.4-blue.svg)]()
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)
[![Docker](https://img.shields.io/badge/Docker-Ready-blue.svg)](https://www.docker.com/)
[![Python](https://img.shields.io/badge/Python-3.11+-green.svg)](https://www.python.org/)
@@ -1151,8 +1151,8 @@ This project is licensed under the **MIT License** - see the [LICENSE](LICENSE)
## 📝 Changelog
See [CHANGELOG.md](./CHANGELOG.md) for the complete version history (v1.0.0 → v2.39.3).
See [CHANGELOG.md](./CHANGELOG.md) for the complete version history (v1.0.0 → v2.39.4).
---
*Project: ObsiGate | Version: 2.39.3 | Last updated: September 2026*
*Project: ObsiGate | Version: 2.39.4 | Last updated: September 2026*
+1 -1
View File
@@ -1 +1 @@
2.39.3
2.39.4
+1 -1
View File
@@ -2626,7 +2626,7 @@ dependencies = [
[[package]]
name = "obsigate-desktop"
version = "2.39.3"
version = "2.39.4"
dependencies = [
"chrono",
"env_logger",
+1 -1
View File
@@ -1,6 +1,6 @@
[package]
name = "obsigate-desktop"
version = "2.39.3"
version = "2.39.4"
description = "ObsiGate Desktop — Porte d'entrée native pour vos vaults Obsidian"
authors = ["Bruno Charest"]
edition = "2021"
+1 -1
View File
@@ -1,7 +1,7 @@
{
"$schema": "https://raw.githubusercontent.com/nicedoc/obsigate/main/desktop/tauri.conf.schema.json",
"productName": "ObsiGate",
"version": "2.39.3",
"version": "2.39.4",
"identifier": "com.obsigate.desktop",
"build": {
"frontendDist": "../frontend",
+1 -1
View File
@@ -1,6 +1,6 @@
# ObsiGate — Roadmap
> **Version :** 2.39.3 | **Dernière mise à jour :** 2026-09-28
> **Version :** 2.39.4 | **Dernière mise à jour :** 2026-09-29
> **Ce fichier ne contient que le travail à venir** (🔵 En cours + ⚪ Backlog) et un index compact
> vers les fonctionnalités livrées.
> - **Méthode de livraison à appliquer pour toute tâche : [DELIVERY_WORKFLOW.md](./DELIVERY_WORKFLOW.md)**
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "obsigate",
"version": "2.39.3",
"version": "2.39.4",
"description": "**Porte d'entrée web ultra-léger pour vos vaults Obsidian** — Accédez, naviguez et recherchez dans toutes vos notes Obsidian depuis n'importe quel appareil via une interface web moderne et responsive.",
"main": "patch.js",
"directories": {