fix: diagnostic semgrep-core dans le job security - CPU, disque et exec brute traces BUG-091
This commit is contained in:
+28
-2
@@ -141,9 +141,11 @@ jobs:
|
||||
# fixe tomli~=2.0.1 (pip-audit 2.10+ exige >=2.2.1) et
|
||||
# pyjwt~=2.12.0 (PYSEC-2026-178) — le plancher pyjwt>=2.13.0 de
|
||||
# requirements.txt resterait insatisfaisable s'il était co-installé.
|
||||
# 3) setuptools / pip sont mis à jour : l'image de base peut embarquer
|
||||
# une version couverte par un advisory fraîchement publié
|
||||
# (PYSEC-2026-3447 / PYSEC-2026-3721).
|
||||
# NOTE runner Gitea Act (BUG-083) : aucun `#` dans le `run:`.
|
||||
run: |
|
||||
# setuptools récent : l'image de base peut embarquer une version
|
||||
# couverte par un advisory fraîchement publié (PYSEC-2026-3447).
|
||||
pip install -U pip setuptools
|
||||
pip install bandit pip-audit
|
||||
pip install -r backend/requirements.txt
|
||||
@@ -156,6 +158,30 @@ jobs:
|
||||
# vrais positifs restants portent un `# nosec` justifié inline.
|
||||
run: bandit -r backend/ --skip B101,B105,B110,B310
|
||||
|
||||
- name: Diagnostic semgrep-core (BUG-091)
|
||||
# Le core est un exécutable natif : sur un CPU trop ancien il sort en
|
||||
# 127 sans message exploitable. On trace CPU, taille/permissions du
|
||||
# core et exécution brute pour distinguer un refus ISA/libc d'un
|
||||
# simple fichier absent ou non exécutable.
|
||||
# NOTE runner Gitea Act (BUG-083) : aucun `#` dans le `run:`.
|
||||
run: |
|
||||
echo "== CPU =="
|
||||
grep -m1 "model name" /proc/cpuinfo || echo "cpuinfo illisible"
|
||||
echo -n "flags attendues : "
|
||||
for f in sse4_2 popcnt avx avx2; do
|
||||
if grep -qm1 " $f " /proc/cpuinfo; then echo -n "$f "; fi
|
||||
done
|
||||
echo
|
||||
echo "== disque =="
|
||||
df -h /tmp | tail -1 || true
|
||||
echo "== core =="
|
||||
CORE=$(/tmp/semgrep-venv/bin/python -c "import semgrep,os;print(os.path.join(os.path.dirname(semgrep.__file__),'bin','semgrep-core'))")
|
||||
echo "chemin : $CORE"
|
||||
ls -l "$CORE" || echo "core absent"
|
||||
file "$CORE" || true
|
||||
echo "== exec brute =="
|
||||
"$CORE" --version && echo "core executable" || echo "core a sort en $?"
|
||||
|
||||
- name: Semgrep (SAST local, bloquant — #87)
|
||||
# Règles 100 % locales (semgrep-rules/, 8 règles) : aucun
|
||||
# téléchargement de registre (runner au réseau fragile).
|
||||
|
||||
+5
-1
@@ -6,7 +6,7 @@ Format basé sur [Keep a Changelog](https://keepachangelog.com/fr/1.1.0/),
|
||||
et [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
|
||||
|
||||
> **En cours de développement** : les changements à venir sont listés dans la section
|
||||
> [Unreleased](#unreleased). La dernière version livrée est **2.39.3**.
|
||||
> [Unreleased](#unreleased). La dernière version livrée est **2.39.4**.
|
||||
|
||||
---
|
||||
|
||||
@@ -14,6 +14,10 @@ et [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
|
||||
|
||||
---
|
||||
|
||||
## [2.39.4] — 2026-09-29
|
||||
|
||||
---
|
||||
|
||||
## [2.39.3] — 2026-09-28
|
||||
|
||||
---
|
||||
|
||||
+3
-3
@@ -4,7 +4,7 @@
|
||||
|
||||
**Porte d'entrée web ultra-léger pour vos vaults Obsidian** — Accédez, naviguez et recherchez dans toutes vos notes Obsidian depuis n'importe quel appareil via une interface web moderne et responsive.
|
||||
|
||||
[]()
|
||||
[]()
|
||||
[](https://opensource.org/licenses/MIT)
|
||||
[](https://www.docker.com/)
|
||||
[](https://www.python.org/)
|
||||
@@ -976,8 +976,8 @@ Ce projet est sous licence **MIT** — voir le fichier [LICENSE](LICENSE) pour l
|
||||
|
||||
## 📝 Changelog
|
||||
|
||||
Consultez le [CHANGELOG.md](./CHANGELOG.md) pour l'historique complet de toutes les versions (v1.0.0 → v2.39.3).
|
||||
Consultez le [CHANGELOG.md](./CHANGELOG.md) pour l'historique complet de toutes les versions (v1.0.0 → v2.39.4).
|
||||
|
||||
---
|
||||
|
||||
*Projet : ObsiGate | Version : 2.39.3 | Dernière mise à jour : Septembre 2026*
|
||||
*Projet : ObsiGate | Version : 2.39.4 | Dernière mise à jour : Septembre 2026*
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
|
||||
**Ultra-light web gateway for your Obsidian vaults** — Access, browse, and search all your Obsidian notes from any device via a modern, responsive web interface.
|
||||
|
||||
[]()
|
||||
[]()
|
||||
[](https://opensource.org/licenses/MIT)
|
||||
[](https://www.docker.com/)
|
||||
[](https://www.python.org/)
|
||||
@@ -1151,8 +1151,8 @@ This project is licensed under the **MIT License** - see the [LICENSE](LICENSE)
|
||||
|
||||
## 📝 Changelog
|
||||
|
||||
See [CHANGELOG.md](./CHANGELOG.md) for the complete version history (v1.0.0 → v2.39.3).
|
||||
See [CHANGELOG.md](./CHANGELOG.md) for the complete version history (v1.0.0 → v2.39.4).
|
||||
|
||||
---
|
||||
|
||||
*Project: ObsiGate | Version: 2.39.3 | Last updated: September 2026*
|
||||
*Project: ObsiGate | Version: 2.39.4 | Last updated: September 2026*
|
||||
|
||||
Generated
+1
-1
@@ -2626,7 +2626,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "obsigate-desktop"
|
||||
version = "2.39.3"
|
||||
version = "2.39.4"
|
||||
dependencies = [
|
||||
"chrono",
|
||||
"env_logger",
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "obsigate-desktop"
|
||||
version = "2.39.3"
|
||||
version = "2.39.4"
|
||||
description = "ObsiGate Desktop — Porte d'entrée native pour vos vaults Obsidian"
|
||||
authors = ["Bruno Charest"]
|
||||
edition = "2021"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"$schema": "https://raw.githubusercontent.com/nicedoc/obsigate/main/desktop/tauri.conf.schema.json",
|
||||
"productName": "ObsiGate",
|
||||
"version": "2.39.3",
|
||||
"version": "2.39.4",
|
||||
"identifier": "com.obsigate.desktop",
|
||||
"build": {
|
||||
"frontendDist": "../frontend",
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
# ObsiGate — Roadmap
|
||||
|
||||
> **Version :** 2.39.3 | **Dernière mise à jour :** 2026-09-28
|
||||
> **Version :** 2.39.4 | **Dernière mise à jour :** 2026-09-29
|
||||
> **Ce fichier ne contient que le travail à venir** (🔵 En cours + ⚪ Backlog) et un index compact
|
||||
> vers les fonctionnalités livrées.
|
||||
> - **Méthode de livraison à appliquer pour toute tâche : [DELIVERY_WORKFLOW.md](./DELIVERY_WORKFLOW.md)**
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "obsigate",
|
||||
"version": "2.39.3",
|
||||
"version": "2.39.4",
|
||||
"description": "**Porte d'entrée web ultra-léger pour vos vaults Obsidian** — Accédez, naviguez et recherchez dans toutes vos notes Obsidian depuis n'importe quel appareil via une interface web moderne et responsive.",
|
||||
"main": "patch.js",
|
||||
"directories": {
|
||||
|
||||
Reference in New Issue
Block a user