Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
28 commits
Select commit Hold shift + click to select a range
e264e33
chore(deps): bump crytic/slither-action from 0.3.0 to 0.4.0
dependabot[bot] Oct 21, 2024
7cd9c3e
chore(deps): bump actions/checkout from 4.2.1 to 4.2.2
dependabot[bot] Oct 23, 2024
fabf048
chore(deps): bump actions/dependency-review-action from 4.3.4 to 4.5.0
dependabot[bot] Nov 20, 2024
ec2bf1a
Merge pull request #281 from rsksmart/QA-Test
Luisfc68 Dec 11, 2024
fd6bb5e
chore(deps): bump actions/upload-artifact from 4.4.0 to 4.5.0
dependabot[bot] Dec 18, 2024
c2c7050
chore(deps): bump github/codeql-action from 3.26.9 to 3.28.0
dependabot[bot] Dec 20, 2024
325913c
Merge pull request #286 from rsksmart/dependabot/github_actions/githu…
Luisfc68 Jan 17, 2025
54012a5
Merge branch 'master' into dependabot/github_actions/actions/upload-a…
Luisfc68 Jan 17, 2025
a520f84
Merge pull request #284 from rsksmart/dependabot/github_actions/actio…
Luisfc68 Jan 17, 2025
b72d4bd
Merge branch 'master' into dependabot/github_actions/actions/dependen…
Luisfc68 Jan 17, 2025
47ef54b
Merge pull request #273 from rsksmart/dependabot/github_actions/actio…
Luisfc68 Jan 17, 2025
3ea58ef
Merge branch 'master' into dependabot/github_actions/crytic/slither-a…
Luisfc68 Jan 17, 2025
9bed03d
Merge pull request #252 from rsksmart/dependabot/github_actions/cryti…
Luisfc68 Jan 17, 2025
8d9131f
Merge branch 'master' into dependabot/github_actions/actions/checkout…
bernacodesido Jan 17, 2025
d1a71b7
Exclude openzeppelin contracts
bernacodesido Jan 17, 2025
3fedbad
Merge pull request #264 from rsksmart/dependabot/github_actions/actio…
Luisfc68 Jan 17, 2025
ece56bc
Configure codeQL
bernacodesido Jan 17, 2025
95c4460
Update .github/workflows/slither.yml
bernacodesido Jan 17, 2025
d030bcd
Merge branch 'master' into slither
bernacodesido Jan 17, 2025
aedf529
Merge branch 'master' into codeql
bernacodesido Jan 17, 2025
085dd1d
Merge pull request #297 from rsksmart/slither
Luisfc68 Jan 17, 2025
d7f57f3
Merge branch 'master' into codeql
Luisfc68 Jan 17, 2025
5808968
Merge pull request #298 from rsksmart/codeql
Luisfc68 Jan 17, 2025
45ffbe6
chore: add mainnet deploy info
Luisfc68 Jan 22, 2025
1721450
Merge pull request #314 from rsksmart/mainnet-deploy
Luisfc68 Jan 31, 2025
f5ca977
Merge branch 'master' into Stable-Test
Luisfc68 Jan 31, 2025
9249b30
Merge branch 'QA-Test' into Stable-Test
Luisfc68 Jul 16, 2025
545679d
chore: lint ci files
Luisfc68 Jul 16, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ jobs:
# Steps represent a sequence of tasks that will be executed as part of the job
steps:
# Checks-out your repository under $GITHUB_WORKSPACE, so your job can access it
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

- name: Use Node.js 20.15.1
uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4
Expand Down
44 changes: 44 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
name: "CodeQL"

on:
push:
branches: [master, Stable-Test, QA-Test]
pull_request:
branches: [master, Stable-Test, QA-Test]
schedule:
- cron: "0 6 * * *"

# Declare default permissions as read only.
permissions: read-all

jobs:
analyze:
name: Analyze
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write

strategy:
fail-fast: false
matrix:
language: [javascript]

steps:
- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

- name: Initialize CodeQL
uses: github/codeql-action/init@aa578102511db1f4524ed59b8cc2bae4f6e88195 #v3.27.6
with:
languages: ${{ matrix.language }}
queries: +security-and-quality

- name: Autobuild
uses: github/codeql-action/autobuild@aa578102511db1f4524ed59b8cc2bae4f6e88195 #v3.27.6

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@aa578102511db1f4524ed59b8cc2bae4f6e88195 #v3.27.6
with:
category: "/language:${{ matrix.language }}"
4 changes: 2 additions & 2 deletions .github/workflows/dependency-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,8 +20,8 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: "Checkout Repository"
uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- name: "Dependency Review"
uses: actions/dependency-review-action@5a2ce3f5b92ee19cbb1541a4984c76d921601d7c # v4.3.4
uses: actions/dependency-review-action@3b139cfc5fae8b618d3eae3675e383bb1769c019 # v4.5.0
with:
comment-summary-in-pr: true
6 changes: 3 additions & 3 deletions .github/workflows/scorecard.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ jobs:

steps:
- name: "Checkout code"
uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
persist-credentials: false

Expand All @@ -30,13 +30,13 @@ jobs:
publish_results: true

- name: "Upload artifact"
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
uses: actions/upload-artifact@6f51ac03b9356f520e9adb1b1b7802705f340c2b # v4.5.0
with:
name: SARIF file
path: results.sarif
retention-days: 5

- name: "Upload to code-scanning"
uses: github/codeql-action/upload-sarif@461ef6c76dfe95d5c364de2f431ddbd31a417628 # v3.26.9
uses: github/codeql-action/upload-sarif@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # v3.28.0
with:
sarif_file: results.sarif
7 changes: 3 additions & 4 deletions .github/workflows/slither.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ jobs:
security-events: write
packages: read
steps:
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

- name: Use Node.js 20.15.1
uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4
Expand All @@ -27,15 +27,14 @@ jobs:
run: npm ci

- name: Run Slither
uses: crytic/slither-action@6ef3a33e56de4e8f59488cf60858b5c1bf4967c0 # v0.3.0
uses: crytic/slither-action@f197989dea5b53e986d0f88c60a034ddd77ec9a8 # v0.4.0
id: slither
with:
sarif: results.sarif
fail-on: none
target: .
slither-args: --filter-paths "node_modules/|contracts/safe-test-contracts/"

- name: Upload SARIF file
uses: github/codeql-action/upload-sarif@461ef6c76dfe95d5c364de2f431ddbd31a417628 # v3.26.9
uses: github/codeql-action/upload-sarif@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # v3.28.0
with:
sarif_file: ${{ steps.slither.outputs.sarif }}
Loading
Loading