Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 5 additions & 3 deletions .github/workflows/helm-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,9 +28,7 @@ on:
required: true

permissions:
contents: write # push to gh-pages + create per-chart Release
packages: write # push helm chart to ghcr.io OCI registry
pages: read
contents: read # least-privilege at top level; write scoped per job

concurrency:
group: helm-publish-${{ github.repository }}
Expand All @@ -39,6 +37,10 @@ concurrency:
jobs:
publish:
runs-on: ubuntu-latest
permissions:
contents: write # push to gh-pages + create per-chart Release
packages: write # push helm chart to ghcr.io OCI registry
pages: read
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -266,13 +266,13 @@ jobs:
contents: read
steps:
- name: Checkout release repo
uses: actions/checkout@v6
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6
with:
repository: keiailab/postgres-operator
ref: ${{ needs.preflight.outputs.tag }}
path: source
- name: Checkout community-operators fork
uses: actions/checkout@v6
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6
with:
repository: eightynine01/community-operators
token: ${{ secrets.COMMUNITY_OPERATORS_PAT }}
Expand Down
6 changes: 4 additions & 2 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -217,13 +217,13 @@ hooks-check: ## 현재 repo 에 lefthook hook 이 설치되어 있는지 확인
.PHONY: audit
audit: ## govulncheck + trivy + gosec — RFC 0002 L3 security 게이트 (3-repo 정합).
@echo "=== govulncheck (call-graph CVE) ==="
@command -v $(GOBIN)/govulncheck >/dev/null 2>&1 || go install golang.org/x/vuln/cmd/govulncheck@latest
@command -v $(GOBIN)/govulncheck >/dev/null 2>&1 || go install golang.org/x/vuln/cmd/govulncheck@$(GOVULNCHECK_VERSION)
$(GOBIN)/govulncheck ./...
@echo "=== trivy fs (lockfile + base CVE) ==="
@command -v trivy >/dev/null 2>&1 || { echo "[error] trivy not installed: brew install trivy (or apt install trivy)"; exit 1; }
trivy fs --severity HIGH,CRITICAL --exit-code 1 --ignore-unfixed --skip-dirs vendor,bin,tmp .
@echo "=== gosec (HIGH only) ==="
@command -v $(GOBIN)/gosec >/dev/null 2>&1 || go install github.com/securego/gosec/v2/cmd/gosec@latest
@command -v $(GOBIN)/gosec >/dev/null 2>&1 || go install github.com/securego/gosec/v2/cmd/gosec@$(GOSEC_VERSION)
$(GOBIN)/gosec -quiet -severity high ./internal/...

.PHONY: test-scripts
Expand Down Expand Up @@ -610,6 +610,8 @@ ENVTEST_K8S_VERSION ?= $(shell v='$(call gomodver,k8s.io/api)'; \
printf '%s\n' "$$v" | sed -E 's/^v?[0-9]+\.([0-9]+).*/1.\1/')

GOLANGCI_LINT_VERSION ?= v2.8.0
GOVULNCHECK_VERSION ?= v1.8.0
GOSEC_VERSION ?= v2.29.0
.PHONY: kustomize
kustomize: $(KUSTOMIZE) ## Download kustomize locally if necessary.
$(KUSTOMIZE): $(LOCALBIN)
Expand Down
Loading