Compare commits

..
7 Commits
Author SHA1 Message Date
Stéphane Lesimple dcaed638f1 chore: release workflow: use a PR to sync source-build to master 2026-07-30 16:37:00 +02:00
github-actions[bot] 8f3f295a14 release: sync v26.36.0730501 from source-build
built from source-build commit ed7f348f83
 dated 2026-07-30 12:04:02 +0000
2026-07-30 12:35:24 +00:00
Stéphane Lesimple 85e5daad8f fix: release.yml: yaml syntax 2026-07-30 14:31:04 +02:00
Stéphane Lesimple a441987adb ci: add manual path-scoped release workflow (master-only)
Add .github/workflows/release.yml, triggered manually via workflow_dispatch,
with two independent actions:

  - sync-from-source-build: copy every top-level file from source-build
    except .github/ onto master as a single commit
  - draft-github-release: create a draft GitHub release from master's current
    script, with an auto-drafted changelog assembled from source-build.

This replaces merging source-build into master that caused modify/delete
conflict of the master-only workflows.
2026-07-30 14:09:32 +02:00
Stéphane Lesimple c1aee44717 chore: udpate stale github workflow 2026-06-06 19:00:05 +02:00
Stéphane Lesimple 4031b0f3bd chore: bump gh actions modules 2026-06-06 15:06:31 +02:00
Stéphane Lesimple d6624c30af v26.36.0602723 (#577)
* fix: arm64: collapse per-core CPU info lists to a single line (#576)

 built from commit 7d9345a32f
 dated 2026-06-02 17:21:31 +0000
 by Stéphane Lesimple (speed47_github@speed47.net)

 Store the per-core implementer/part/arch/variant/revision lists
space-separated (no embedded newlines, which also cleans up JSON and
prometheus output) and dedup them for the human-readable display, so
homogeneous systems show e.g. "0x41" instead of repeating it per core.
2026-06-02 18:05:47 +00:00
4 changed files with 448 additions and 0 deletions
+41
View File
@@ -0,0 +1,41 @@
name: autoupdate
on:
workflow_dispatch:
schedule:
- cron: '42 9 * * *'
permissions:
pull-requests: write
contents: write
jobs:
autoupdate:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
with:
ref: source
- name: Install prerequisites
run: sudo apt-get update && sudo apt-get install -y --no-install-recommends iucode-tool sqlite3 unzip shfmt
- name: Update microcode versions
run: ./scripts/update_mcedb.sh
- name: Update Intel models
run: ./scripts/update_intel_models.sh
- name: Check git diff
id: diff
run: |
echo change="$(git diff | awk '/MCEDB/ { if(V) { print V" to "$4; exit } else { V=$4 } }')" >> "$GITHUB_OUTPUT"
echo nbdiff="$(git diff | grep -cE -- '^\+# [AI],')" >> "$GITHUB_OUTPUT"
git diff
cat "$GITHUB_OUTPUT"
- name: Create Pull Request if needed
if: steps.diff.outputs.nbdiff != '0'
uses: peter-evans/create-pull-request@v7
with:
branch: autoupdate-fwdb
commit-message: "update: fwdb from ${{ steps.diff.outputs.change }}, ${{ steps.diff.outputs.nbdiff }} microcode changes"
title: "[Auto] Update fwdb from ${{ steps.diff.outputs.change }}"
body: |
Automated PR to update fwdb from ${{ steps.diff.outputs.change }}
Detected ${{ steps.diff.outputs.nbdiff }} microcode changes
+181
View File
@@ -0,0 +1,181 @@
name: release
# Manual, path-scoped release helper for master.
#
# `master` is BOTH the distribution branch (users download the script here)
# AND the default branch that hosts the scheduled CI workflows
# (autoupdate / stale / vuln-watch). `source-build` is a build-OUTPUT branch.
#
# We therefore never merge source-build into master: that would drag source-build's
# whole tree, including the *absence* of the master-only workflows.
# Instead we copy only the assembled artifact files across, and cut GitHub
# releases from master directly.
#
# Two independent manual actions to run against the `master` branch:
#
# 1. sync-from-source-build : open a PR against master carrying the assembled
# files (everything on source-build EXCEPT
# .github/). Nothing lands on master until the PR
# is reviewed and merged.
# 2. draft-github-release : create a DRAFT GitHub release from the script
# currently on master, with an auto-drafted
# changelog.
on:
workflow_dispatch:
inputs:
action:
description: What to do
type: choice
required: true
default: sync-from-source-build
options:
- sync-from-source-build
- draft-github-release
permissions:
contents: write
pull-requests: write
concurrency:
group: release-master
cancel-in-progress: false
jobs:
# ---------------------------------------------------------------------------
# 1. Copy assembled files from source-build onto master (no .github/),
# as a pull request.
# ---------------------------------------------------------------------------
sync-from-source-build:
if: inputs.action == 'sync-from-source-build'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
with:
ref: master
fetch-depth: 0
persist-credentials: true
- name: sync assembled files from source-build
id: sync
run: |
set -eu
git fetch --no-tags origin source-build
# Every top-level entry on source-build EXCEPT .github/ (master keeps
# its own CI). Computed dynamically so any new top-level artifact is
# picked up automatically.
readarray -t paths < <(git ls-tree --name-only origin/source-build | grep -vxF '.github')
echo "Syncing: ${paths[*]}"
# Mirror source-build exactly for those paths, removing first so that
# deletions/renames inside doc/ etc. propagate too.
for p in "${paths[@]}"; do rm -rf -- "$p"; done
git checkout origin/source-build -- "${paths[@]}"
git add --all -- "${paths[@]}"
if git diff --cached --quiet; then
echo "master already up to date with source-build; nothing to sync."
echo "changed=false" >> "$GITHUB_OUTPUT"
exit 0
fi
{
echo "changed=true"
echo "version=$(grep -m1 "^VERSION=" spectre-meltdown-checker.sh | cut -d"'" -f2)"
echo "sb=$(git rev-parse origin/source-build)"
echo "sbdate=$(git log -1 --format=%ai origin/source-build)"
} >> "$GITHUB_OUTPUT"
# Note: the repo must have "Allow GitHub Actions to create and approve
# pull requests" enabled for this to work.
- name: open the sync pull request
if: steps.sync.outputs.changed == 'true'
uses: peter-evans/create-pull-request@v7
with:
base: master
branch: release/sync-from-source-build
delete-branch: true
committer: "github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>"
author: "github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>"
title: "release: sync v${{ steps.sync.outputs.version }} from source-build"
commit-message: |
release: sync v${{ steps.sync.outputs.version }} from source-build
built from source-build commit ${{ steps.sync.outputs.sb }}
dated ${{ steps.sync.outputs.sbdate }}
body: |
Assembled files copied from `source-build` onto `master` (everything
except `.github/`, which stays master-only).
- version: `${{ steps.sync.outputs.version }}`
- built from source-build commit: ${{ steps.sync.outputs.sb }}
- dated: ${{ steps.sync.outputs.sbdate }}
Once merged, run this workflow again with the `draft-github-release`
action to cut the release, if required.
# ---------------------------------------------------------------------------
# 2. Draft a GitHub release from the script currently on master.
# ---------------------------------------------------------------------------
draft-github-release:
if: inputs.action == 'draft-github-release'
runs-on: ubuntu-latest
env:
GH_TOKEN: ${{ github.token }}
steps:
- uses: actions/checkout@v6
with:
ref: master
fetch-depth: 0
persist-credentials: true
- name: draft a release from the current master script
run: |
set -eu
ver=$(grep -m1 "^VERSION=" spectre-meltdown-checker.sh | cut -d"'" -f2)
tag="v${ver}"
if gh release view "$tag" >/dev/null 2>&1; then
echo "A release for $tag already exists; refusing to recreate." >&2
echo "Delete it first if needed." >&2
exit 1
fi
# Draft the changelog from the source-build commits assembled since the
# previous published release. We locate the source-build commit whose
# built VERSION equals the last release tag, then list what came after.
git fetch --no-tags origin source-build
last_tag=$(gh release list --exclude-drafts --limit 1 --json tagName --jq '.[0].tagName // empty')
old_ver="${last_tag#v}"
base=""
if [ -n "$old_ver" ]; then
while read -r h; do
v=$(git show "$h:spectre-meltdown-checker.sh" 2>/dev/null | grep -m1 "^VERSION=" | cut -d"'" -f2 || true)
if [ "$v" = "$old_ver" ]; then base="$h"; break; fi
done < <(git rev-list --max-count=500 origin/source-build)
fi
{
echo "## ${tag}"
echo
if [ -n "$base" ]; then
git log --no-merges --format='- %s' "${base}..origin/source-build"
else
echo "_Could not determine the previous release point automatically — please fill in the changelog. Last 30 assembled commits below as a starting point:_"
echo
git log --no-merges --format='- %s' --max-count=30 origin/source-build
fi
} > notes.md
echo "----- draft notes -----"; cat notes.md; echo "-----------------------"
gh release create "$tag" \
--draft \
--target "$GITHUB_SHA" \
--title "$tag" \
--notes-file notes.md \
spectre-meltdown-checker.sh
echo "Draft release $tag created."
+36
View File
@@ -0,0 +1,36 @@
name: 'Manage stale issues and PRs'
on:
schedule:
- cron: '37 7 * * *'
workflow_dispatch:
inputs:
action:
description: "dry-run"
required: true
default: "apply"
type: choice
options:
- dryrun
- apply
permissions:
issues: write
pull-requests: write
jobs:
stale:
runs-on: ubuntu-latest
steps:
- uses: actions/stale@v10
with:
any-of-labels: 'needs-more-info,answered'
labels-to-remove-when-unstale: 'needs-more-info,answered'
days-before-stale: 30
days-before-close: 7
stale-issue-label: stale
remove-stale-when-updated: true
close-issue-reason: completed
stale-issue-message: "If there are no further comments or activity on this issue, it'll be closed automatically in 7 days."
close-issue-message: "Automatically closing this issue due to inactivity, don't hesitate to open a new issue if needed."
debug-only: ${{ case(inputs.action == 'dryrun', true, false) }}
+190
View File
@@ -0,0 +1,190 @@
name: Online search for vulns
on:
schedule:
- cron: '42 8 * * *'
workflow_dispatch:
inputs:
model:
description: 'Claude model to use (cron runs default to Sonnet)'
required: false
type: choice
default: claude-sonnet-4-6
options:
- claude-sonnet-4-6
- claude-opus-4-7
- claude-haiku-4-5-20251001
window_hours:
description: 'Lookback window in hours (cron runs use 25)'
required: false
type: string
default: '25'
reconsider_age_days:
description: 'Only reconsider backlog entries last reviewed ≥ N days ago (0 = all, default 7)'
required: false
type: string
default: '7'
permissions:
contents: read
actions: read # needed to list/download previous run artifacts
id-token: write # needed by claude-code-action for OIDC auth
concurrency:
group: vuln-watch
cancel-in-progress: true
jobs:
watch:
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
# The scripts driving this workflow live on the `vuln-watch` branch so
# they don't clutter master (which is what ships to production). The
# workflow file itself MUST stay on the default branch, as GitHub only
# honors `schedule:` triggers on the default branch.
- name: Checkout vuln-watch branch (scripts + prompt)
uses: actions/checkout@v6
with:
ref: vuln-watch
fetch-depth: 1
persist-credentials: false
- name: Set up Python
uses: actions/setup-python@v6
with:
python-version: '3.12'
- name: Install Python dependencies
run: python -m pip install --quiet feedparser
# ---- Load previous state ---------------------------------------------
# Find the most recent successful run of THIS workflow (other than the
# current one) and pull its `vuln-watch-state` artifact. On the very
# first run there will be none — that's fine, we start empty.
- name: Find previous successful run id
id: prev
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
set -e
run_id=$(gh run list \
--workflow="${{ github.workflow }}" \
--status=success \
--limit 1 \
--json databaseId \
--jq '.[0].databaseId // empty')
echo "run_id=${run_id}" >> "$GITHUB_OUTPUT"
if [ -n "$run_id" ]; then
echo "Found previous successful run: $run_id"
else
echo "No previous successful run — starting from empty state."
fi
- name: Download previous state artifact
if: steps.prev.outputs.run_id != ''
uses: actions/download-artifact@v8
continue-on-error: true # tolerate retention expiry
with:
name: vuln-watch-state
path: state/
run-id: ${{ steps.prev.outputs.run_id }}
github-token: ${{ secrets.GITHUB_TOKEN }}
# ---- Fetch + diff (token-free; runs every time) ---------------------
# Performs conditional GETs (ETag / If-Modified-Since) against every
# source, parses RSS/Atom/HTML, dedups against state.seen + state.aliases,
# applies the time-window filter, and emits new_items.json.
# Updates state.sources (HTTP cache metadata + per-source high-water
# marks) in place so the cache survives even when Claude doesn't run.
- name: Fetch + diff all sources
id: diff
env:
SCAN_DATE: ${{ github.run_started_at }}
# Cron runs have no `inputs` context, so the fallback kicks in.
WINDOW_HOURS: ${{ inputs.window_hours || '25' }}
RECONSIDER_AGE_DAYS: ${{ inputs.reconsider_age_days || '7' }}
run: python -m scripts.vuln_watch.fetch_and_diff
# ---- Fetch checker code so Claude can grep it for coverage ---------
# The orphan vuln-watch branch has none of the actual checker code,
# so we pull the `test` branch (the dev branch where coded-but-
# unreleased CVE checks live) into ./checker/. The prompt tells
# Claude this is the canonical source of truth for "is CVE-X already
# implemented?". Only fetched on days with something to classify.
- name: Checkout checker code (test branch) for coverage grep
if: steps.diff.outputs.new_count != '0' || steps.diff.outputs.reconsider_count != '0'
uses: actions/checkout@v6
with:
ref: test
path: checker
fetch-depth: 1
persist-credentials: false
# ---- Classify new items with Claude (skipped when nothing is new) ---
# Model selection: a manual workflow_dispatch run picks from a dropdown
# (defaulting to Sonnet). Scheduled cron runs have no `inputs` context,
# so the `|| 'claude-sonnet-4-6'` fallback kicks in — cron always uses
# Sonnet to keep the daily cost floor low.
- name: Run classifier with Claude
id: classify
if: steps.diff.outputs.new_count != '0' || steps.diff.outputs.reconsider_count != '0'
uses: anthropics/claude-code-action@v1
env:
SCAN_DATE: ${{ github.run_started_at }}
with:
prompt: |
Read the full task instructions from scripts/daily_vuln_watch_prompt.md
and execute them end-to-end. Your input is new_items.json (already
deduped, windowed, and pre-filtered — do NOT re-fetch sources).
Write the three watch_${TODAY}_*.md files and classifications.json.
Use $SCAN_DATE as the canonical timestamp.
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
# model + tool allowlist pass through claude_args (v1 dropped the
# dedicated `model:` and `allowed_tools:` inputs). Job-level
# `timeout-minutes: 20` above bounds total runtime.
claude_args: |
--model ${{ inputs.model || 'claude-sonnet-4-6' }}
--allowedTools "Read,Write,Edit,Bash,Grep,Glob,WebFetch"
- name: Upload Claude execution log
if: ${{ always() && steps.classify.outputs.execution_file != '' }}
uses: actions/upload-artifact@v7
with:
name: claude-execution-log-${{ github.run_id }}
path: ${{ steps.classify.outputs.execution_file }}
retention-days: 30
if-no-files-found: warn
# ---- Merge classifications back into state --------------------------
# Also writes stub watch_*.md files if the classify step was skipped, so
# the report artifact is consistent across runs.
- name: Merge classifications into state
if: always()
env:
SCAN_DATE: ${{ github.run_started_at }}
run: python -m scripts.vuln_watch.merge_state
- name: Upload new state artifact
if: always()
uses: actions/upload-artifact@v7
with:
name: vuln-watch-state
path: state/seen.json
retention-days: 90
if-no-files-found: error
- name: Upload daily report
if: always()
uses: actions/upload-artifact@v7
with:
name: vuln-watch-report-${{ github.run_id }}
path: |
watch_*.md
current_toimplement.md
current_tocheck.md
new_items.json
classifications.json
retention-days: 90
if-no-files-found: warn