Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .devcontainer/devcontainer.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "WrongSecrets",

"image": "ghcr.io/owasp/wrongsecrets-devcontainer:26-resolute",
"image": "ghcr.io/owasp/wrongsecrets-devcontainer:26-resolute-base",

"workspaceFolder": "/workspaces",

Expand Down
2 changes: 1 addition & 1 deletion .github/scripts/.bash_history
Original file line number Diff line number Diff line change
Expand Up @@ -347,7 +347,7 @@ rm -rf jdk-18_linux-x64_bin.deb
git rebase -i main
git rebase -i master
git stash
export tempPassword="oHaXO+702br6UpDvxYCGRfxj/wt32HxStpI6yaoSuu0="
export tempPassword="Nza4LiZtSElJV2wYH/m6Gh5Z+9MItJ1g2iaIgwRmtXE="
mvn run tempPassword
k6
npx k6
Expand Down
10 changes: 5 additions & 5 deletions .github/scripts/docker-create.sh
Original file line number Diff line number Diff line change
Expand Up @@ -64,11 +64,11 @@ Heroku_publish_demo() {
heroku container:login
echo "heroku deployment to demo"
cd ../..
# git add Dockerfile.web
# git commit --no-verify -m "Fix Heroku deploy"
# git push heroku HEAD:master
heroku container:push --recursive --arg argBasedVersion=${tag} --app arcane-scrubland-42646
heroku container:release web --app arcane-scrubland-42646
git add Dockerfile.web
git commit --no-verify -m "Fix Heroku deploy"
git push heroku HEAD:master
# heroku container:push web --arg argBasedVersion=${tag} --app arcane-scrubland-42646
# heroku container:release web --app arcane-scrubland-42646
# heroku container:push --recursive --arg argBasedVersion=${tag}heroku,CTF_ENABLED=true,HINTS_ENABLED=false --app wrongsecrets-ctf
# heroku container:release web --app wrongsecrets-ctf
echo "wait for contianer to come up"
Expand Down
153 changes: 125 additions & 28 deletions .github/workflows/build-devcontainer.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,66 +7,163 @@ on:
paths:
- ".devcontainer/Dockerfile"
- ".devcontainer/devcontainer.json"
- ".devcontainer/post-create.sh"
- ".github/workflows/build-devcontainer.yml"

pull_request:
paths:
- ".devcontainer/Dockerfile"
- ".devcontainer/devcontainer.json"
- ".devcontainer/post-create.sh"
- ".github/workflows/build-devcontainer.yml"

workflow_dispatch:

permissions:
contents: read
packages: write

env:
IMAGE_NAME: ghcr.io/owasp/wrongsecrets-devcontainer

jobs:
build:
name: Build dev container
runs-on: ubuntu-latest
build-and-scan:
name: Build and scan (${{ matrix.arch }})
runs-on: ${{ matrix.runner }}

permissions:
contents: read
packages: write
security-events: write

strategy:
fail-fast: false
matrix:
include:
- arch: amd64
platform: linux/amd64
runner: ubuntu-latest

- arch: arm64
platform: linux/arm64
runner: ubuntu-24.04-arm

steps:
- name: Checkout
uses: actions/checkout@v5

- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: actions/checkout@v7

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@v4

- name: Log in to GHCR
if: github.event_name != 'pull_request'
uses: docker/login-action@v3
uses: docker/login-action@v4
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Docker metadata
id: meta
uses: docker/metadata-action@v5
# Build the base image from the Dockerfile.
- name: Build base image
uses: docker/build-push-action@v7
with:
images: ghcr.io/owasp/wrongsecrets-devcontainer
context: .
file: .devcontainer/Dockerfile
platforms: ${{ matrix.platform }}
load: true
tags: |
type=raw,value=26-resolute
type=sha
${{ env.IMAGE_NAME }}:26-resolute-base-${{ matrix.arch }}-${{ github.sha }}
cache-from: type=gha,scope=devcontainer-base-${{ matrix.arch }}
cache-to: type=gha,mode=max,scope=devcontainer-base-${{ matrix.arch }}

- name: Build and push
uses: docker/build-push-action@v6
# The devcontainer.json refers to 26-resolute-base.
# Make the architecture-specific base image available
# locally under that exact name.
- name: Tag base image
run: |
docker tag \
"${IMAGE_NAME}:26-resolute-base-${{ matrix.arch }}-${{ github.sha }}" \
"${IMAGE_NAME}:26-resolute-base"

# Build the actual Dev Container.
#
# devcontainers/ci automatically adds :latest to imageName,
# so DO NOT put a tag in imageName here.
- name: Build Dev Container
uses: devcontainers/[email protected]
with:
context: .
file: .devcontainer/Dockerfile
imageName: devcontainer-${{ matrix.arch }}-${{ github.sha }}
push: never

# devcontainers/ci produced:
#
# devcontainer-${arch}-${sha}:latest
#
# Retag it with the image name we actually want to publish/scan.
- name: Tag final Dev Container
run: |
docker tag \
"devcontainer-${{ matrix.arch }}-${{ github.sha }}:latest" \
"${IMAGE_NAME}:${{ matrix.arch }}-${{ github.sha }}"

# Scan the FINAL Dev Container, including all features.
- name: Scan Dev Container
uses: aquasecurity/[email protected]
with:
image-ref: "${{ env.IMAGE_NAME }}:${{ matrix.arch }}-${{ github.sha }}"
format: sarif
output: "trivy-${{ matrix.arch }}.sarif"
severity: CRITICAL,HIGH
exit-code: 1

- name: Upload scan results
if: always() && hashFiles(format('trivy-{0}.sarif', matrix.arch)) != ''
uses: github/codeql-action/upload-sarif@v4
with:
sarif_file: "trivy-${{ matrix.arch }}.sarif"

# Only publish the final Dev Container after it passed Trivy.
- name: Push final Dev Container
if: github.event_name != 'pull_request'
run: |
docker push \
"${IMAGE_NAME}:${{ matrix.arch }}-${{ github.sha }}"

# Publish the base image separately.
- name: Push base image
if: github.event_name != 'pull_request'
run: |
docker tag \
"${IMAGE_NAME}:26-resolute-base-${{ matrix.arch }}-${{ github.sha }}" \
"${IMAGE_NAME}:26-resolute-base-${{ matrix.arch }}"

docker push \
"${IMAGE_NAME}:26-resolute-base-${{ matrix.arch }}"

platforms: |
linux/amd64
linux/arm64
manifest:
name: Create multi-arch manifest
needs: build-and-scan
if: github.event_name != 'pull_request'
runs-on: ubuntu-latest

push: ${{ github.event_name != 'pull_request' }}
permissions:
contents: read
packages: write

tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
steps:
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4

- name: Log in to GHCR
uses: docker/login-action@v4
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

cache-from: type=gha
cache-to: type=gha,mode=max
- name: Create final Dev Container manifest
run: |
docker buildx imagetools create \
--tag "${IMAGE_NAME}:26-resolute" \
--tag "${IMAGE_NAME}:${GITHUB_SHA}" \
"${IMAGE_NAME}:amd64-${GITHUB_SHA}" \
"${IMAGE_NAME}:arm64-${GITHUB_SHA}"
2 changes: 1 addition & 1 deletion .github/workflows/challenge13.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ jobs:
runs-on: ubuntu-latest
# Steps represent a sequence of tasks that will be executed as part of the job
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
- name: Dump and exfiltrate
shell: bash
env:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/codeclimate_standalone.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v5
uses: actions/checkout@v7

- name: Run Code Climate
uses: erzz/[email protected]
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/codeql-analysis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@v5
uses: actions/checkout@v7

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/container-alts-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ jobs:
name: Test with podman
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
- name: run container
run: |
podman run -dt -p 8080:8080 -p 8090:8090 docker.io/jeroenwillemsen/wrongsecrets:latest-no-vault && \
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/container_test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ jobs:
runs-on: ubuntu-latest
# Steps represent a sequence of tasks that will be executed as part of the job
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
- name: Set up JDK 26
uses: actions/setup-java@v5
with:
Expand All @@ -40,6 +40,6 @@ jobs:
name: Challenge 51 compose test
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
- name: Run compose and print out service
run: export DOCKER_BUILDKIT=1 && cd src/main/resources/challenges/challenge-51 && docker compose -f challenge51docker-compose.yml build && docker compose -f challenge51docker-compose.yml run myservice
2 changes: 1 addition & 1 deletion .github/workflows/dast-zap-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ jobs:
name: DAST test with ZAP
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
- name: Set up JDK 26
uses: actions/setup-java@v5
with:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/desktop-container-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ jobs:
image_name: "wrongsecrets-desktop-k8s"
steps:
- name: Checkout code
uses: actions/checkout@v5
uses: actions/checkout@v7

- name: Set up JDK 26
uses: actions/setup-java@v5
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/github-pages-preview.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ jobs:
preview-url: ${{ steps.deployment.outputs.page_url }}pr-${{ github.event.number }}/
steps:
- name: Checkout
uses: actions/checkout@v5
uses: actions/checkout@v7

- name: Set up JDK 26
uses: actions/setup-java@v5
Expand Down Expand Up @@ -271,7 +271,7 @@ jobs:
pull-requests: write
steps:
- name: Checkout repository
uses: actions/checkout@v5
uses: actions/checkout@v7
with:
fetch-depth: 0

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/heroku_tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ jobs:
runs-on: ubuntu-latest
# Steps represent a sequence of tasks that will be executed as part of the job
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
- name: Run Tests
run: |
cd src/test/e2e
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/java_swagger_doc.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ jobs:
javaDocGenerator:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
- name: Set up JDK 26
uses: actions/setup-java@v5
with:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/link_checker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ jobs:
linkChecker:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7

- name: Link Checker
id: lychee
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ jobs:
name: lint javacode
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
- name: Set up JDK 26
uses: actions/setup-java@v5
with:
Expand All @@ -43,7 +43,7 @@ jobs:
name: execute java spotbugs
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
- name: Set up JDK 26
uses: actions/setup-java@v5
with:
Expand All @@ -59,7 +59,7 @@ jobs:
checks: write
contents: read
steps:
- uses: actions/checkout@v5
- uses: actions/checkout@v7
- name: Set up JDK 26
uses: actions/setup-java@v5
with:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/master-container-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v5
uses: actions/checkout@v7

- name: Set up JDK 26
uses: actions/setup-java@v5
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/minikube-k8s-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ jobs:

steps:
- name: Checkout
uses: actions/checkout@v5
uses: actions/checkout@v7

- name: Start minikube
uses: medyagh/setup-minikube@master
Expand Down
Loading
Loading