Commit graph

94 commits

Author SHA1 Message Date
Kovid Goyal
a28abf1573
Ignore inapplicable CVE
Some checks are pending
CI / Linux (python=3.13 cc=clang sanitize=1) (push) Waiting to run
CI / Linux (python=3.11 cc=gcc sanitize=0) (push) Waiting to run
CI / Linux (python=3.12 cc=gcc sanitize=1) (push) Waiting to run
CI / Linux package (push) Waiting to run
CI / Bundle test (macos-latest) (push) Waiting to run
CI / Bundle test (ubuntu-latest) (push) Waiting to run
CI / macOS Brew (push) Waiting to run
CI / Test ./dev.sh and benchmark (push) Waiting to run
CodeQL / CodeQL-Build (actions, ubuntu-latest) (push) Waiting to run
CodeQL / CodeQL-Build (c, macos-latest) (push) Waiting to run
CodeQL / CodeQL-Build (c, ubuntu-latest) (push) Waiting to run
CodeQL / CodeQL-Build (go, ubuntu-latest) (push) Waiting to run
CodeQL / CodeQL-Build (python, ubuntu-latest) (push) Waiting to run
Depscan / Scan dependencies for vulnerabilities (push) Waiting to run
2026-05-13 15:03:17 +05:30
Kovid Goyal
3a598218d3
Flush streams and sleep before printing crash report 2026-04-19 21:25:08 +05:30
Kovid Goyal
5e8ca630d4
... 2026-04-14 17:39:04 +05:30
Kovid Goyal
27114c9703
DRYer 2026-04-06 11:28:12 +05:30
Kovid Goyal
79bde7f9a9
Ignore inapplicable CVE in python 2026-03-25 20:20:17 +05:30
Kovid Goyal
c57305addc
Ignore dependency CVEs against unreleased versions of deps 2026-03-20 10:45:08 +05:30
Kovid Goyal
1106ee8d10
Ignore CVE that's not an actual issue 2026-03-06 13:46:07 +05:30
Kovid Goyal
3839dcc082
Bump dependency for CVE 2026-02-07 14:41:17 +05:30
Kovid Goyal
0afe77ebc9
Ignore irrelevant CVE 2026-02-05 23:01:58 +05:30
Kovid Goyal
0267a02bb3
Ignore irrelevant python stdlib CVE 2026-02-03 14:48:30 +05:30
Kovid Goyal
cb53c41c7c
... 2026-01-28 09:40:15 +05:30
Kovid Goyal
ae36822837
Ignore a bunch of CVes in python that havent actually had their fixes released yet. 2026-01-23 19:07:02 +05:30
Kovid Goyal
e342f5ffab
Ignore inapplicable CVE in python stdlib 2026-01-16 19:13:16 +05:30
Kovid Goyal
8a10931f0e
Download grype from my own server
Far higher reliability than githubj;wq
2026-01-10 12:42:09 +05:30
Kovid Goyal
24b634ae1a
Nicer 403 error andling when downloading grype 2026-01-02 11:35:28 +05:30
Kovid Goyal
f39183bd6b
Ignore inapplicable CVE 2025-12-11 12:49:16 +05:30
Kovid Goyal
d87ba95d9c
Ignore CVE-2025-13836
We dont care about this DoS enough, so ignore until a new version of
python 3.12 s released with the fix. Not updating past Python 3.12 for
this DoS.
2025-12-04 15:10:26 +05:30
Kovid Goyal
5f90102413
Add support for RAR archive preview 2025-11-27 09:33:15 +05:30
Kovid Goyal
97b030edf7
Dont scan grype itself with grype 2025-11-02 15:41:01 +05:30
Kovid Goyal
d3ef27c2bc
Update grype db as part of install 2025-10-17 10:59:11 +05:30
Kovid Goyal
0bfcffbaed
Fix spurious CVE in dep detection 2025-10-11 13:23:33 +05:30
Kovid Goyal
3b0938e878
Run govulncheck on the binary and remove upload of SARIF to github as github doesnt like the SARIF govulncheck produces 2025-09-24 13:12:00 +05:30
Kovid Goyal
4771de3f95
Print out the govulncheck.sarif file in CI 2025-09-24 12:57:21 +05:30
Kovid Goyal
4ffacbbe80
Another try at running govulncheck 2025-09-24 12:50:06 +05:30
Kovid Goyal
3383675bb2
... 2025-09-23 16:15:34 +05:30
Kovid Goyal
4e240b94e1
explicitly close opened url 2025-09-22 12:30:53 +05:30
Kovid Goyal
53e2f00473
A fancier download_with_retry function 2025-09-22 12:28:48 +05:30
Kovid Goyal
a05a56e413
use a retry for all downloads in CI script 2025-09-22 12:16:41 +05:30
Kovid Goyal
92ee52b68c
Retry grype download on failure 2025-09-22 11:36:27 +05:30
Kovid Goyal
dfeef6df83
Ignore CVE that does not apply 2025-09-20 10:06:30 +05:30
Kovid Goyal
54368be554
Fix grype not scanning C deps that dont have CPEs 2025-09-18 09:22:28 +05:30
Kovid Goyal
c30f8cec46
... 2025-09-17 23:30:37 +05:30
Kovid Goyal
0eddbefda9
List vulnerabilities by CVE 2025-09-17 23:20:39 +05:30
Kovid Goyal
c4cb9cdbb7
Filter out another form of the same CVE 2025-09-17 23:14:40 +05:30
Kovid Goyal
87856efa49
Run grype against SBOM as well 2025-09-17 22:29:49 +05:30
Kovid Goyal
cf9b0da489
... 2025-09-17 22:06:38 +05:30
Kovid Goyal
ebb7ccebd0
Add a check dependencies action
Use the gyre tool to scan all binaries and generate a report
2025-09-17 21:32:28 +05:30
Kovid Goyal
d647e21779
Use the bundle for CodeQL builds
Speeds up the dependency fetch and hopefully fixes the failure on macOS
2025-09-16 07:36:00 +05:30
Kovid Goyal
f02245af79
Also run gofmt on kittens subdir in CI 2025-03-23 20:26:10 +05:30
Kovid Goyal
744145f392
Add cairo and pixman as deps on Linux
Needed to render COLRv1 fonts. Which are needed because bitmap emoji
fonts dont render well at large font sizes such as can be used with
multicell chars.
2025-02-03 11:06:38 +05:30
Kovid Goyal
143705f2a7
Specify filter explicitly when extracting tarfiles in ci script 2024-11-24 21:53:33 +05:30
Kovid Goyal
28a5bfe379
Make NERD font available in CI 2024-07-02 19:42:31 +05:30
Kovid Goyal
2cb823d3f0
Install needed fonts in CI 2024-06-24 07:54:16 +05:30
Kovid Goyal
bd88d2f734
Install systemd headers in CI 2024-05-16 18:48:19 +05:30
Kovid Goyal
8183e9d3ef
Fix CI build failure on macOS
Also update simde to version 0.8. Accidental was using it to debug
issues with building against simde, but now that it's done, keep it.
2024-04-30 09:48:51 +05:30
Kovid Goyal
7821ae39ab
Also need gdb to get coredumps in CI 2024-03-14 16:09:51 +05:30
Kovid Goyal
af0d570725
Install systemd-coredump on CI so we can see coredumps 2024-03-14 15:18:33 +05:30
Kovid Goyal
cb5a2cce53
... 2024-02-25 09:57:37 +05:30
Kovid Goyal
2b9c646c5b
Build dSYM bundles on CI 2024-02-25 09:57:37 +05:30
Kovid Goyal
e5b27d066c
Output macOS crash reports on CI with nicer formatting 2024-02-25 09:57:37 +05:30