From 01323bef41d1a70416c96237817fc80526f37370 Mon Sep 17 00:00:00 2001 From: Jonathan Dumont <5204724+JOduMonT@users.noreply.github.com> Date: Sat, 3 Oct 2026 08:38:30 -0400 Subject: [PATCH 1/3] Add Dependabot config --- .github/dependabot.yml | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..f899a84 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,17 @@ +# Renovate owns routine version bumps in this repository, so Dependabot version updates +# are off (limit 0) to avoid duplicate pull requests. Dependabot alerts and security +# updates are repository settings and stay on regardless. +version: 2 +updates: + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly + day: monday + open-pull-requests-limit: 0 + - package-ecosystem: docker-compose + directory: / + schedule: + interval: weekly + day: monday + open-pull-requests-limit: 0 From 5cfa206f5c13d1590bf259917a9b913bd5b18023 Mon Sep 17 00:00:00 2001 From: Jonathan Dumont <5204724+JOduMonT@users.noreply.github.com> Date: Sat, 3 Oct 2026 08:38:31 -0400 Subject: [PATCH 2/3] Add Dependabot auto-merge workflow --- .github/workflows/dependabot-auto-merge.yml | 51 +++++++++++++++++++++ 1 file changed, 51 insertions(+) create mode 100644 .github/workflows/dependabot-auto-merge.yml diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml new file mode 100644 index 0000000..c55990b --- /dev/null +++ b/.github/workflows/dependabot-auto-merge.yml @@ -0,0 +1,51 @@ +name: Dependabot auto-merge + +# Squash-merges a Dependabot pull request once every other check on it has passed. +# Major version bumps are left open for review. Branch protection is not available on the +# GitHub Free plan, so the wait-for-checks gate lives in this job instead of in a ruleset. + +on: + pull_request: + +permissions: + contents: write + pull-requests: write + checks: read + +jobs: + auto-merge: + name: auto-merge + if: github.event.pull_request.user.login == 'dependabot[bot]' + runs-on: ubuntu-latest + timeout-minutes: 35 + steps: + - name: Read Dependabot metadata + id: meta + uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0 + with: + github-token: ${{ secrets.GITHUB_TOKEN }} + + - name: Wait for the other checks, then merge + if: steps.meta.outputs.update-type != 'version-update:semver-major' + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + REPO: ${{ github.repository }} + SHA: ${{ github.event.pull_request.head.sha }} + PR_URL: ${{ github.event.pull_request.html_url }} + run: | + set -eu + sleep 60 # let the other workflows register their checks + deadline=$((SECONDS + 1800)) + while :; do + runs=$(gh api "repos/$REPO/commits/$SHA/check-runs?per_page=100" \ + --jq '[.check_runs[] | select(.name != "auto-merge") | {name, status, conclusion}]') + bad=$(echo "$runs" | jq '[.[] | select(.status == "completed" and (.conclusion | IN("success", "neutral", "skipped") | not))] | length') + pending=$(echo "$runs" | jq '[.[] | select(.status != "completed")] | length') + if [ "$bad" -gt 0 ]; then + echo "A check failed; not merging."; echo "$runs" | jq .; exit 1 + fi + [ "$pending" -eq 0 ] && break + [ "$SECONDS" -gt "$deadline" ] && { echo "Timed out waiting for checks."; exit 1; } + sleep 30 + done + gh pr merge --squash --delete-branch "$PR_URL" From 044268455ada0a9e3619b638328146a1f8119f9b Mon Sep 17 00:00:00 2001 From: Jonathan Dumont <5204724+JOduMonT@users.noreply.github.com> Date: Sat, 3 Oct 2026 08:38:33 -0400 Subject: [PATCH 3/3] Write a repo-specific SECURITY.md --- SECURITY.md | 37 +++++++++++++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..7d90564 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,37 @@ +# Security Policy + +Deployment config for a shared PostgreSQL instance pinned to a stable Alpine tag, standalone or as shared tenant infrastructure on Coolify. + +## Supported versions + +Only the current `main` branch is supported. Fixes land on `main`; there are no release branches. + +## Reporting a vulnerability + +Please report privately. Do not open a public issue or pull request. + +- **Preferred:** [report a vulnerability](https://github.com/JOduMonT/postgresql/security/advisories/new) through GitHub private vulnerability reporting. +- **Email:** jodumont+security@gmail.com +- Include what you found, the affected file or service, steps to reproduce and the impact you see. +- Do not access, change or delete data that is not yours, and do not run denial-of-service or automated scanning against live systems. + +You can expect an acknowledgement within 3 business days and a status update within 10. Confirmed issues are fixed as quickly as severity allows, and you are credited in the fix unless you prefer not to be. + +## Scope + +In scope: + +- Compose files: published ports, authentication method, how superuser and tenant credentials are supplied, volume permissions. + +Out of scope: + +- PostgreSQL itself: report it to the PostgreSQL security team. +- Social engineering and physical attacks. + +## How this repository is kept safe + +- Dependabot alerts and security updates are on; a vulnerable dependency gets an automatic pull request. Routine version bumps are opened by Renovate, and `.github/dependabot.yml` keeps Dependabot's own version updates off to avoid duplicate pull requests. +- Dependabot pull requests are merged automatically by `.github/workflows/dependabot-auto-merge.yml` once every other check passes. Major version bumps are left open for review. +- GitHub secret scanning with push protection and CodeQL code scanning are enabled. +- Credentials are injected by Coolify or `.env`, never committed; keep the instance internal-only. +- Image bumps come from Renovate and are smoke-tested in CI; a major upgrade is a dump and restore, done by hand.