Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 17 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# Renovate owns routine version bumps in this repository, so Dependabot version updates
# are off (limit 0) to avoid duplicate pull requests. Dependabot alerts and security
# updates are repository settings and stay on regardless.
version: 2
updates:
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
day: monday
open-pull-requests-limit: 0
- package-ecosystem: docker-compose
directory: /
schedule:
interval: weekly
day: monday
open-pull-requests-limit: 0
51 changes: 51 additions & 0 deletions .github/workflows/dependabot-auto-merge.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
name: Dependabot auto-merge

# Squash-merges a Dependabot pull request once every other check on it has passed.
# Major version bumps are left open for review. Branch protection is not available on the
# GitHub Free plan, so the wait-for-checks gate lives in this job instead of in a ruleset.

on:
pull_request:

permissions:
contents: write
pull-requests: write
checks: read

jobs:
auto-merge:
name: auto-merge
if: github.event.pull_request.user.login == 'dependabot[bot]'
runs-on: ubuntu-latest
timeout-minutes: 35
steps:
- name: Read Dependabot metadata
id: meta
uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0
with:
github-token: ${{ secrets.GITHUB_TOKEN }}

- name: Wait for the other checks, then merge
if: steps.meta.outputs.update-type != 'version-update:semver-major'
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
REPO: ${{ github.repository }}
SHA: ${{ github.event.pull_request.head.sha }}
PR_URL: ${{ github.event.pull_request.html_url }}
run: |
set -eu
sleep 60 # let the other workflows register their checks
deadline=$((SECONDS + 1800))
while :; do
runs=$(gh api "repos/$REPO/commits/$SHA/check-runs?per_page=100" \
--jq '[.check_runs[] | select(.name != "auto-merge") | {name, status, conclusion}]')
bad=$(echo "$runs" | jq '[.[] | select(.status == "completed" and (.conclusion | IN("success", "neutral", "skipped") | not))] | length')
pending=$(echo "$runs" | jq '[.[] | select(.status != "completed")] | length')
if [ "$bad" -gt 0 ]; then
echo "A check failed; not merging."; echo "$runs" | jq .; exit 1
fi
[ "$pending" -eq 0 ] && break
[ "$SECONDS" -gt "$deadline" ] && { echo "Timed out waiting for checks."; exit 1; }
sleep 30
done
gh pr merge --squash --delete-branch "$PR_URL"
37 changes: 37 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
# Security Policy

Deployment config for a shared PostgreSQL instance pinned to a stable Alpine tag, standalone or as shared tenant infrastructure on Coolify.

## Supported versions

Only the current `main` branch is supported. Fixes land on `main`; there are no release branches.

## Reporting a vulnerability

Please report privately. Do not open a public issue or pull request.

- **Preferred:** [report a vulnerability](https://github.com/JOduMonT/postgresql/security/advisories/new) through GitHub private vulnerability reporting.
- **Email:** jodumont+security@gmail.com
- Include what you found, the affected file or service, steps to reproduce and the impact you see.
- Do not access, change or delete data that is not yours, and do not run denial-of-service or automated scanning against live systems.

You can expect an acknowledgement within 3 business days and a status update within 10. Confirmed issues are fixed as quickly as severity allows, and you are credited in the fix unless you prefer not to be.

## Scope

In scope:

- Compose files: published ports, authentication method, how superuser and tenant credentials are supplied, volume permissions.

Out of scope:

- PostgreSQL itself: report it to the PostgreSQL security team.
- Social engineering and physical attacks.

## How this repository is kept safe

- Dependabot alerts and security updates are on; a vulnerable dependency gets an automatic pull request. Routine version bumps are opened by Renovate, and `.github/dependabot.yml` keeps Dependabot's own version updates off to avoid duplicate pull requests.
- Dependabot pull requests are merged automatically by `.github/workflows/dependabot-auto-merge.yml` once every other check passes. Major version bumps are left open for review.
- GitHub secret scanning with push protection and CodeQL code scanning are enabled.
- Credentials are injected by Coolify or `.env`, never committed; keep the instance internal-only.
- Image bumps come from Renovate and are smoke-tested in CI; a major upgrade is a dump and restore, done by hand.
Loading