mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-02 05:12:11 +03:00
* chore(release): continue v3.8.25 development cycle after main code-sync (r5) main fast-forwarded to release/v3.8.25 (#3863): unblocked Build+Docker via #3864, plus #3837 (mimocode proxy) and #3862 (trivy bump). This marker re-opens the umbrella PR for further v3.8.25 work. No version bump. * fix(db): persist the Keep-latest-backups retention setting (#3834) (#3867) * fix(oauth): clear GitLab Duo setup message instead of 500 (#3861) (#3868) * test(oauth): prove refresh_token preserved on real gemini-cli/antigravity dispatch (#3850) (#3869) * feat(compression-ui): unified compression config UI — per-engine pages + combos editor + menu + WS default-on (#3860) Integrated into release/v3.8.25 — feat(compression-ui): unified compression configuration UI (Compression Hub + per-engine Lite/Aggressive/Ultra pages + combos editor + sidebar entry + live-WS default-on). File-size re-baselined for sidebarVisibility.ts/chatCore.ts growth; orphan ws test relocated to a collected path. * docs(changelog): complete the v3.8.25 release notes + credit all contributors Audited every commit since v3.8.24 and filled the gaps the [3.8.25] section was missing: a New Features section (compression engines + Compression Studios #3848, compression UI #3860, injection-guard #3857, kiro discovery #3836, Veo #3839, mimocode proxy #3837, Arena ELO flag #3821), 9 more Fixed entries (#3811/#3807/#3759/#3849/#3838/#3835/#3814/#3820/#3819), a Security section (CCR IDOR #3859, supply-chain #3824), and an Internal/Quality section. Every contributor and issue reporter is now credited. * docs(changelog): restore + complete the v3.8.25 release notes Re-adds CHANGELOG.md (a prior server-side commit accidentally dropped it) with the complete, audited [3.8.25] section: New Features, the full Fixed list, Security & Hardening, and Internal/Quality — every contributor and issue reporter credited. * chore(release): finalize v3.8.25 — reconcile CHANGELOG + i18n mirrors, document OMNIROUTE_MAX_PENDING_MIGRATIONS, green the unit suite Release-gate reconciliation for v3.8.25: - CHANGELOG: dated 2026-06-14, linked #3826, rolled up file-size re-baselines (#3823/#3833), recorded the test-greening; re-synced all 41 i18n CHANGELOG mirrors. - Documented OMNIROUTE_MAX_PENDING_MIGRATIONS (#3416) in .env.example + ENVIRONMENT.md. - Greened the unit suite (was merged red on 4 CI shards): aligned 10 stale tests to this cycle's intended behavior (#3838/#3822/#3501/SOCKS5/Vertex-Express/Antigravity) and the same-provider 503 fall-through test; de-flaked the compression benchmark reproducibility and ServiceSupervisor crash tests. No production code changed. * ci(security): clear OpenSSF Scorecard code-scanning noise + harden workflow token permissions The Security tab held 155 open alerts, ALL from the advisory OpenSSF Scorecard tool (#3824) — supply-chain/posture scores, not code vulnerabilities — which drowned out real CodeQL findings. - scorecard.yml: stop uploading SARIF to the code-scanning tab (drop the upload-sarif step + the now-unused security-events: write). The run still produces the OpenSSF badge (publish_results) and a downloadable SARIF artifact. - TokenPermissions hardening (the high-severity, genuinely-valuable subset): set each workflow's top-level token to read-only and grant the exact writes at the job level that needs them — npm-publish (id-token/packages on publish jobs), docker-publish (packages on build), electron-release (contents on build/release, id-token/packages on publish-npm), build-fork (packages on build), claude (empty top-level; job grants its own). The 155 existing alerts were dismissed. Not adopting repo-wide SHA-pinning (143 PinnedDependencies advisories) — declined. * test(integration): align stale wiring/socks5 integration tests to this cycle's behavior These were red on the CI Integration job (pre-existing). No production code changed: - integration-wiring: the combos page no longer renders a per-page EmailPrivacyToggle (#3822 consolidated it into Settings → Appearance); the provider-detail test-result masking and upstream-proxy copy moved to decomposed components (#3501 BatchTestResultsModal / UpstreamProxyCard) — assertions now read the owning files. - api-routes-critical: SOCKS5 is now enabled by default (opt-out), so the disabled- rejection test must set ENABLE_SOCKS5_PROXY=false explicitly (an unset env now means enabled). (The ~32 live-Gemini integration tests are gated on OMNIROUTE_API_KEY and skip in CI; they only 'fail' locally when that key is present without a running server.)
372 lines
13 KiB
YAML
372 lines
13 KiB
YAML
name: Publish to Docker Hub
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
tags:
|
|
- "v*"
|
|
paths-ignore:
|
|
- ".github/workflows/**"
|
|
# Use 'released' instead of 'published' so editing/re-publishing old releases
|
|
# does NOT re-trigger this workflow. 'released' fires only on the initial
|
|
# release publication (and pre-release → release transition).
|
|
release:
|
|
types: [released]
|
|
workflow_dispatch:
|
|
inputs:
|
|
version:
|
|
description: "Version tag to build (e.g. 3.8.4)"
|
|
required: true
|
|
type: string
|
|
promote_latest:
|
|
description: "Also tag :latest (only if this is the highest semver)"
|
|
required: false
|
|
type: boolean
|
|
default: false
|
|
|
|
# Least-privilege default: read-only at the top level; the build and merge jobs that
|
|
# push to GHCR grant packages: write themselves (Scorecard TokenPermissions).
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
prepare:
|
|
name: Resolve Docker release metadata
|
|
runs-on: ubuntu-latest
|
|
outputs:
|
|
version: ${{ steps.version.outputs.version }}
|
|
promote_latest: ${{ steps.version.outputs.promote_latest }}
|
|
skip: ${{ steps.version.outputs.skip }}
|
|
env:
|
|
IMAGE_NAME: diegosouzapw/omniroute
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
ref: ${{ github.event_name == 'workflow_dispatch' && format('refs/tags/v{0}', inputs.version) || '' }}
|
|
# Need full tag history for semver comparison when deciding :latest.
|
|
fetch-depth: 0
|
|
|
|
- name: Resolve version, latest-promotion, and skip flag
|
|
id: version
|
|
env:
|
|
EVENT_NAME: ${{ github.event_name }}
|
|
REF_NAME: ${{ github.ref_name }}
|
|
REF_TYPE: ${{ github.ref_type }}
|
|
INPUT_VERSION: ${{ inputs.version }}
|
|
PROMOTE_INPUT: ${{ inputs.promote_latest }}
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
# 1) Resolve version string from the trigger (all inputs come via env).
|
|
case "$EVENT_NAME" in
|
|
workflow_dispatch)
|
|
VERSION="${INPUT_VERSION#v}"
|
|
;;
|
|
push)
|
|
if [ "$REF_TYPE" = "tag" ]; then
|
|
VERSION="${REF_NAME#v}"
|
|
else
|
|
# Push to main → build & tag as `main` only. Never touch :latest.
|
|
VERSION="main"
|
|
fi
|
|
;;
|
|
release)
|
|
VERSION="${REF_NAME#v}"
|
|
;;
|
|
*)
|
|
VERSION="${REF_NAME#v}"
|
|
;;
|
|
esac
|
|
# Sanity-check: only allow [A-Za-z0-9._-] in VERSION (defense in depth).
|
|
if ! printf '%s' "$VERSION" | grep -qE '^[A-Za-z0-9._-]+$'; then
|
|
echo "Refusing to use unsafe VERSION value: $VERSION" >&2
|
|
exit 1
|
|
fi
|
|
echo "version=$VERSION" >> "$GITHUB_OUTPUT"
|
|
|
|
# 2) Decide whether to promote :latest.
|
|
PROMOTE="false"
|
|
if [ "$VERSION" = "main" ]; then
|
|
PROMOTE="false"
|
|
elif printf '%s' "$VERSION" | grep -qE -- '-(rc|alpha|beta|pre|next)'; then
|
|
echo "Pre-release identifier detected — skipping :latest."
|
|
PROMOTE="false"
|
|
elif [ "$EVENT_NAME" = "workflow_dispatch" ]; then
|
|
PROMOTE="${PROMOTE_INPUT:-false}"
|
|
else
|
|
git fetch --tags --quiet || true
|
|
HIGHEST=$(git tag -l 'v[0-9]*' | sed 's/^v//' | grep -vE -- '-(rc|alpha|beta|pre|next)' | sort -V | tail -1 || echo "")
|
|
if [ -n "$HIGHEST" ] && [ "$VERSION" = "$HIGHEST" ]; then
|
|
PROMOTE="true"
|
|
else
|
|
echo "Version $VERSION is not the highest semver tag (highest=${HIGHEST:-<none>}). Not promoting :latest."
|
|
fi
|
|
fi
|
|
echo "promote_latest=$PROMOTE" >> "$GITHUB_OUTPUT"
|
|
|
|
# 3) Skip if this exact version is already published in Docker Hub.
|
|
# `main` is always rebuilt (mutable floating tag).
|
|
SKIP="false"
|
|
if [ "$VERSION" != "main" ]; then
|
|
if docker manifest inspect "diegosouzapw/omniroute:${VERSION}" >/dev/null 2>&1; then
|
|
echo "Image diegosouzapw/omniroute:${VERSION} already exists on Docker Hub — skipping rebuild."
|
|
SKIP="true"
|
|
fi
|
|
fi
|
|
echo "skip=$SKIP" >> "$GITHUB_OUTPUT"
|
|
|
|
echo "Publishing diegosouzapw/omniroute:$VERSION (promote_latest=$PROMOTE, skip=$SKIP)"
|
|
|
|
build:
|
|
name: Build Docker (${{ matrix.platform }})
|
|
needs: prepare
|
|
if: needs.prepare.outputs.skip != 'true'
|
|
runs-on: ${{ matrix.runner }}
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
include:
|
|
- platform: linux/amd64
|
|
runner: ubuntu-24.04
|
|
arch: amd64
|
|
- platform: linux/arm64
|
|
runner: ubuntu-24.04-arm
|
|
arch: arm64
|
|
env:
|
|
IMAGE_NAME: diegosouzapw/omniroute
|
|
GHCR_IMAGE_NAME: ghcr.io/diegosouzapw/omniroute
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
ref: ${{ github.event_name == 'workflow_dispatch' && format('refs/tags/v{0}', inputs.version) || '' }}
|
|
fetch-depth: 0
|
|
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@v4
|
|
|
|
- name: Login to Docker Hub
|
|
uses: docker/login-action@v4
|
|
with:
|
|
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
|
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
|
|
|
- name: Login to GitHub Container Registry
|
|
uses: docker/login-action@v4
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Build and push platform image by digest
|
|
id: build
|
|
uses: docker/build-push-action@v7
|
|
with:
|
|
context: .
|
|
target: runner-base
|
|
platforms: ${{ matrix.platform }}
|
|
outputs: type=image,push-by-digest=true,name-canonical=true,push=true
|
|
tags: |
|
|
${{ env.IMAGE_NAME }}
|
|
${{ env.GHCR_IMAGE_NAME }}
|
|
cache-from: type=gha,scope=docker-${{ matrix.arch }}
|
|
cache-to: type=gha,scope=docker-${{ matrix.arch }},mode=max
|
|
no-cache: false
|
|
env:
|
|
DOCKER_BUILDKIT_INLINE_CACHE: 1
|
|
|
|
- name: Build and push WEB platform image by digest
|
|
id: build-web
|
|
uses: docker/build-push-action@v7
|
|
with:
|
|
context: .
|
|
target: runner-web
|
|
platforms: ${{ matrix.platform }}
|
|
outputs: type=image,push-by-digest=true,name-canonical=true,push=true
|
|
tags: |
|
|
${{ env.IMAGE_NAME }}
|
|
${{ env.GHCR_IMAGE_NAME }}
|
|
cache-from: type=gha,scope=docker-web-${{ matrix.arch }}
|
|
cache-to: type=gha,scope=docker-web-${{ matrix.arch }},mode=max
|
|
no-cache: false
|
|
env:
|
|
DOCKER_BUILDKIT_INLINE_CACHE: 1
|
|
|
|
- name: Export digests
|
|
env:
|
|
DIGEST_BASE: ${{ steps.build.outputs.digest }}
|
|
DIGEST_WEB: ${{ steps.build-web.outputs.digest }}
|
|
run: |
|
|
set -euo pipefail
|
|
mkdir -p /tmp/digests/base /tmp/digests/web
|
|
touch "/tmp/digests/base/${DIGEST_BASE#sha256:}"
|
|
touch "/tmp/digests/web/${DIGEST_WEB#sha256:}"
|
|
|
|
- name: Upload base digests
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: digests-base-${{ matrix.arch }}
|
|
path: /tmp/digests/base/*
|
|
if-no-files-found: error
|
|
retention-days: 1
|
|
|
|
- name: Upload web digests
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: digests-web-${{ matrix.arch }}
|
|
path: /tmp/digests/web/*
|
|
if-no-files-found: error
|
|
retention-days: 1
|
|
|
|
merge:
|
|
name: Publish multi-arch manifests
|
|
needs:
|
|
- prepare
|
|
- build
|
|
if: needs.prepare.outputs.skip != 'true'
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
security-events: write
|
|
env:
|
|
IMAGE_NAME: diegosouzapw/omniroute
|
|
GHCR_IMAGE_NAME: ghcr.io/diegosouzapw/omniroute
|
|
VERSION: ${{ needs.prepare.outputs.version }}
|
|
PROMOTE_LATEST: ${{ needs.prepare.outputs.promote_latest }}
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
ref: ${{ github.event_name == 'workflow_dispatch' && format('refs/tags/v{0}', inputs.version) || '' }}
|
|
fetch-depth: 0
|
|
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@v4
|
|
|
|
- name: Login to Docker Hub
|
|
uses: docker/login-action@v4
|
|
with:
|
|
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
|
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
|
|
|
- name: Login to GitHub Container Registry
|
|
uses: docker/login-action@v4
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Download base digests
|
|
uses: actions/download-artifact@v8
|
|
with:
|
|
pattern: digests-base-*
|
|
path: /tmp/digests/base
|
|
merge-multiple: true
|
|
|
|
- name: Download web digests
|
|
uses: actions/download-artifact@v8
|
|
with:
|
|
pattern: digests-web-*
|
|
path: /tmp/digests/web
|
|
merge-multiple: true
|
|
|
|
- name: Create Docker Hub manifest
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
create_manifest() {
|
|
local image="$1" suffix="$2" dir="$3"
|
|
local tags=(-t "${image}:${VERSION}${suffix}")
|
|
if [ "$PROMOTE_LATEST" = "true" ]; then
|
|
tags+=(-t "${image}:latest${suffix}")
|
|
fi
|
|
local refs=()
|
|
while IFS= read -r digest_file; do
|
|
refs+=("${image}@sha256:$(basename "$digest_file")")
|
|
done < <(find "$dir" -type f | sort)
|
|
if [ "${#refs[@]}" -eq 0 ]; then
|
|
echo "No image digests in $dir" >&2
|
|
exit 1
|
|
fi
|
|
docker buildx imagetools create "${tags[@]}" "${refs[@]}"
|
|
}
|
|
|
|
create_manifest "${IMAGE_NAME}" "" /tmp/digests/base
|
|
create_manifest "${IMAGE_NAME}" "-web" /tmp/digests/web
|
|
|
|
- name: Create GHCR manifest
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
create_manifest() {
|
|
local image="$1" suffix="$2" dir="$3"
|
|
local tags=(-t "${image}:${VERSION}${suffix}")
|
|
if [ "$PROMOTE_LATEST" = "true" ]; then
|
|
tags+=(-t "${image}:latest${suffix}")
|
|
fi
|
|
local refs=()
|
|
while IFS= read -r digest_file; do
|
|
refs+=("${image}@sha256:$(basename "$digest_file")")
|
|
done < <(find "$dir" -type f | sort)
|
|
if [ "${#refs[@]}" -eq 0 ]; then
|
|
echo "No image digests in $dir" >&2
|
|
exit 1
|
|
fi
|
|
docker buildx imagetools create "${tags[@]}" "${refs[@]}"
|
|
}
|
|
|
|
create_manifest "${GHCR_IMAGE_NAME}" "" /tmp/digests/base
|
|
create_manifest "${GHCR_IMAGE_NAME}" "-web" /tmp/digests/web
|
|
|
|
- name: Inspect image
|
|
if: needs.prepare.outputs.version != 'main'
|
|
run: |
|
|
docker buildx imagetools inspect "${IMAGE_NAME}:${VERSION}"
|
|
|
|
- name: Generate CycloneDX SBOM (image, advisory)
|
|
if: needs.prepare.outputs.version != 'main'
|
|
continue-on-error: true
|
|
uses: anchore/sbom-action@v0
|
|
with:
|
|
image: ${{ env.GHCR_IMAGE_NAME }}:${{ env.VERSION }}
|
|
format: cyclonedx-json
|
|
output-file: sbom-image.cdx.json
|
|
artifact-name: sbom-image.cdx.json
|
|
|
|
- name: Trivy image scan (advisory)
|
|
if: needs.prepare.outputs.version != 'main'
|
|
continue-on-error: true
|
|
uses: aquasecurity/trivy-action@v0.36.0
|
|
with:
|
|
image-ref: ${{ env.GHCR_IMAGE_NAME }}:${{ env.VERSION }}
|
|
format: sarif
|
|
output: trivy-results.sarif
|
|
severity: HIGH,CRITICAL
|
|
exit-code: "0"
|
|
|
|
- name: Upload Trivy SARIF to Security tab
|
|
if: needs.prepare.outputs.version != 'main'
|
|
continue-on-error: true
|
|
uses: github/codeql-action/upload-sarif@v3
|
|
with:
|
|
sarif_file: trivy-results.sarif
|
|
category: trivy-image
|
|
|
|
- name: Update Docker Hub description
|
|
# Only refresh README/description when we actually promote :latest
|
|
# (avoids overwriting from main pushes or back-fill builds).
|
|
if: needs.prepare.outputs.promote_latest == 'true'
|
|
uses: peter-evans/dockerhub-description@v5
|
|
with:
|
|
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
|
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
|
repository: diegosouzapw/omniroute
|
|
short-description: "OmniRoute — Unified AI proxy. Route any LLM through one endpoint."
|
|
readme-filepath: ./README.md
|