Compare commits

..

2 Commits

Author SHA1 Message Date
MickLesk 9a597a5453 add dependabot for gh actions 2026-07-27 19:49:39 +02:00
MickLesk d1bb6b37ce Bump GitHub Actions across workflows
Update workflow dependencies to newer major versions in repository automation files. This upgrades `actions/checkout` to v7, `actions/github-script` to v9, `actions/create-github-app-token` to v3, and GitHub Pages actions (`upload-pages-artifact` and `deploy-pages`) to v5 to keep CI/CD and maintenance workflows current.
2026-07-27 19:48:57 +02:00
22 changed files with 64 additions and 104 deletions
+17
View File
@@ -0,0 +1,17 @@
# Keeps the GitHub Actions referenced in .github/workflows up to date.
# https://docs.github.com/code-security/dependabot/working-with-dependabot/dependabot-options-reference
version: 2
updates:
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
day: "monday"
open-pull-requests-limit: 5
labels:
- "dependencies"
# One PR per week for all action bumps instead of one PR per action.
groups:
github-actions:
patterns:
- "*"
+3 -3
View File
@@ -20,21 +20,21 @@ jobs:
steps:
- name: Generate a token
id: generate-token
uses: actions/create-github-app-token@v1
uses: actions/create-github-app-token@v3
with:
app-id: ${{ vars.APP_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}
- name: Generate a token for PR approval and merge
id: generate-token-merge
uses: actions/create-github-app-token@v1
uses: actions/create-github-app-token@v3
with:
app-id: ${{ secrets.APP_ID_APPROVE_AND_MERGE }}
private-key: ${{ secrets.APP_KEY_APPROVE_AND_MERGE }}
# Step 1: Checkout repository
- name: Checkout repository
uses: actions/checkout@v2
uses: actions/checkout@v7
# Step 2: Disable file mode changes detection
- name: Disable file mode changes
+2 -2
View File
@@ -16,13 +16,13 @@ jobs:
CONFIG_PATH: .github/autolabeler-config.json
steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@v7
- name: Install dependencies
run: npm install minimatch
- name: Label PR based on file changes, title, and PR template
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const fs = require('fs').promises;
+4 -4
View File
@@ -19,25 +19,25 @@ jobs:
steps:
- name: Generate a token
id: generate-token
uses: actions/create-github-app-token@v1
uses: actions/create-github-app-token@v3
with:
app-id: ${{ vars.APP_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}
- name: Generate a token for PR approval and merge
id: generate-token-merge
uses: actions/create-github-app-token@v1
uses: actions/create-github-app-token@v3
with:
app-id: ${{ secrets.APP_ID_APPROVE_AND_MERGE }}
private-key: ${{ secrets.APP_KEY_APPROVE_AND_MERGE }}
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
fetch-depth: 0
- name: Archive old changelog entries
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const fs = require('fs').promises;
+5 -5
View File
@@ -19,20 +19,20 @@ jobs:
steps:
- name: Generate a token
id: generate-token
uses: actions/create-github-app-token@v1
uses: actions/create-github-app-token@v3
with:
app-id: ${{ vars.APP_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}
- name: Generate a token for PR approval and merge
id: generate-token-merge
uses: actions/create-github-app-token@v1
uses: actions/create-github-app-token@v3
with:
app-id: ${{ secrets.APP_ID_APPROVE_AND_MERGE }}
private-key: ${{ secrets.APP_KEY_APPROVE_AND_MERGE }}
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
fetch-depth: 0
@@ -53,7 +53,7 @@ jobs:
- name: Get categorized pull requests
id: get-categorized-prs
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
async function main() {
@@ -213,7 +213,7 @@ jobs:
return await main();
- name: Update CHANGELOG.md
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const fs = require('fs').promises;
+1 -1
View File
@@ -17,7 +17,7 @@ jobs:
steps:
- name: Checkout Repository
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
ref: main
+3 -3
View File
@@ -15,7 +15,7 @@ jobs:
contents: read
steps:
- name: Close PR if it does not follow the PR template
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const pr = context.payload.pull_request;
@@ -45,7 +45,7 @@ jobs:
}
const labels = pr.labels.map((label) => label.name);
const skipLabels = ["automated pr", "keep-open"];
const skipLabels = ["automated pr", "keep open"];
if (skipLabels.some((label) => labels.includes(label))) {
core.info(`PR #${prNumber} has a skip label (${labels.join(", ")}) — skipping template validation.`);
@@ -136,7 +136,7 @@ jobs:
``,
`> Use the template sections, fill in the description, check all prerequisite boxes, and select at least one type of change.`,
``,
`Maintainers can add the \`keep-open\` label to exempt a PR from this check.`,
`Maintainers can add the \`keep open\` label to exempt a PR from this check.`,
``,
`Thank you for contributing! 🙏`,
].join("\n");
+1 -1
View File
@@ -14,7 +14,7 @@ jobs:
contents: read
steps:
- name: Close PR if unauthorized new script submission
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const pr = context.payload.pull_request;
+1 -1
View File
@@ -9,7 +9,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Auto-close if tteck script detected
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const issue = context.payload.issue;
+1 -1
View File
@@ -16,7 +16,7 @@ jobs:
steps:
- name: Checkout target repo (merge commit)
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
repository: community-scripts/ProxmoxVE
ref: ${{ github.event.pull_request.merge_commit_sha }}
+1 -1
View File
@@ -19,7 +19,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Delete branches of merged PRs
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const owner = context.repo.owner;
+1 -1
View File
@@ -17,7 +17,7 @@ jobs:
runs-on: self-hosted
steps:
- name: Checkout Repository
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
fetch-depth: 0
+1 -1
View File
@@ -13,7 +13,7 @@ jobs:
contents: write
steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@v7
- name: Clean CHANGELOG (remove HTML header)
run: sed -n '/^## /,$p' CHANGELOG.md > changelog_cleaned.md
+1 -1
View File
@@ -14,7 +14,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Lock old issues and PRs
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const daysBeforeLock = 7;
+1 -1
View File
@@ -26,7 +26,7 @@ jobs:
steps:
- name: Mint GitHub App token (bot identity)
id: app-token
uses: actions/create-github-app-token@v1
uses: actions/create-github-app-token@v3
with:
app-id: ${{ secrets.PB_BOT_APP_ID }}
private-key: ${{ secrets.PB_BOT_APP_PRIVATE_KEY }}
+1 -1
View File
@@ -12,7 +12,7 @@ jobs:
runs-on: self-hosted
steps:
- name: Checkout Repository
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
fetch-depth: 0
+1 -1
View File
@@ -16,7 +16,7 @@ jobs:
contents: read
steps:
- name: Handle stale PRs
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const now = new Date();
+3 -3
View File
@@ -13,7 +13,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
- name: Create redirect page
run: |
@@ -33,9 +33,9 @@ jobs:
</html>
EOF
- uses: actions/upload-pages-artifact@v3
- uses: actions/upload-pages-artifact@v5
with:
path: site
- name: Deploy
uses: actions/deploy-pages@v4
uses: actions/deploy-pages@v5
+1 -1
View File
@@ -16,7 +16,7 @@ jobs:
runs-on: self-hosted
steps:
- name: Checkout Repository
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
fetch-depth: 0
-8
View File
@@ -508,14 +508,6 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
</details>
## 2026-07-28
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Cloudflare-DDNS: store API token in a 600 env file and build the binary at install time [@angusmaul](https://github.com/angusmaul) ([#16100](https://github.com/community-scripts/ProxmoxVE/pull/16100))
## 2026-07-27
### 🆕 New Scripts
+3 -27
View File
@@ -11,7 +11,7 @@ var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-1024}"
var_disk="${var_disk:-3}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_version="${var_version:-12}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
@@ -24,35 +24,11 @@ function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -f /usr/local/bin/ddns ]]; then
if [[ ! -f /etc/systemd/system/cloudflare-ddns.service ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "cloudflare-ddns" "favonia/cloudflare-ddns"; then
msg_info "Stopping Service"
systemctl stop cloudflare-ddns
msg_ok "Stopped Service"
setup_go
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "cloudflare-ddns" "favonia/cloudflare-ddns" "tarball"
msg_info "Updating ${APP}"
cd /opt/cloudflare-ddns
export CGO_ENABLED=0 GOOS=linux
$STD go build -trimpath -ldflags="-s -w" -o /usr/local/bin/ddns ./cmd/ddns
msg_ok "Updated ${APP}"
msg_info "Removing Build Dependencies"
rm -rf /usr/local/go /usr/local/bin/go /usr/local/bin/gofmt /root/go /root/.cache/go-build /opt/cloudflare-ddns
msg_ok "Removed Build Dependencies"
msg_info "Starting Service"
systemctl start cloudflare-ddns
msg_ok "Started Service"
msg_ok "Updated successfully!"
fi
msg_error "There is no update function for ${APP}."
exit
}
+12 -37
View File
@@ -13,6 +13,8 @@ setting_up_container
network_check
update_os
setup_go
var_cf_api_token="default"
read -rp "${TAB3}Enter the Cloudflare API token: " var_cf_api_token
@@ -51,50 +53,23 @@ while true; do
done
msg_ok "Configured Application"
setup_go
fetch_and_deploy_gh_release "cloudflare-ddns" "favonia/cloudflare-ddns" "tarball"
msg_info "Building ${APPLICATION}"
cd /opt/cloudflare-ddns
export CGO_ENABLED=0 GOOS=linux
$STD go build -trimpath -ldflags="-s -w" -o /usr/local/bin/ddns ./cmd/ddns
msg_ok "Built ${APPLICATION}"
# The binary is statically linked (CGO_ENABLED=0), so Go is only a build-time
# dependency. Removing it keeps the container small; update_script reinstalls it
# via setup_go when a rebuild is needed.
msg_info "Removing Build Dependencies"
rm -rf /usr/local/go /usr/local/bin/go /usr/local/bin/gofmt /root/go /root/.cache/go-build /opt/cloudflare-ddns
msg_ok "Removed Build Dependencies"
msg_info "Setting up service"
useradd --system --no-create-home --shell /usr/sbin/nologin cloudflare-ddns 2>/dev/null || true
cat <<EOF >/etc/cloudflare-ddns.env
CLOUDFLARE_API_TOKEN=${var_cf_api_token}
DOMAINS=${var_cf_domains}
PROXIED=${var_cf_proxied}
IP6_PROVIDER=${var_cf_ip6_provider}
EOF
chown root:root /etc/cloudflare-ddns.env
chmod 600 /etc/cloudflare-ddns.env
mkdir -p /root/go
cat <<EOF >/etc/systemd/system/cloudflare-ddns.service
[Unit]
Description=Cloudflare DDNS Service
After=network-online.target
Wants=network-online.target
Description=Cloudflare DDNS Service (Go run)
After=network.target
[Service]
Type=simple
User=cloudflare-ddns
Group=cloudflare-ddns
EnvironmentFile=/etc/cloudflare-ddns.env
ExecStart=/usr/local/bin/ddns
Environment="CLOUDFLARE_API_TOKEN=${var_cf_api_token}"
Environment="DOMAINS=${var_cf_domains}"
Environment="PROXIED=${var_cf_proxied}"
Environment="IP6_PROVIDER=${var_cf_ip6_provider}"
Environment="GOPATH=/root/go"
Environment="GOCACHE=/tmp/go-build"
ExecStart=/usr/local/bin/go run github.com/favonia/cloudflare-ddns/cmd/ddns@latest
Restart=always
RestartSec=300
NoNewPrivileges=true
ProtectSystem=strict
ProtectHome=true
PrivateTmp=true
[Install]
WantedBy=multi-user.target