Skip to content
This repository has been archived by the owner on Apr 5, 2024. It is now read-only.

[DO NOT MERGE] test E2ESDK #154

Closed
wants to merge 13 commits into from
Closed

[DO NOT MERGE] test E2ESDK #154

wants to merge 13 commits into from

Conversation

matmut7
Copy link
Member

@matmut7 matmut7 commented Apr 18, 2023

No description provided.

@gitguardian
Copy link

gitguardian bot commented Apr 18, 2023

️✅ There are no secrets present in this pull request anymore.

If these secrets were true positive and are still valid, we highly recommend you to revoke them.
Once a secret has been leaked into a git repository, you should consider it compromised, even if it was deleted immediately.
Find here more information about risks.


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

Our GitHub checks need improvements? Share your feedbacks!

@matmut7 matmut7 changed the base branch from main to hasura April 18, 2023 15:25
* fix

* cosmetics

* fix

* fix: dockerfile hasura
@revolunet revolunet temporarily deployed to review April 25, 2023 09:00 — with GitHub Actions Inactive
@SocialGroovyBot SocialGroovyBot temporarily deployed to review-test-e2e April 25, 2023 09:01 Destroyed
@socket-security
Copy link

socket-security bot commented Apr 25, 2023

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Issue Package Version Note Source
Install scripts @swc/core 1.3.49
  • Install script: postinstall
  • Source: node postinstall.js
package.json via @socialgouv/[email protected]
Install scripts hasura-cli 2.25.0
  • Install script: postinstall
  • Source: node dist/index.js
package.json

Next steps

What is an install script?

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore [email protected] bar@* or ignore all packages with @SocketSecurity ignore-all

* fix

* fixe

* fix

* cleanup

* basic upload

* add dropzone

* fix: more

* fix: keys

* fix: answers in nav

* feat: upload files

* fix: file key leak

* feat: read files

* feat: random files gen + refine files read

* fix: use keycloak UUID + cosmetics

* fix: fake submissions

* doc

* csp

* fix

* fix csp + upload dir

* upload

* disable-size

* debug

* clean

---------

Co-authored-by: Matéo Mévollon <[email protected]>
Co-authored-by: devthejo <[email protected]>
@revolunet revolunet temporarily deployed to review May 24, 2023 22:16 — with GitHub Actions Inactive
@SocialGroovyBot SocialGroovyBot temporarily deployed to review-test-e2e May 24, 2023 22:17 Destroyed
* fix-csp

* cleanup

* Update src/lib/e2esdk.ts

Co-authored-by: François Best <[email protected]>

* fix: use @socialgouv/e2esdk-crypto.fileMetadataSchema

* fix: readAndEncryptFile signature

* feat: use modal for file previews

* dummy

---------

Co-authored-by: François Best <[email protected]>
@SocialGroovyBot SocialGroovyBot temporarily deployed to review-test-e2e June 5, 2023 06:47 Destroyed
@SocialGroovyBot SocialGroovyBot temporarily deployed to review-test-e2e June 14, 2023 15:25 Destroyed
@socket-security
Copy link

socket-security bot commented Jun 14, 2023

New and updated dependency changes detected. Learn more about Socket for GitHub ↗︎

Packages Version New capabilities Transitives1 Size Publisher
js-image-generator 🆕 1.0.4 None +1 78.5 kB ahupp
@socialgouv/e2esdk-react 🆕 1.0.0-beta.27 network +11 2.13 MB socialgroovybot
@socialgouv/e2esdk-crypto 🆕 1.0.0-beta.19 network, filesystem +6 1.42 MB socialgroovybot
@socialgouv/e2esdk-client 🆕 1.0.0-beta.27 network, filesystem +10 2.12 MB socialgroovybot
@types/formidable 🆕 2.0.6 None +0 18.7 kB types
boring-avatars 🆕 1.7.0 None +0 23.3 kB josepmartins
@socialgouv/e2esdk-devtools 🆕 1.0.0-beta.37 network +195 718 MB socialgroovybot
react-dropzone 🆕 14.2.3 None +2 639 kB rolandjitsu
random-words 🆕 1.3.0 None +1 406 kB boutell
hasura-cli 🆕 2.25.0 filesystem, environment +1 398 kB jjangga0214
formidable 🆕 3.2.5 None +3 138 kB grossacasacs
react-hook-form 🆕 7.44.2 network +0 854 kB bluebill1049
zod 🆕 3.21.4 None +0 604 kB colinmcd94
eslint-config-next ⬆️ 13.1.0...13.4.4 None +11/-12 6.42 MB vercel-release-bot
next-auth ⬆️ 4.19.2...4.22.1 network +4/-4 1.51 MB balazsorban
@mui/material ⬆️ 5.11.7...5.13.3 None +30/-43 22.9 MB hbjorbj
node-talisman ⬆️ 1.29.6...1.29.10 None +0/-0 62 kB pgmanutd
@emotion/server ⬆️ 11.10.0...11.11.0 None +1/-1 67 kB emotion-release-bot
@emotion/styled ⬆️ 11.10.5...11.11.0 None +17/-32 3.89 MB emotion-release-bot
@codegouvfr/react-dsfr ⬆️ 0.28.0...0.58.1 environment +1/-1 60.8 MB garronej
@emotion/react ⬆️ 11.10.5...11.11.0 None +15/-30 3.68 MB emotion-release-bot
@babel/core ⬆️ 7.20.12...7.22.1 None +17/-18 9.13 MB nicolo-ribaudo
tsx ⬆️ 3.12.2...3.12.7 None +4/-2 374 kB hirokiosame
@mui/icons-material ⬆️ 5.11.0...5.11.16 None +31/-44 41.4 MB siriwatknp
@mui/x-data-grid ⬆️ 5.17.22...6.5.0 None +32/-45 28.6 MB danailh
eslint ⬆️ 8.30.0...8.41.0 None +9/-10 6.34 MB eslintbot
eslint-plugin-storybook ⬆️ 0.5.13...0.6.12 None +15/-13 8.33 MB yannbf

🚮 Removed packages: [email protected]

Footnotes

  1. https://docs.socket.dev

@SocialGroovyBot SocialGroovyBot temporarily deployed to review-test-e2e June 14, 2023 15:34 Destroyed
@SocialGroovyBot SocialGroovyBot temporarily deployed to review-test-e2e June 15, 2023 07:28 Destroyed
This includes API breaking changes, though they are not used here.
However, there are data breaking changes that will require
resetting the e2esdk database when upgrading the server.
@SocialGroovyBot SocialGroovyBot temporarily deployed to review-test-e2e June 21, 2023 09:01 Destroyed
@SocialGroovyBot SocialGroovyBot temporarily deployed to review-test-e2e June 21, 2023 12:54 Destroyed
@SocialGroovyBot SocialGroovyBot temporarily deployed to review-test-e2e June 21, 2023 13:03 Destroyed
@revolunet revolunet temporarily deployed to review June 21, 2023 13:10 — with GitHub Actions Inactive
@SocialGroovyBot SocialGroovyBot temporarily deployed to review-test-e2e June 21, 2023 13:13 Destroyed
@SocialGroovyBot SocialGroovyBot temporarily deployed to review-test-e2e June 21, 2023 16:02 Destroyed
@revolunet revolunet temporarily deployed to review June 21, 2023 17:30 — with GitHub Actions Inactive
@SocialGroovyBot SocialGroovyBot temporarily deployed to review-test-e2e June 21, 2023 17:31 Destroyed
@revolunet revolunet temporarily deployed to review June 21, 2023 17:50 — with GitHub Actions Inactive
@SocialGroovyBot SocialGroovyBot temporarily deployed to review-test-e2e June 21, 2023 17:51 Destroyed
* feat: add export new device key

* Update pages/profil.tsx

Co-authored-by: François Best <[email protected]>

---------

Co-authored-by: François Best <[email protected]>
@revolunet revolunet temporarily deployed to review June 27, 2023 21:53 — with GitHub Actions Inactive
@sonarqubecloud
Copy link

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 16 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

@github-actions
Copy link

🎉 Deployment for commit c7dec2e :

Ingresses
Docker images
  • 📦 docker pull harbor.fabrique.social.gouv.fr/fabrique/template/app:sha-c7dec2eecb278aff50cdbfb62b0436bf42666aa0
  • 📦 docker pull harbor.fabrique.social.gouv.fr/fabrique/template/hasura:sha-c7dec2eecb278aff50cdbfb62b0436bf42666aa0
Debug

@revolunet
Copy link
Member

replaced by #169

@revolunet revolunet closed this Sep 21, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants