diff --git a/.github/renovate.json b/.github/renovate.json new file mode 100644 index 0000000000..a7652417c0 --- /dev/null +++ b/.github/renovate.json @@ -0,0 +1,128 @@ +{ + "$schema": "https://docs.renovatebot.com/renovate-schema.json", + "extends": [ + "config:best-practices", + ":enablePreCommit", + ":semanticCommits", + ":enableVulnerabilityAlertsWithLabel(security)", + "docker:enableMajor", + "helpers:pinGitHubActionDigestsToSemver", + "helpers:disableTypesNodeMajor", + "security:openssf-scorecard", + "customManagers:githubActionsVersions", + "customManagers:dockerfileVersions" + ], + "timezone": "Europe/Madrid", + "baseBranches": [ + "master" + ], + "labels": [ + "dependencies" + ], + "dependencyDashboardTitle": "Dependency Dashboard", + "prConcurrentLimit": 20, + "prHourlyLimit": 10, + "vulnerabilityAlerts": { + "prHourlyLimit": 0, + "prConcurrentLimit": 0 + }, + "configMigration": true, + "minimumReleaseAge": "7 days", + "rangeStrategy": "pin", + "packageRules": [ + { + "description": "Minors: 8th of every 3 months, Madrid overnight window (22:00-06:00)", + "matchUpdateTypes": [ + "minor" + ], + "schedule": [ + "* 22-23,0-5 8 */3 *" + ] + }, + { + "description": "Majors: 15th of every 3 months, Madrid overnight window", + "matchUpdateTypes": [ + "major" + ], + "schedule": [ + "* 22-23,0-5 15 */3 *" + ] + }, + { + "description": "GitHub Actions - single grouped PR, no changelog, scope=ci", + "matchManagers": [ + "github-actions" + ], + "groupName": "github-actions", + "semanticCommitScope": "ci", + "addLabels": [ + "no-changelog" + ] + }, + { + "description": "Docker images - single grouped PR, no changelog, scope=docker", + "matchManagers": [ + "dockerfile", + "docker-compose" + ], + "groupName": "docker", + "semanticCommitScope": "docker", + "addLabels": [ + "no-changelog" + ] + }, + { + "description": "Pre-commit hooks - single grouped PR, scope=pre-commit", + "matchManagers": [ + "pre-commit" + ], + "groupName": "pre-commit hooks", + "semanticCommitScope": "pre-commit", + "addLabels": [ + "no-changelog" + ] + }, + { + "description": "UI - scope=ui", + "matchFileNames": [ + "ui/**" + ], + "semanticCommitScope": "ui" + }, + { + "description": "API - scope=api", + "matchFileNames": [ + "api/**" + ], + "semanticCommitScope": "api" + }, + { + "description": "MCP server - scope=mcp", + "matchFileNames": [ + "mcp_server/**" + ], + "semanticCommitScope": "mcp" + }, + { + "description": "Python SDK (root) - scope=sdk", + "matchFileNames": [ + "pyproject.toml", + "poetry.lock", + "util/prowler-bulk-provisioning/**" + ], + "semanticCommitScope": "sdk" + }, + { + "description": "UI devDependencies - no changelog", + "matchFileNames": [ + "ui/**" + ], + "matchDepTypes": [ + "devDependencies" + ], + "addLabels": [ + "no-changelog" + ] + } + ] +} diff --git a/.github/workflows/renovate-config-validate.yml b/.github/workflows/renovate-config-validate.yml new file mode 100644 index 0000000000..af32eac074 --- /dev/null +++ b/.github/workflows/renovate-config-validate.yml @@ -0,0 +1,57 @@ +name: 'CI: Renovate Config Validate' + +on: + pull_request: + branches: + - 'master' + paths: + - '.github/renovate.json' + - '.pre-commit-config.yaml' + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number }} + cancel-in-progress: true + +permissions: {} + +env: + # renovate: datasource=pypi depName=prek + PREK_VERSION: '0.4.0' + +jobs: + validate: + name: Validate Renovate config + runs-on: ubuntu-latest + timeout-minutes: 10 + permissions: + contents: read + + steps: + - name: Harden Runner + uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 + with: + egress-policy: block + allowed-endpoints: > + api.github.com:443 + github.com:443 + objects.githubusercontent.com:443 + codeload.github.com:443 + release-assets.githubusercontent.com:443 + pypi.org:443 + files.pythonhosted.org:443 + registry.npmjs.org:443 + nodejs.org:443 + + - name: Checkout repository + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: Set up uv + uses: astral-sh/setup-uv@5a095e7a2014a4212f075830d4f7277575a9d098 # v7.3.1 + + - name: Install prek + run: uv tool install "prek==${PREK_VERSION}" + + - name: Validate Renovate config + run: prek run renovate-config-validator --files .github/renovate.json diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index dcd4581ef0..1d894cf531 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -49,6 +49,14 @@ repos: files: ^\.github/(workflows|actions)/.+\.ya?ml$|^\.github/dependabot\.ya?ml$ priority: 30 + ## RENOVATE + - repo: https://github.com/renovatebot/pre-commit-hooks + rev: 43.150.0 + hooks: + - id: renovate-config-validator + files: ^\.github/renovate\.json$ + priority: 10 + ## BASH - repo: https://github.com/koalaman/shellcheck-precommit rev: v0.11.0 diff --git a/.worktreeinclude b/.worktreeinclude index a9fce75e0f..b2828287f7 100644 --- a/.worktreeinclude +++ b/.worktreeinclude @@ -1,2 +1,3 @@ .envrc ui/.env.local +openspec/ diff --git a/docs/security/software-security.mdx b/docs/security/software-security.mdx index eb3afc606f..3fee8d1251 100644 --- a/docs/security/software-security.mdx +++ b/docs/security/software-security.mdx @@ -101,6 +101,28 @@ Dependencies are scanned against public vulnerability databases on every pull re - Per-vulnerability ignores live in [`osv-scanner.toml`](https://github.com/prowler-cloud/prowler/blob/master/osv-scanner.toml) at the repo root, each with a reason and an expiry date. - **Trivy:** scans container images for OS-package and application-dependency vulnerabilities. Runs in [`sdk-container-checks.yml`](https://github.com/prowler-cloud/prowler/blob/master/.github/workflows/sdk-container-checks.yml), [`api-container-checks.yml`](https://github.com/prowler-cloud/prowler/blob/master/.github/workflows/api-container-checks.yml), [`ui-container-checks.yml`](https://github.com/prowler-cloud/prowler/blob/master/.github/workflows/ui-container-checks.yml), and [`mcp-container-checks.yml`](https://github.com/prowler-cloud/prowler/blob/master/.github/workflows/mcp-container-checks.yml). Trivy uploads SARIF to the GitHub Security tab and posts a scan summary on the PR. - **Dependabot:** [configured](https://github.com/prowler-cloud/prowler/blob/master/.github/dependabot.yml) for monthly updates of the SDK Python dependencies, GitHub Actions, Docker base images, and pre-commit hooks. Dependabot opens pull requests for known security advisories, so critical patches reach the team without delay. A 7-day default cooldown reduces exposure to compromised package releases. +- **Renovate:** [configured](https://github.com/prowler-cloud/prowler/blob/master/.github/renovate.json) dependency update automation is transitioning from Dependabot to **Renovate** to gain finer control over update cadence, grouping, and per-component scope. Both tools currently run in parallel during the migration. + +#### Renovate (Primary) + +Configuration: [`.github/renovate.json`](https://github.com/prowler-cloud/prowler/blob/master/.github/renovate.json) + +- **Coverage:** Python (SDK, API, MCP Server), npm (UI), GitHub Actions, Docker images, and Pre-commit hooks +- **Range Strategy:** Versions are pinned to ensure reproducible builds +- **Vulnerability Alerts:** GitHub Security Advisories generate immediate pull requests that bypass rate limits and scheduled windows, labeled `security` for prioritized triage + +#### Dependabot (Legacy) + +Configuration: [`.github/dependabot.yml`](https://github.com/prowler-cloud/prowler/blob/master/.github/dependabot.yml) + +Dependabot remains active for the SDK and shared automation ecosystems until the Renovate migration completes: + +- **Python (pip):** Monthly updates for SDK +- **GitHub Actions:** Monthly updates for workflow dependencies +- **Docker:** Monthly updates for base images +- **Pre-commit:** Monthly updates for hook revisions + +Dependabot is paused for the API and UI; Renovate now handles those components. Even when paused, Dependabot continues to open pull requests for security vulnerabilities, ensuring critical patches are never delayed. ### JavaScript/TypeScript (UI)