Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
181 commits
Select commit Hold shift + click to select a range
2bde56e
refactor: move agent and dashboard into lynx/ subfolder
Jaro-c May 12, 2026
6a60093
chore: add GitHub Sponsors funding button
Jaro-c May 12, 2026
883b7a3
chore: add .gitignore, exclude CLAUDE.md
Jaro-c May 12, 2026
36dadab
chore: regenerate node_modules folder to resolve dependency inconsist…
Jaro-c May 12, 2026
916d2fe
chore: add missing node_modules dependencies and source files
Jaro-c May 12, 2026
396d263
feat: initialize Next.js dashboard project with Biome and Tailwind CS…
Jaro-c May 12, 2026
ee4885d
feat: initialize dashboard UI with Next.js, Biome, Tailwind CSS, and …
Jaro-c May 12, 2026
178232b
feat: initialize Next.js dashboard UI project with Tailwind CSS, Biom…
Jaro-c May 12, 2026
4c32cfd
feat: initialize dashboard UI project with Next.js, Tailwind CSS, and…
Jaro-c May 12, 2026
c735362
feat: initialize Next.js dashboard project with Biome configuration a…
Jaro-c May 12, 2026
5951c5d
feat: initialize dashboard UI with Next.js, Tailwind CSS, and shadcn/…
Jaro-c May 12, 2026
91fd7c9
feat: initialize Next.js dashboard UI project with shadcn/ui and Tail…
Jaro-c May 12, 2026
b594fae
feat: initialize Next.js dashboard project with Shadcn UI and project…
Jaro-c May 12, 2026
af76205
feat: initialize Next.js dashboard UI with shadcn/ui components
Jaro-c May 12, 2026
4789b8b
feat: initialize Next.js dashboard project with Shadcn UI components …
Jaro-c May 12, 2026
c835145
feat: initialize dashboard UI with Next.js, Tailwind CSS, shadcn/ui c…
Jaro-c May 12, 2026
3649dba
feat: initialize dashboard UI with Tailwind CSS, Next.js configuratio…
Jaro-c May 12, 2026
2b7fb7b
feat: scaffold new Next.js dashboard UI with component library and co…
Jaro-c May 12, 2026
e642dbc
feat: initialize dashboard UI with Next.js 16, shadcn/ui components, …
Jaro-c May 12, 2026
346d380
feat: scaffold Next.js dashboard UI and implement system management u…
Jaro-c May 13, 2026
ee9b085
feat: implement Next.js dashboard scaffolding and automate system mig…
Jaro-c May 13, 2026
71fb136
feat: initialize Next.js dashboard UI with Tailwind CSS and Shadcn, a…
Jaro-c May 13, 2026
07c3880
feat: initialize dashboard Next.js project and harden Podman storage,…
Jaro-c May 13, 2026
e722b78
feat: initialize Next.js dashboard UI and add installation scripts fo…
Jaro-c May 13, 2026
9232e36
feat: initialize dashboard UI project structure and agent installatio…
Jaro-c May 13, 2026
a1c49db
feat: scaffold Lynx dashboard UI with shadcn/ui and implement agent i…
Jaro-c May 13, 2026
7eae606
feat: initialize Lynx dashboard UI and deployment scripts
Jaro-c May 13, 2026
fea111a
feat: initialize dashboard project structure, UI components, and auto…
Jaro-c May 13, 2026
08f5779
feat: initialize Next.js dashboard UI project and add installation sc…
Jaro-c May 13, 2026
45ae3f4
feat: initialize dashboard UI and add agent/infrastructure installati…
Jaro-c May 13, 2026
e81009c
feat: initialize Next.js dashboard project with Shadcn UI and add age…
Jaro-c May 13, 2026
ec10310
feat: initialize dashboard UI framework and add agent/dashboard insta…
Jaro-c May 13, 2026
ee24928
feat: initialize dashboard UI project with Next.js, Tailwind CSS, and…
Jaro-c May 13, 2026
2941ba9
feat: initialize dashboard UI project structure with Tailwind CSS, co…
Jaro-c May 13, 2026
651a4c6
feat: initialize Next.js dashboard UI project and update lint-shell w…
Jaro-c May 13, 2026
e41e367
feat: initialize dashboard UI with Next.js, Tailwind CSS, shadcn/ui c…
Jaro-c May 13, 2026
eb78e2f
feat: initialize Next.js dashboard UI project with Tailwind CSS and S…
Jaro-c May 13, 2026
4939cb5
feat: initialize dashboard UI with Next.js, Tailwind CSS, and shadcn …
Jaro-c May 13, 2026
19c47a3
feat: initialize dashboard UI with standard components and app structure
Jaro-c May 13, 2026
8958c0b
feat: initialize dashboard UI with comprehensive component library an…
Jaro-c May 13, 2026
ecb3724
feat: initialize dashboard UI with Next.js template and standardized …
Jaro-c May 13, 2026
c362234
feat: initialize Next.js dashboard UI project with Tailwind CSS and b…
Jaro-c May 13, 2026
b466c1a
feat: integrate shadcn/ui and configure agentic development skills fo…
Jaro-c May 13, 2026
5e33c26
feat: scaffold shadcn/ui integration with comprehensive agent rules a…
Jaro-c May 13, 2026
3f901b2
feat: implement dashboard backend, container orchestration service, a…
Jaro-c May 13, 2026
3325d88
feat: implement dashboard server with Docker support and refactor com…
Jaro-c May 13, 2026
e873b5d
feat: implement core compose utilities, file parsing tests, and dashb…
Jaro-c May 13, 2026
c8c1e0f
feat: initialize monorepo structure with dashboard server, agent, and…
Jaro-c May 13, 2026
6d8bbdd
chore: initialize project configuration in Cargo.toml
Jaro-c May 14, 2026
203343c
docs: add styling guidelines and agent documentation to UI dashboard
Jaro-c May 14, 2026
0c4b3b2
feat: initialize dashboard server and agent modules while expanding D…
Jaro-c May 14, 2026
65facdd
feat: implement file-watch engine with develop support and initialize…
Jaro-c May 14, 2026
16986bf
feat: initialize lynx project structure including dashboard UI, backe…
Jaro-c May 14, 2026
0eb7344
feat: implement dashboard scaffolding and refactor compose type modules
Jaro-c May 14, 2026
b8a09de
feat: implement dashboard project scaffolding with containerized serv…
Jaro-c May 15, 2026
934b6be
feat: scaffold monorepo structure with Rust backend and Next.js dashb…
Jaro-c May 15, 2026
87a545e
feat: implement file-watch engine, add workspace configuration, and s…
Jaro-c May 15, 2026
c1d868e
feat: scaffold dashboard service, agent module, and UI architecture w…
Jaro-c May 15, 2026
0216c51
chore(compose): bump version to 0.2.0
Jaro-c May 15, 2026
98d3816
feat: initialize Lynx dashboard and agent infrastructure with base co…
Jaro-c May 15, 2026
6319b14
feat: scaffold dashboard infrastructure and improve compose parser se…
Jaro-c May 15, 2026
b4772a0
feat: initialize dashboard frontend and server with containerization …
Jaro-c May 15, 2026
7f83d10
feat: scaffold dashboard web UI and server, add workspace configurati…
Jaro-c May 15, 2026
b2e9b85
feat(dashboard): implement auth backend + full UI with i18n
Jaro-c May 16, 2026
bc0208b
feat(agent): implement agent core with auth, nftables, Podman, metric…
Jaro-c May 16, 2026
01a68bb
feat(agent): add agent install script with WireGuard, systemd, Podman…
Jaro-c May 16, 2026
a10ec65
feat(ui): add /app/agents page with Server Component, skeleton loadin…
Jaro-c May 16, 2026
8e8ec6e
feat: implement audit log sync (agent → dashboard) with per-agent syn…
Jaro-c May 16, 2026
d3b6636
feat: add organizations backend + UI
Jaro-c May 16, 2026
6742eaa
feat(agent): add nftables divergence detection with dashboard alerting
Jaro-c May 16, 2026
847a249
feat(dashboard/ui): add settings page with session management and key…
Jaro-c May 16, 2026
d230c0d
feat(agent/dashboard): container management commands + auto-update sy…
Jaro-c May 16, 2026
d85498a
feat(dashboard): agent registration dialog, overview stats, events feed
Jaro-c May 16, 2026
fe95617
feat(dashboard/agent): WireGuard PSK rotation
Jaro-c May 16, 2026
e30fa4c
feat(ui): org creation dialog, i18n keys for org/agent registration
Jaro-c May 16, 2026
aba691d
feat(dashboard/agent): internal PKI — CA issues Ed25519 certs to agents
Jaro-c May 16, 2026
e251e92
feat(dashboard): white-label branding from PostgreSQL
Jaro-c May 16, 2026
f63b402
feat(orgs): member management — invite, list, remove
Jaro-c May 16, 2026
ccfe122
feat(orgs): project listing and vertical scaling UI
Jaro-c May 16, 2026
6535752
feat(nftables): divergence detection and restore/accept flow
Jaro-c May 16, 2026
310f38c
feat(orgs): add project creation
Jaro-c May 16, 2026
84f647d
feat(containers): deploy and lifecycle management UI
Jaro-c May 16, 2026
f9a6b5d
feat(ui): persistent footer and dynamic login branding
Jaro-c May 16, 2026
89d12e2
feat(settings): update check and trigger UI
Jaro-c May 16, 2026
c32e3c4
feat(scale): implement cross-agent horizontal scaling via WireGuard d…
Jaro-c May 16, 2026
807ea83
feat(audit): add per-agent audit log viewer
Jaro-c May 16, 2026
00afafe
feat(domain): add custom domain configuration with Let's Encrypt and …
Jaro-c May 16, 2026
0abfb1d
feat(migration): implement dashboard-to-dashboard migration flow
Jaro-c May 16, 2026
437afd3
feat(auth): add password change and profile endpoints
Jaro-c May 16, 2026
148e402
feat(settings): add key rotation history to security section
Jaro-c May 16, 2026
c75925e
feat(pki): push cert.update to online agents on rotation; add CI work…
Jaro-c May 16, 2026
a9eba3c
fix(dashboard): use base64url unpadded encoding for signed commands
Jaro-c May 16, 2026
76b9339
feat(dashboard): add background heartbeat scheduler
Jaro-c May 16, 2026
23b8cee
fix(dashboard): shorten WireGuard interface name to wg-lynx-dash
Jaro-c May 16, 2026
4183614
fix(dashboard): correct Redis key pattern in JWT session flush
Jaro-c May 16, 2026
e2d5939
feat(dashboard): add ip_pool allocator, logs/reset-admin-password CLI…
Jaro-c May 18, 2026
e8e3b17
feat(dashboard): security alerts, headers, startup health guard, inte…
Jaro-c May 18, 2026
d7f560e
feat(agent): command rate limiter (100/min) with rejected_rate_limit …
Jaro-c May 18, 2026
db6d985
feat(domain): route nginx/certbot/nftables ops through local agent
Jaro-c May 18, 2026
cfff764
refactor(agent): split handlers.rs into handlers/ module
Jaro-c May 18, 2026
abc4f7e
feat: add missing files from prior implementation sessions
Jaro-c May 18, 2026
08d6643
feat: implement X.509 mTLS, heartbeat scheduler, PKI, and frontend im…
Jaro-c May 18, 2026
c94b0cd
feat(scheduler): full 90-day rotation — JWT flush + WireGuard PSKs + …
Jaro-c May 18, 2026
6419ada
feat(domain): custom cert upload with PEM validation (Cloudflare + ow…
Jaro-c May 18, 2026
bc6ae01
fix(domain): set_hsts uses correct cert path for cloudflare/custom ce…
Jaro-c May 18, 2026
86066c4
feat(ws): add persistent WebSocket channel between agent and dashboard
Jaro-c May 18, 2026
dc0edb0
feat(ws): skip HTTP heartbeat poll for WS-connected agents
Jaro-c May 18, 2026
6fed478
feat(agent+dashboard): nftables 3-chain architecture, real-time metri…
Jaro-c May 18, 2026
fb89e2c
feat(events): real-time agent events pipeline to browser WS
Jaro-c May 18, 2026
3945337
feat(dashboard): add admin user and role management
Jaro-c May 18, 2026
1bfd75a
feat(dashboard): add theme system and user preferences
Jaro-c May 18, 2026
6aeb9b1
feat(dashboard): add locale switcher and i18n sign-out in sidebar
Jaro-c May 18, 2026
810d494
feat(dashboard): single-session mode and theme-on-login
Jaro-c May 18, 2026
25b84f6
test(dashboard): add integration test suite for auth, admin, rotation…
Jaro-c May 18, 2026
b08992b
test(dashboard/server): add unit tests for crypto, validation, and au…
Jaro-c May 18, 2026
d329fb8
test(dashboard/ui): add Vitest unit tests and Playwright E2E setup
Jaro-c May 18, 2026
363a32a
ci: add CI workflows for agent, dashboard-server, and dashboard-ui
Jaro-c May 18, 2026
7f6c003
refactor(auth): split handlers.rs into handlers/ submodule; add WS or…
Jaro-c May 18, 2026
fc43e13
fix(security): audit log hash chain verification + offline agent pend…
Jaro-c May 18, 2026
8a8896f
fix(ui): cursor-pointer + disabled:cursor-not-allowed on Button; robo…
Jaro-c May 18, 2026
ae54be3
feat(agent): split metrics by frequency; fix WireGuard config path
Jaro-c May 18, 2026
56c640a
feat(dashboard): close remaining CLAUDE.md gaps
Jaro-c May 18, 2026
1760133
fix(lint): resolve all clippy -D warnings + fmt in agent and server
Jaro-c May 18, 2026
78ddf8e
test(dashboard): fix all 17 Playwright E2E tests
Jaro-c May 18, 2026
deb2287
fix(dashboard): install rustls ring provider at startup
Jaro-c May 18, 2026
7bcdd7b
ci: add toolchain: stable to all dtolnay/rust-toolchain usages
Jaro-c May 18, 2026
752c0d7
fix(ci): remove sqlx-mysql CVE and fix compose formatting
Jaro-c May 18, 2026
bc25be8
fix(ci): ignore RUSTSEC-2023-0071 in cargo audit
Jaro-c May 18, 2026
9fcf002
fix(security): validate IDs as UUIDs before URL interpolation in Serv…
Jaro-c May 18, 2026
e7dd4ed
ci(dashboard-ui): pin all action SHAs; quote CI env var as string
Jaro-c May 18, 2026
a3d18fd
chore: merge main into develop to resolve conflicts
Jaro-c May 18, 2026
cfb2db4
fix(ui): add validateName() and inline container URL builds to elimin…
Jaro-c May 18, 2026
8121433
test(e2e): waitForURL on root redirect test to handle RSC redirect ti…
Jaro-c May 18, 2026
0682a34
fix(ui): use .bind() for local nft actions to avoid passing arrow fns…
Jaro-c May 18, 2026
15a405f
fix(ui): pass placeholder values to migrationAgentsProgress to satisf…
Jaro-c May 18, 2026
de2e8cf
ci: add explicit permissions block to all workflows (CodeQL hardening)
Jaro-c May 18, 2026
fd3e17e
merge: resolve add/add conflicts — take develop version
Jaro-c May 18, 2026
9bf3c73
chore: remove tracked junk files and update gitignore
Jaro-c May 18, 2026
de0eb04
fix(gitignore): correct playwright-mcp ignore pattern
Jaro-c May 18, 2026
832b261
refactor: update UI components and dependencies across the dashboard …
Jaro-c May 18, 2026
d46109e
chore(deps): bump actions/upload-artifact from 4.6.2 to 7.0.1 (#7)
dependabot[bot] May 18, 2026
f460013
chore(deps): bump actions/checkout from 4.3.1 to 6.0.2 (#6)
dependabot[bot] May 18, 2026
64bfc5a
chore(dashboard): remove development mode, production only
Jaro-c May 18, 2026
5c7c6e8
feat(nftables): add output chain support and seed global protection r…
Jaro-c May 18, 2026
4f0cbb7
style(ui): apply biome formatting across dashboard ui
Jaro-c May 18, 2026
3e0ca00
fix: replace gen_random_uuid() with uuidv7() — all tables must use UU…
Jaro-c May 18, 2026
3fc84cb
feat(ui): switch font from Geist to Poppins
Jaro-c May 18, 2026
d428e5d
chore(github): add repo metadata files
Jaro-c May 18, 2026
3ea5502
ci: add URL audit script and job to CI pipelines
Jaro-c May 18, 2026
2f1ef2a
ci: add release workflows for agent and dashboard
Jaro-c May 18, 2026
4d9eacc
chore(deps): scan full cargo workspace in dependabot daily
Jaro-c May 18, 2026
500e703
feat(db): add arch column to agents table
Jaro-c May 18, 2026
4ad94ba
feat(agent): report arch in heartbeat, hardcode release key, add fall…
Jaro-c May 18, 2026
a6904af
feat(dashboard): track agent arch and use in arch-aware update dispatch
Jaro-c May 18, 2026
400e999
feat(dashboard): implement full binary swap pipeline for releases
Jaro-c May 18, 2026
b5f1425
fix: strengthen security hardening across agent and dashboard, includ…
Jaro-c May 18, 2026
a3c7e61
refactor: enhance system security with constant-time cryptographic ch…
Jaro-c May 18, 2026
6d3556c
fix(security): prevent SQL injection in DB password rotation
Jaro-c May 18, 2026
cffaeaa
fix(agent): eliminate shell injection in rootless Podman execution
Jaro-c May 18, 2026
e14eae2
fix(agent): add SSRF protection with DNS pinning for binary downloads
Jaro-c May 18, 2026
db565f3
fix(agent): harden WireGuard handler — interface validation, file per…
Jaro-c May 18, 2026
e082264
fix(agent): prevent path traversal in nginx cert path construction
Jaro-c May 18, 2026
f2dfded
fix(security): heartbeat ACK requires Ed25519 signed command — bearer…
Jaro-c May 18, 2026
12573fc
fix(security): validate audit log hash chain on HTTP sync path
Jaro-c May 18, 2026
517f235
fix(security): WS origin validation, vps:read permission checks, WG I…
Jaro-c May 18, 2026
6042f01
fix(auth): per-username rate limit, SHA256 ct_eq for setup token, con…
Jaro-c May 18, 2026
73523f7
fix(auth): enforce nbf and iat claims in JWT validation — reject futu…
Jaro-c May 18, 2026
b77393c
fix(security): strict domain and branding input validation — block pa…
Jaro-c May 18, 2026
da8a555
fix(security): validate IP/CIDR format and port range in nftables rul…
Jaro-c May 18, 2026
715e219
fix(security): add HSTS header to all HTTPS responses
Jaro-c May 18, 2026
d4fbb7d
fix(db): extend cert_type constraint to include cloudflare and custom…
Jaro-c May 18, 2026
d297a40
fix(scripts): replace eval PKG_UPDATE with direct case statement — el…
Jaro-c May 18, 2026
0082eb5
feat(site): add GitHub Pages landing page
Jaro-c May 18, 2026
4473c24
fix(ci): close security audit gaps across all components
Jaro-c May 18, 2026
550cc73
fix(agent): extend nftables_state chain constraint before seeding out…
Jaro-c May 18, 2026
63a36c2
fix(db): renumber conflicting dashboard migrations and fix IPv6 link-…
Jaro-c May 18, 2026
8f702c1
fix(server): refactor update params to struct; bypass rate limit in C…
Jaro-c May 18, 2026
794c044
fix(tests): serialize dashboard-server tests and flush testadmin rate…
Jaro-c May 18, 2026
5c35280
merge: resolve conflicts from main — add security-events:write and mi…
Jaro-c May 18, 2026
533bcd9
fix(ui): remove duplicate migration label props from settings page
Jaro-c May 18, 2026
58e979c
ci(lint-shell): always run shellcheck on PRs to main, not just on .sh…
Jaro-c May 18, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
1 change: 1 addition & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
* @Jaro-c
5 changes: 5 additions & 0 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
blank_issues_enabled: false
contact_links:
- name: Security vulnerability
url: https://github.com/Jaro-c/Lynx/security/advisories/new
about: Report a security vulnerability privately (do not open a public issue)
8 changes: 4 additions & 4 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,13 +12,13 @@ updates:
target-branch: "develop"

- package-ecosystem: "cargo"
directory: "/lynx/translators/compose"
directory: "/lynx"
schedule:
interval: "weekly"
interval: "daily"
labels:
- "dependencies"
- "translator/compose"
open-pull-requests-limit: 5
- "rust"
open-pull-requests-limit: 10
target-branch: "develop"

- package-ecosystem: "bun"
Expand Down
77 changes: 77 additions & 0 deletions .github/scripts/audit-urls.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,77 @@
#!/usr/bin/env python3
"""Audit download modules for HTTP URLs outside the allowed GitHub domains.

Only scans files that perform binary downloads (update modules and scheduler).
Other files (agent command endpoints, nginx configs) are intentionally excluded.

Exits 1 if any non-allowed URL literal is found in non-comment lines.

To suppress a specific line that is intentionally non-GitHub (e.g. a self health check),
add an inline comment:
.get("http://127.0.0.1:8080/health") // audit-urls: ok — reason

Run from the repository root.
"""
import re
import sys
import pathlib

# Only GitHub release domains are allowed for binary downloads.
ALLOWED = re.compile(
r"https?://"
r"(github\.com|objects\.githubusercontent\.com|api\.github\.com)"
)

URL_RE = re.compile(r'https?://[^\s\'">,)]+')

# Format strings / templates — skip lines containing these (not real URLs)
FORMAT_MARKERS = re.compile(r"\{[^}]*\}|\$\w+|%[sdfi]")

COMMENT_RE = re.compile(r"^\s*//")
SUPPRESS_RE = re.compile(r"//\s*audit-urls:\s*ok")

# Only files that perform outbound binary downloads.
# Adding a new download path outside these files requires a conscious update here.
SCAN_FILES = [
"lynx/agent/src/update/mod.rs",
"lynx/agent/src/update/fallback.rs",
"lynx/dashboard/server/src/update.rs",
"lynx/dashboard/server/src/scheduler.rs",
]

failures: list[str] = []

for path_str in SCAN_FILES:
f = pathlib.Path(path_str)
if not f.exists():
print(f"⚠️ Scan target not found: {f} (skipped)")
continue
for i, line in enumerate(f.read_text(encoding="utf-8").splitlines(), 1):
if COMMENT_RE.match(line):
continue
if SUPPRESS_RE.search(line):
continue
if FORMAT_MARKERS.search(line):
continue
for url in URL_RE.findall(line):
if not ALLOWED.match(url):
failures.append(f" {f}:{i} {url}")

if failures:
print("❌ Non-allowed URL found in download modules:")
for entry in failures:
print(entry)
print()
print("Allowed domains: github.com, objects.githubusercontent.com, api.github.com")
print()
print("If this URL is intentional (e.g. a self health check, not a download):")
print(" Add an inline suppression comment on that line:")
print(' .get("http://...") // audit-urls: ok — reason')
print()
print("If this is a new external download domain:")
print(" Add it to ALLOWED in .github/scripts/audit-urls.py with justification.")
sys.exit(1)

scanned = ", ".join(SCAN_FILES)
print(f"✅ All HTTP URLs in download modules are from allowed domains.")
print(f" Scanned: {len(SCAN_FILES)} files")
40 changes: 40 additions & 0 deletions .github/scripts/sign.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
#!/usr/bin/env python3
"""Sign a file with an Ed25519 private key (raw 32-byte seed, base64-encoded).

Usage:
sign.py <base64-private-key> <input-file> [<output-sig-file>]

If output-sig-file is omitted, writes to <input-file>.sig.
The key must be the raw 32-byte Ed25519 seed in standard base64.
"""
import base64
import sys

from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey


def main() -> None:
if len(sys.argv) < 3:
print(__doc__, file=sys.stderr)
sys.exit(1)

key_b64 = sys.argv[1]
input_file = sys.argv[2]
sig_file = sys.argv[3] if len(sys.argv) > 3 else input_file + ".sig"

key_bytes = base64.b64decode(key_b64 + "==")
private_key = Ed25519PrivateKey.from_private_bytes(key_bytes)

with open(input_file, "rb") as f:
data = f.read()

sig = private_key.sign(data)

with open(sig_file, "wb") as f:
f.write(sig)

print(f"signed {input_file} ({len(data):,} bytes) → {sig_file} ({len(sig)} bytes)")


if __name__ == "__main__":
main()
17 changes: 13 additions & 4 deletions .github/workflows/agent.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ jobs:
run:
working-directory: lynx
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # stable
with:
Expand All @@ -45,14 +45,23 @@ jobs:
- name: fmt
run: cargo fmt --package lynx-agent -- --check

audit-urls:
name: Audit download URLs
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- name: Check download URLs are from allowed domains
run: python3 .github/scripts/audit-urls.py

audit:
name: Security audit
runs-on: ubuntu-latest
defaults:
run:
working-directory: lynx
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # stable
with:
Expand Down Expand Up @@ -85,7 +94,7 @@ jobs:
--health-timeout 5s
--health-retries 10
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # stable
with:
Expand Down Expand Up @@ -129,7 +138,7 @@ jobs:
--health-timeout 5s
--health-retries 10
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # stable
with:
Expand Down
23 changes: 21 additions & 2 deletions .github/workflows/compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,14 +23,33 @@ env:
RUST_BACKTRACE: 1

jobs:
audit:
name: Security audit
runs-on: ubuntu-latest
defaults:
run:
working-directory: lynx
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # stable
with:
toolchain: stable

- name: Install cargo-audit
run: cargo install cargo-audit --locked

- name: audit
run: cargo audit --ignore RUSTSEC-2023-0071

check:
name: Check & Lint
runs-on: ubuntu-latest
defaults:
run:
working-directory: lynx
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # stable
with:
Expand All @@ -54,7 +73,7 @@ jobs:
run:
working-directory: lynx
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # stable
with:
Expand Down
19 changes: 14 additions & 5 deletions .github/workflows/dashboard-server.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ jobs:
run:
working-directory: lynx
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # stable
with:
Expand All @@ -43,14 +43,23 @@ jobs:
- name: fmt
run: cargo fmt --package lynx-dashboard-server -- --check

audit-urls:
name: Audit download URLs
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- name: Check download URLs are from allowed domains
run: python3 .github/scripts/audit-urls.py

audit:
name: Security audit
runs-on: ubuntu-latest
defaults:
run:
working-directory: lynx
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # stable
with:
Expand Down Expand Up @@ -83,7 +92,7 @@ jobs:
--health-timeout 5s
--health-retries 10
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # stable
with:
Expand Down Expand Up @@ -136,7 +145,7 @@ jobs:
--health-timeout 5s
--health-retries 10
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # stable
with:
Expand All @@ -155,7 +164,7 @@ jobs:
DATABASE_URL: postgres://lynx_ci:lynx_ci@localhost:5432/lynx_ci

- name: test
run: cargo test --package lynx-dashboard-server
run: cargo test --package lynx-dashboard-server -- --test-threads=1
env:
DATABASE_URL: postgres://lynx_ci:lynx_ci@localhost:5432/lynx_ci
REDIS_URL: redis://localhost:6379
27 changes: 23 additions & 4 deletions .github/workflows/dashboard-ui.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,14 +17,33 @@ permissions:
security-events: write

jobs:
audit:
name: Security audit (bun)
runs-on: ubuntu-latest
defaults:
run:
working-directory: lynx/dashboard/ui
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
with:
bun-version: latest

- name: Install dependencies
run: bun install --frozen-lockfile

- name: audit
run: bun audit --audit-level high

typecheck:
name: TypeScript
runs-on: ubuntu-latest
defaults:
run:
working-directory: lynx/dashboard/ui
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
with:
Expand All @@ -43,7 +62,7 @@ jobs:
run:
working-directory: lynx/dashboard/ui
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
with:
Expand All @@ -62,7 +81,7 @@ jobs:
run:
working-directory: lynx/dashboard/ui
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
with:
Expand All @@ -86,7 +105,7 @@ jobs:
BACKEND_URL: http://localhost:8080

- name: Upload Playwright report
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: failure()
with:
name: playwright-report
Expand Down
4 changes: 1 addition & 3 deletions .github/workflows/lint-shell.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,6 @@ on:
pull_request:
branches:
- main
paths:
- "**.sh"

permissions:
contents: read
Expand All @@ -21,7 +19,7 @@ jobs:
name: shellcheck
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- name: Run shellcheck
run: bash scripts/lint.sh
Loading
Loading