ci: add Renovate for automated dependency updates #12

Merged
james merged 2 commits from ci/add-renovate into main 2026-09-06 18:21:56 +00:00
Owner

Summary

Adds a scheduled Forgejo Actions workflow that runs Renovate against this repo, pointed at Forgejo natively (RENOVATE_PLATFORM=forgejo).

  • renovate.json extends config:recommended � Renovate auto-detects go.mod and web/package.json, no further config needed to start.
  • .forgejo/workflows/renovate.yml runs npx renovate daily (plus manual workflow_dispatch), matching this repo's existing CI conventions (actions/checkout@v4, actions/setup-node@v4).

Before merging

A RENOVATE_TOKEN repo secret needs to be added (Settings ? Actions ? Secrets): a personal API token for a bot/user account with push + PR rights on this repo. Without it the workflow will run but fail to open PRs.

## Summary Adds a scheduled Forgejo Actions workflow that runs Renovate against this repo, pointed at Forgejo natively (`RENOVATE_PLATFORM=forgejo`). - `renovate.json` extends `config:recommended` � Renovate auto-detects `go.mod` and `web/package.json`, no further config needed to start. - `.forgejo/workflows/renovate.yml` runs `npx renovate` daily (plus manual `workflow_dispatch`), matching this repo's existing CI conventions (`actions/checkout@v4`, `actions/setup-node@v4`). ## Before merging A `RENOVATE_TOKEN` repo secret needs to be added (Settings ? Actions ? Secrets): a personal API token for a bot/user account with push + PR rights on this repo. Without it the workflow will run but fail to open PRs.
ci: add Renovate for automated dependency updates
All checks were successful
security-scan / scan (pull_request) Successful in 24s
test / go (pull_request) Successful in 2m42s
test / web (pull_request) Successful in 2m15s
110b9980d8
Scheduled Forgejo Actions workflow runs Renovate's CLI directly via npx
against this Forgejo instance (RENOVATE_PLATFORM=forgejo), daily plus
manual dispatch. renovate.json extends config:recommended as a starting
point — Renovate auto-detects go.mod and web/package.json.

Requires a RENOVATE_TOKEN repo secret (a personal API token with push/PR
rights) to be added before this can open PRs.

🔎 ojo scan results

Severity Count
🟠 HIGH 13
🟡 MEDIUM 7
🟢 LOW 5
⚪ UNKNOWN 5
Details (30)
Type Severity ID/Rule Location Description
vuln 🟠 HIGH CVE-2026-33487 github.com/russellhaering/[email protected] validateSignature Loop Variable Capture Signature Bypass in goxmldsig
vuln 🟠 HIGH CVE-2026-73088 [email protected] Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
vuln 🟠 HIGH CVE-2026-73089 [email protected] Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM
vuln 🟠 HIGH CVE-2026-67213 [email protected] nanoid: custom generators can loop indefinitely when size is zero
secret 🟠 HIGH db-connection-string README.md:28 Database connection string with embedded password detected
secret 🟠 HIGH db-connection-string deploy/docker/docker-compose.yml:29 Database connection string with embedded password detected
secret 🟠 HIGH db-connection-string deploy/k8s/00-namespace-config.yaml:17 Database connection string with embedded password detected
sast 🟠 HIGH go-ssrf internal/auth/saml_test.go:325 http.Get URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL
sast 🟠 HIGH go-ssrf internal/integrations/jira.go:43 http.NewRequestWithContext URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL
sast 🟠 HIGH go-ssrf internal/integrations/jira.go:73 http.NewRequestWithContext URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL
sast 🟠 HIGH js-ssrf web/src/lib/api.ts:39 fetch(...) URL argument is derived from request/env input (directly, or through a local variable) or built via template-literal interpolation/concatenation rather than a validated/allowlisted URL
sast 🟠 HIGH js-ssrf web/src/lib/api.ts:64 fetch(...) URL argument is derived from request/env input (directly, or through a local variable) or built via template-literal interpolation/concatenation rather than a validated/allowlisted URL
sast 🟠 HIGH js-ssrf web/src/lib/api.ts:95 fetch(...) URL argument is derived from request/env input (directly, or through a local variable) or built via template-literal interpolation/concatenation rather than a validated/allowlisted URL
misconfig 🟡 MEDIUM k8s-run-as-root deploy/k8s/10-postgres.yaml:1 container postgres
misconfig 🟡 MEDIUM k8s-run-as-root deploy/k8s/20-api.yaml:1 container api
misconfig 🟡 MEDIUM k8s-run-as-root deploy/k8s/30-web.yaml:1 container web
sast 🟡 MEDIUM go-open-redirect internal/api/handlers/oidc_handler.go:50 http.Redirect target is derived from request input (directly or through a local variable) or built via Sprintf/concatenation rather than a literal/allowlisted URL
sast 🟡 MEDIUM go-open-redirect internal/api/handlers/oidc_handler.go:99 http.Redirect target is derived from request input (directly or through a local variable) or built via Sprintf/concatenation rather than a literal/allowlisted URL
sast 🟡 MEDIUM go-open-redirect internal/api/handlers/saml_handler.go:54 http.Redirect target is derived from request input (directly or through a local variable) or built via Sprintf/concatenation rather than a literal/allowlisted URL
sast 🟡 MEDIUM go-open-redirect internal/api/handlers/saml_handler.go:95 http.Redirect target is derived from request input (directly or through a local variable) or built via Sprintf/concatenation rather than a literal/allowlisted URL
misconfig 🟢 LOW dockerfile-no-healthcheck deploy/docker/Dockerfile:1 image has no HEALTHCHECK
misconfig 🟢 LOW dockerfile-no-healthcheck deploy/docker/Dockerfile.web:1 image has no HEALTHCHECK
misconfig 🟢 LOW k8s-missing-resource-limits deploy/k8s/10-postgres.yaml:1 container postgres can consume unbounded CPU/memory
sast 🟢 LOW go-cookie-missing-flags internal/api/handlers/auth_handlers.go:42 http.Cookie{...} doesn't set Secure; it defaults to false, weakening cookie protection unless set elsewhere
sast 🟢 LOW go-cookie-missing-flags internal/api/handlers/auth_handlers.go:52 http.Cookie{...} doesn't set Secure; it defaults to false, weakening cookie protection unless set elsewhere
vuln ⚪ UNKNOWN GO-2026-5932 golang.org/x/[email protected] The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
vuln ⚪ UNKNOWN CVE-2026-56854 golang.org/x/[email protected] Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh
vuln ⚪ UNKNOWN CVE-2026-78662 golang.org/x/[email protected] Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
vuln ⚪ UNKNOWN CVE-2026-56855 golang.org/x/[email protected] Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
vuln ⚪ UNKNOWN CVE-2026-56852 golang.org/x/[email protected] Infinite loop on invalid input in golang.org/x/text
<!-- ojo-scan-summary --> ### 🔎 ojo scan results | Severity | Count | |---|---| | 🟠 HIGH | 13 | | 🟡 MEDIUM | 7 | | 🟢 LOW | 5 | | ⚪ UNKNOWN | 5 | <details><summary>Details (30)</summary> | Type | Severity | ID/Rule | Location | Description | |---|---|---|---|---| | vuln | 🟠 HIGH | <a href="https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-479m-364c-43vc" target="_blank" rel="noopener noreferrer">CVE-2026-33487</a> | github.com/russellhaering/[email protected] | validateSignature Loop Variable Capture Signature Bypass in goxmldsig | | vuln | 🟠 HIGH | <a href="https://github.com/browserslist/browserslist/security/advisories/GHSA-73wf-gq98-2v4g" target="_blank" rel="noopener noreferrer">CVE-2026-73088</a> | [email protected] | Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) | | vuln | 🟠 HIGH | <a href="https://github.com/browserslist/browserslist/security/advisories/GHSA-c83g-rgw3-j3cx" target="_blank" rel="noopener noreferrer">CVE-2026-73089</a> | [email protected] | Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM | | vuln | 🟠 HIGH | <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-67213" target="_blank" rel="noopener noreferrer">CVE-2026-67213</a> | [email protected] | nanoid: custom generators can loop indefinitely when size is zero | | secret | 🟠 HIGH | db-connection-string | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/README.md#L28" target="_blank" rel="noopener noreferrer">README.md:28</a> | Database connection string with embedded password detected | | secret | 🟠 HIGH | db-connection-string | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/deploy/docker/docker-compose.yml#L29" target="_blank" rel="noopener noreferrer">deploy/docker/docker-compose.yml:29</a> | Database connection string with embedded password detected | | secret | 🟠 HIGH | db-connection-string | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/deploy/k8s/00-namespace-config.yaml#L17" target="_blank" rel="noopener noreferrer">deploy/k8s/00-namespace-config.yaml:17</a> | Database connection string with embedded password detected | | sast | 🟠 HIGH | go-ssrf | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/internal/auth/saml_test.go#L325" target="_blank" rel="noopener noreferrer">internal/auth/saml_test.go:325</a> | http.Get URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL | | sast | 🟠 HIGH | go-ssrf | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/internal/integrations/jira.go#L43" target="_blank" rel="noopener noreferrer">internal/integrations/jira.go:43</a> | http.NewRequestWithContext URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL | | sast | 🟠 HIGH | go-ssrf | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/internal/integrations/jira.go#L73" target="_blank" rel="noopener noreferrer">internal/integrations/jira.go:73</a> | http.NewRequestWithContext URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL | | sast | 🟠 HIGH | js-ssrf | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/web/src/lib/api.ts#L39" target="_blank" rel="noopener noreferrer">web/src/lib/api.ts:39</a> | fetch(...) URL argument is derived from request/env input (directly, or through a local variable) or built via template-literal interpolation/concatenation rather than a validated/allowlisted URL | | sast | 🟠 HIGH | js-ssrf | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/web/src/lib/api.ts#L64" target="_blank" rel="noopener noreferrer">web/src/lib/api.ts:64</a> | fetch(...) URL argument is derived from request/env input (directly, or through a local variable) or built via template-literal interpolation/concatenation rather than a validated/allowlisted URL | | sast | 🟠 HIGH | js-ssrf | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/web/src/lib/api.ts#L95" target="_blank" rel="noopener noreferrer">web/src/lib/api.ts:95</a> | fetch(...) URL argument is derived from request/env input (directly, or through a local variable) or built via template-literal interpolation/concatenation rather than a validated/allowlisted URL | | misconfig | 🟡 MEDIUM | k8s-run-as-root | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/deploy/k8s/10-postgres.yaml#L1" target="_blank" rel="noopener noreferrer">deploy/k8s/10-postgres.yaml:1</a> | container postgres | | misconfig | 🟡 MEDIUM | k8s-run-as-root | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/deploy/k8s/20-api.yaml#L1" target="_blank" rel="noopener noreferrer">deploy/k8s/20-api.yaml:1</a> | container api | | misconfig | 🟡 MEDIUM | k8s-run-as-root | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/deploy/k8s/30-web.yaml#L1" target="_blank" rel="noopener noreferrer">deploy/k8s/30-web.yaml:1</a> | container web | | sast | 🟡 MEDIUM | go-open-redirect | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/internal/api/handlers/oidc_handler.go#L50" target="_blank" rel="noopener noreferrer">internal/api/handlers/oidc_handler.go:50</a> | http.Redirect target is derived from request input (directly or through a local variable) or built via Sprintf/concatenation rather than a literal/allowlisted URL | | sast | 🟡 MEDIUM | go-open-redirect | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/internal/api/handlers/oidc_handler.go#L99" target="_blank" rel="noopener noreferrer">internal/api/handlers/oidc_handler.go:99</a> | http.Redirect target is derived from request input (directly or through a local variable) or built via Sprintf/concatenation rather than a literal/allowlisted URL | | sast | 🟡 MEDIUM | go-open-redirect | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/internal/api/handlers/saml_handler.go#L54" target="_blank" rel="noopener noreferrer">internal/api/handlers/saml_handler.go:54</a> | http.Redirect target is derived from request input (directly or through a local variable) or built via Sprintf/concatenation rather than a literal/allowlisted URL | | sast | 🟡 MEDIUM | go-open-redirect | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/internal/api/handlers/saml_handler.go#L95" target="_blank" rel="noopener noreferrer">internal/api/handlers/saml_handler.go:95</a> | http.Redirect target is derived from request input (directly or through a local variable) or built via Sprintf/concatenation rather than a literal/allowlisted URL | | misconfig | 🟢 LOW | dockerfile-no-healthcheck | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/deploy/docker/Dockerfile#L1" target="_blank" rel="noopener noreferrer">deploy/docker/Dockerfile:1</a> | image has no HEALTHCHECK | | misconfig | 🟢 LOW | dockerfile-no-healthcheck | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/deploy/docker/Dockerfile.web#L1" target="_blank" rel="noopener noreferrer">deploy/docker/Dockerfile.web:1</a> | image has no HEALTHCHECK | | misconfig | 🟢 LOW | k8s-missing-resource-limits | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/deploy/k8s/10-postgres.yaml#L1" target="_blank" rel="noopener noreferrer">deploy/k8s/10-postgres.yaml:1</a> | container postgres can consume unbounded CPU/memory | | sast | 🟢 LOW | go-cookie-missing-flags | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/internal/api/handlers/auth_handlers.go#L42" target="_blank" rel="noopener noreferrer">internal/api/handlers/auth_handlers.go:42</a> | http.Cookie{...} doesn't set Secure; it defaults to false, weakening cookie protection unless set elsewhere | | sast | 🟢 LOW | go-cookie-missing-flags | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/481e025e987d892342cd434776fa32c53cfe5126/internal/api/handlers/auth_handlers.go#L52" target="_blank" rel="noopener noreferrer">internal/api/handlers/auth_handlers.go:52</a> | http.Cookie{...} doesn't set Secure; it defaults to false, weakening cookie protection unless set elsewhere | | vuln | ⚪ UNKNOWN | <a href="https://go.dev/issue/44226" target="_blank" rel="noopener noreferrer">GO-2026-5932</a> | golang.org/x/[email protected] | The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues | | vuln | ⚪ UNKNOWN | <a href="https://go.dev/issue/80213" target="_blank" rel="noopener noreferrer">CVE-2026-56854</a> | golang.org/x/[email protected] | Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh | | vuln | ⚪ UNKNOWN | <a href="https://go.dev/issue/81316" target="_blank" rel="noopener noreferrer">CVE-2026-78662</a> | golang.org/x/[email protected] | Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh | | vuln | ⚪ UNKNOWN | <a href="https://go.dev/issue/81317" target="_blank" rel="noopener noreferrer">CVE-2026-56855</a> | golang.org/x/[email protected] | Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh | | vuln | ⚪ UNKNOWN | <a href="https://go.dev/issue/80142" target="_blank" rel="noopener noreferrer">CVE-2026-56852</a> | golang.org/x/[email protected] | Infinite loop on invalid input in golang.org/x/text | </details>
james force-pushed ci/add-renovate from 110b9980d8
All checks were successful
security-scan / scan (pull_request) Successful in 24s
test / go (pull_request) Successful in 2m42s
test / web (pull_request) Successful in 2m15s
to fdd79ccf5a
All checks were successful
security-scan / scan (pull_request) Successful in 34s
test / web (pull_request) Successful in 1m20s
test / go (pull_request) Successful in 2m37s
2026-09-06 17:44:07 +00:00
Compare
james force-pushed ci/add-renovate from fdd79ccf5a
All checks were successful
security-scan / scan (pull_request) Successful in 34s
test / web (pull_request) Successful in 1m20s
test / go (pull_request) Successful in 2m37s
to e70a5de87f
All checks were successful
security-scan / scan (pull_request) Successful in 24s
test / web (pull_request) Successful in 1m13s
test / go (pull_request) Successful in 1m26s
2026-09-06 17:55:52 +00:00
Compare
Update .forgejo/workflows/renovate.yml
All checks were successful
security-scan / scan (pull_request) Successful in 24s
test / go (pull_request) Successful in 1m13s
test / web (pull_request) Successful in 58s
481e025e98
Move from branch tag to sha hash tag
james force-pushed ci/add-renovate from 481e025e98
All checks were successful
security-scan / scan (pull_request) Successful in 24s
test / go (pull_request) Successful in 1m13s
test / web (pull_request) Successful in 58s
to 81a1d1c32a
All checks were successful
security-scan / scan-1 (pull_request) Successful in 25s
security-scan / scan (pull_request) Successful in 0s
test / web (pull_request) Successful in 1m17s
test / go (pull_request) Successful in 2m47s
2026-09-06 18:20:44 +00:00
Compare
james merged commit 897642d8ef into main 2026-09-06 18:21:56 +00:00
james deleted branch ci/add-renovate 2026-09-06 18:21:57 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ColibriSec/balam!12
No description provided.