Compare commits
5 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
c090320e47
|
|||
|
c7a07f8327
|
|||
| 31f91fcd28 | |||
|
5268e5834b
|
|||
|
532cc68fb3
|
@@ -22,8 +22,15 @@ jobs:
|
|||||||
- name: Run pre-commit hooks
|
- name: Run pre-commit hooks
|
||||||
run: pre-commit run --all-files --color always
|
run: pre-commit run --all-files --color always
|
||||||
|
|
||||||
|
- name: Install Poetry
|
||||||
|
run: |
|
||||||
|
pip install poetry
|
||||||
|
poetry self add poetry-plugin-export
|
||||||
|
|
||||||
- name: Install pip-audit
|
- name: Install pip-audit
|
||||||
run: pip install pip-audit
|
run: pip install pip-audit
|
||||||
|
|
||||||
- name: Run pip-audit
|
- name: Audit dependencies (Poetry lockfile)
|
||||||
run: pip-audit
|
run: |
|
||||||
|
poetry export -f requirements.txt --without-hashes \
|
||||||
|
| pip-audit -r /dev/stdin
|
||||||
|
|||||||
61
.gitea/workflows/trivy-scan.yml
Normal file
61
.gitea/workflows/trivy-scan.yml
Normal file
@@ -0,0 +1,61 @@
|
|||||||
|
---
|
||||||
|
name: Trivy Scan
|
||||||
|
on:
|
||||||
|
schedule:
|
||||||
|
- cron: 17 8 * * *
|
||||||
|
workflow_dispatch:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
security-scan:
|
||||||
|
runs-on: running-man
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Trivy scan via Docker
|
||||||
|
id: trivy
|
||||||
|
continue-on-error: true
|
||||||
|
run: |
|
||||||
|
docker run --rm \
|
||||||
|
--volumes-from "$HOSTNAME" \
|
||||||
|
aquasec/trivy:latest \
|
||||||
|
fs /workspace/guardutils/filedust \
|
||||||
|
--scanners vuln \
|
||||||
|
--pkg-types library \
|
||||||
|
--include-dev-deps \
|
||||||
|
--severity MEDIUM,HIGH,CRITICAL \
|
||||||
|
--ignore-unfixed \
|
||||||
|
--format json \
|
||||||
|
--output /workspace/guardutils/filedust/trivy.json \
|
||||||
|
--exit-code 1
|
||||||
|
|
||||||
|
- name: Notify Node-RED on vulnerabilities
|
||||||
|
if: steps.trivy.outcome == 'failure'
|
||||||
|
run: |
|
||||||
|
jq -r '
|
||||||
|
{
|
||||||
|
repo: "guardutils/filedust",
|
||||||
|
summary: (
|
||||||
|
"Total: " +
|
||||||
|
((.Results[].Vulnerabilities | length) | tostring)
|
||||||
|
),
|
||||||
|
vulnerabilities: [
|
||||||
|
.Results[].Vulnerabilities[] | {
|
||||||
|
library: .PkgName,
|
||||||
|
cve: .VulnerabilityID,
|
||||||
|
severity: .Severity,
|
||||||
|
installed: .InstalledVersion,
|
||||||
|
fixed: .FixedVersion,
|
||||||
|
title: .Title,
|
||||||
|
url: .PrimaryURL
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
' trivy.json \
|
||||||
|
| curl -s -X POST https://nodered.sysmd.uk/trivy-alert \
|
||||||
|
-H "Content-Type: application/json" \
|
||||||
|
--data-binary @-
|
||||||
|
|
||||||
|
- name: Fail workflow if vulnerabilities found
|
||||||
|
if: steps.trivy.outcome == 'failure'
|
||||||
|
run: exit 1
|
||||||
@@ -4,6 +4,10 @@
|
|||||||
|
|
||||||
# filedust
|
# filedust
|
||||||
|
|
||||||
|
<div align="center">
|
||||||
|
<img src="filedust.png" alt="filedust logo" width="256" />
|
||||||
|
</div>
|
||||||
|
|
||||||
**filedust** is a small, fast, and safe command-line tool that scans your filesystem for obvious junk — things like Python __pycache__ folders, build artifacts, editor backup files, and leftover temporary files — and cleans them up.
|
**filedust** is a small, fast, and safe command-line tool that scans your filesystem for obvious junk — things like Python __pycache__ folders, build artifacts, editor backup files, and leftover temporary files — and cleans them up.
|
||||||
|
|
||||||
Think of it as “`autoremove` for files.”
|
Think of it as “`autoremove` for files.”
|
||||||
|
|||||||
BIN
filedust.png
Normal file
BIN
filedust.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 35 KiB |
14
poetry.lock
generated
14
poetry.lock
generated
@@ -173,13 +173,13 @@ test = ["pytest (>=6)"]
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "filelock"
|
name = "filelock"
|
||||||
version = "3.20.0"
|
version = "3.20.3"
|
||||||
description = "A platform independent file lock."
|
description = "A platform independent file lock."
|
||||||
optional = false
|
optional = false
|
||||||
python-versions = ">=3.10"
|
python-versions = ">=3.10"
|
||||||
files = [
|
files = [
|
||||||
{file = "filelock-3.20.0-py3-none-any.whl", hash = "sha256:339b4732ffda5cd79b13f4e2711a31b0365ce445d95d243bb996273d072546a2"},
|
{file = "filelock-3.20.3-py3-none-any.whl", hash = "sha256:4b0dda527ee31078689fc205ec4f1c1bf7d56cf88b6dc9426c4f230e46c2dce1"},
|
||||||
{file = "filelock-3.20.0.tar.gz", hash = "sha256:711e943b4ec6be42e1d4e6690b48dc175c822967466bb31c0c293f34334c13f4"},
|
{file = "filelock-3.20.3.tar.gz", hash = "sha256:18c57ee915c7ec61cff0ecf7f0f869936c7c30191bb0cf406f1341778d0834e1"},
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -533,18 +533,18 @@ files = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "virtualenv"
|
name = "virtualenv"
|
||||||
version = "20.35.4"
|
version = "20.36.1"
|
||||||
description = "Virtual Python Environment builder"
|
description = "Virtual Python Environment builder"
|
||||||
optional = false
|
optional = false
|
||||||
python-versions = ">=3.8"
|
python-versions = ">=3.8"
|
||||||
files = [
|
files = [
|
||||||
{file = "virtualenv-20.35.4-py3-none-any.whl", hash = "sha256:c21c9cede36c9753eeade68ba7d523529f228a403463376cf821eaae2b650f1b"},
|
{file = "virtualenv-20.36.1-py3-none-any.whl", hash = "sha256:575a8d6b124ef88f6f51d56d656132389f961062a9177016a50e4f507bbcc19f"},
|
||||||
{file = "virtualenv-20.35.4.tar.gz", hash = "sha256:643d3914d73d3eeb0c552cbb12d7e82adf0e504dbf86a3182f8771a153a1971c"},
|
{file = "virtualenv-20.36.1.tar.gz", hash = "sha256:8befb5c81842c641f8ee658481e42641c68b5eab3521d8e092d18320902466ba"},
|
||||||
]
|
]
|
||||||
|
|
||||||
[package.dependencies]
|
[package.dependencies]
|
||||||
distlib = ">=0.3.7,<1"
|
distlib = ">=0.3.7,<1"
|
||||||
filelock = ">=3.12.2,<4"
|
filelock = {version = ">=3.20.1,<4", markers = "python_version >= \"3.10\""}
|
||||||
platformdirs = ">=3.9.1,<5"
|
platformdirs = ">=3.9.1,<5"
|
||||||
typing-extensions = {version = ">=4.13.2", markers = "python_version < \"3.11\""}
|
typing-extensions = {version = ">=4.13.2", markers = "python_version < \"3.11\""}
|
||||||
|
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
[tool.poetry]
|
[tool.poetry]
|
||||||
name = "filedust"
|
name = "filedust"
|
||||||
version = "0.4.0"
|
version = "0.4.1"
|
||||||
description = "Opinionated junk cleaner for dev machines (caches, build artifacts, editor backups)."
|
description = "Opinionated junk cleaner for dev machines (caches, build artifacts, editor backups)."
|
||||||
authors = ["Marco D'Aleo <marco@marcodaleo.com>"]
|
authors = ["Marco D'Aleo <marco@marcodaleo.com>"]
|
||||||
license = "GPL-3.0-or-later"
|
license = "GPL-3.0-or-later"
|
||||||
|
|||||||
Reference in New Issue
Block a user