Commit Graph
222 Commits
Author SHA1 Message Date
andrew 8b9f4819d6 Merge pull request 'feat(gitea): enforce pre-receive hook in secure-gitea.py' (#1) from feat/pre-receive-hook into main
Sync GitHub / sync (push) Successful in 8s
Reviewed-on: #1
Reviewed-by: Andrew <andrew@digitaladapt.com>
2026-08-26 10:02:05 -04:00
lyra a56d97d13d fix(gitea): handle disabled git hooks gracefully in secure-gitea.py
Sync GitHub / sync (push) Successful in 7s
Previously, when Gitea is installed with DISABLE_GIT_HOOKS=true (the
default), every git-hook API call returned 403 and the script:
- marked every repository as FAILED, and
- never counted the hook step at all.

This change detects the disabled state up front with a single probe
against the first editable repo:
- If hooks are disabled, it prints a clear notice, skips the pre-receive
  step for every repo (branch/tag protection still runs normally), and
  exits non-zero (2) so automation notices the run is partial.
- A per-repo 403 on the hook step is isolated (HookNotWritable) so it no
  longer clobbers the whole repo into FAILED -- branch/tag still apply,
  and the hook reports 'SKIPPED (git hooks not writable)'.
- Adds a Hooks skipped counter and distinguishes 'disabled' vs
  'not writable' in the summary.
- Fixes an UnboundLocalError on the 'no editable repos' path by
  initializing hooks_enabled before the probe.

Verified end-to-end against a mock Gitea API for both scenarios (hooks
disabled -> skip + exit 2; hooks enabled -> exact/stale/missing handled
correctly, exit 0).
2026-08-26 05:18:53 -04:00
lyra 9415ded220 feat(gitea): enforce pre-receive hook in secure-gitea.py
Sync GitHub / sync (push) Successful in 7s
Adds pre-receive hook management to the existing hardening script:

- Defines GIT_HOOKS with the canonical guard content (rejects workflow
  changes arriving via untrusted branches) from pre-receive-guard.sh.
- Reads the current hook via the git-hook API; treats is_active=false
  as not set.
- Sets/updates the hook via PATCH only when the content differs, using
  exact-match comparison (Gitea stores hook content verbatim).
- Mirrors the existing branch/tag protection reporting (dry-run vs
  --apply) and adds hooks to the summary counters.
- Skips archived repos and surfaces API failures like the rest of the
  script.
2026-08-26 04:12:39 -04:00
andrew 860b2346c6 added tag protection, also fixed so it will properly detect when no change is needed.
Sync GitHub / sync (push) Successful in 9s
2026-08-20 08:50:31 -04:00
andrew e7366188ac new script to enforce gitea branch protection
Sync GitHub / sync (push) Successful in 7s
2026-08-19 10:36:35 -04:00
andrew dfd12a10cb fixed docker pull
Sync GitHub / sync (push) Successful in 7s
2026-07-25 22:43:19 -04:00
andrew 09dffc3933 new docker scripts, pull and heal.
Sync GitHub / sync (push) Successful in 40s
2026-07-24 23:43:31 -04:00
andrew aa0da565e1 setting up automatic sync from Gitea to GitHub
Sync GitHub / sync (push) Successful in 9s
2026-06-14 11:05:28 -04:00
andrew 32ecd70065 added tailscale notes 2026-02-16 16:04:40 -05:00
andrew 0f5d677e32 Merge branch 'debian-gittree' into debian 2026-02-10 15:00:16 -05:00
andrew f55bb1ec93 added date and author to gittree 2026-02-10 14:59:25 -05:00
andrew 9bc52dcb8a switching to neovim and fixing git-passthru setup 2026-01-29 14:21:52 -05:00
andrew 2708ab61cb minor update to git-prompt 2025-12-07 18:37:50 -05:00
andrew e4556f4843 Merge commit 'af2e9d27dfe18a95554879982b11e2f6c421b4b8' into debian 2025-12-07 18:15:02 -05:00
andrew af2e9d27df Squashed 'nodesource/' changes from ba48c1f..33e0d2a
33e0d2a CI: add NSOLID to the CI tests
a9dab9a CI: add NSOLID to the CI tests
b84e562 Update scripts to support new NSOLID version
7925aa5 Add node25 scripts
612077e Merge pull request #1890 from nodesource/alejo/fix-distributions
2e44c74 ci(rocky): use official Rocky mirrorlist and tolerate unavailable mirrors
904ee90 fix: update apt 3.0.0 (amd64) [#1874] (#1875)
044f89b doc: update docs

git-subtree-dir: nodesource
git-subtree-split: 33e0d2ac2a5421d45bfd9b9fdf04c1fcab35246b
2025-12-07 18:15:02 -05:00
andrew ad8795066b Merge commit '08e062efb44cbf8230a1766b15190f25bef8fb99' into debian 2025-12-07 18:10:58 -05:00
andrew 08e062efb4 Squashed 'golang-install/' changes from 2bb9d3b..f252ea6
f252ea6 Revise OS compatibility section in README
90d4f7a Fix download URL and add auto-detection of latest Go version (#75)
a9cb3b4 Update to Go 1.24.4 (#74)

git-subtree-dir: golang-install
git-subtree-split: f252ea6773ae636e82f60a147111029c4defdc63
2025-12-07 18:10:58 -05:00
andrew 3bb533387d new docker logs script, which shows logs of all running containers 2025-12-06 10:59:44 -05:00
andrew 17b96c7cc6 made name follow convention 2025-11-18 22:18:19 -05:00
andrew d554eefbb3 simplified command to get assigned ip 2025-11-18 22:05:01 -05:00
andrew 5cdf94bfd3 new script for getting network assigned ip address 2025-11-18 21:44:33 -05:00
andrew 32ab993279 updated thermal cron scripts to format output better 2025-11-11 12:51:33 -05:00
andrew 6ec7af0723 would help to define a variable before trying to use it 2025-11-07 15:52:38 -05:00
andrew c42108dc97 sync keys now uses ntfy 2025-11-07 10:42:51 -08:00
andrew a187e446d0 updated storage and thermal crons to work with ntfy, and fixed thermal to not give errors when there is no thermal data to work with 2025-11-07 06:55:09 -08:00
andrew fcdc73edbb minor updates to example config 2025-11-06 12:54:47 -08:00
andrew 8ad77bdfb5 added btop 2025-11-05 17:20:38 -08:00
andrew dd70962060 added option to setup to install ntfy.sh client 2025-11-05 15:56:37 -08:00
andrew 5245484a3c cloudflare script to give more meaningful response when creating records, and automatically including bin folders within host folder 2025-10-24 15:41:53 -04:00
andrew 00f8f3aaca added mosh to extra utilities 2025-10-15 10:24:12 -04:00
andrew 35a5bd34e8 added support for cloudflare script to create missing record 2025-10-14 13:56:59 -04:00
andrew 332889e34c new setup script to enable git ssh passthru to a docker container like gitea. 2025-10-08 10:43:19 -04:00
andrew c550d44750 offer to make docker network 2025-10-06 18:43:49 -04:00
andrew b16881ff32 update to example config 2025-09-21 20:49:23 -04:00
andrew dde20ecf81 Merge remote-tracking branch 'origin/debian' into debian 2025-09-21 20:14:54 -04:00
andrew b3d69e6dac new script to sync ssh keys from a Gitea instance. 2025-09-21 20:10:32 -04:00
andrew 541a4ad323 within setup config script, need to specify files to copy, instead of using star. 2025-09-03 07:50:31 -04:00
andrew 29d22a1024 ascii-image-converter, along with alias "show" to setup scripts. 2025-08-28 16:31:00 -04:00
andrew d1839e9adc ignore branch name if it matches hostname 2025-07-23 10:47:04 -04:00
andrew 254fa04f43 discord alert hook added, made alert crons use it 2025-07-11 09:27:28 -04:00
andrew 6180c88fab storage.sh will now default to showing root drive info 2025-07-03 14:55:08 -04:00
andrew 77a64169b5 storage-alert updated to only messaging when limits are reached. 2025-07-03 13:24:01 -04:00
andrew fa88d6f2b4 php-curl is very important, to pair with php-cli 2025-06-04 15:32:30 -04:00
andrew 0e88a55e56 use editorconfig via plugin instead of apt 2025-05-22 16:08:28 -04:00
andrew 7b1b3aeb3d update vim config, a few colorschemes to choose from 2025-05-22 15:55:29 -04:00
andrew 8be3c74003 only offer to setup docker group if docker is installed 2025-05-21 09:06:22 -04:00
andrew 988734e769 added xcaddy go package 2025-05-20 22:15:06 -04:00
andrew be02666464 discord.sh now displays to console as well by default, and a lot of cleanup 2025-05-16 13:12:29 -04:00
andrew b45bd31954 only try to install prerequisites when missing, only offer node packages, if node installed 2025-05-15 10:53:04 -04:00
andrew 1f800151e5 added notes 2025-05-15 09:52:03 -04:00