Clean main branch - #134
Open
juanma1996 wants to merge 188 commits into
Open
juanma1996 wants to merge 188 commits into
juanma1996 wants to merge 188 commits into
Conversation
Bumps [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) from 6 to 7. - [Release notes](https://github.com/oxsecurity/megalinter/releases) - [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md) - [Commits](oxsecurity/megalinter@v6...v7) --- updated-dependencies: - dependency-name: oxsecurity/megalinter dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 3 to 4. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v3...v4) --- updated-dependencies: - dependency-name: actions/checkout dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [google-github-actions/release-please-action](https://github.com/google-github-actions/release-please-action) from 3 to 4. - [Release notes](https://github.com/google-github-actions/release-please-action/releases) - [Changelog](https://github.com/google-github-actions/release-please-action/blob/main/CHANGELOG.md) - [Commits](google-github-actions/release-please-action@v3...v4) --- updated-dependencies: - dependency-name: google-github-actions/release-please-action dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [stefanzweifel/git-auto-commit-action](https://github.com/stefanzweifel/git-auto-commit-action) from 4 to 5. - [Release notes](https://github.com/stefanzweifel/git-auto-commit-action/releases) - [Changelog](https://github.com/stefanzweifel/git-auto-commit-action/blob/master/CHANGELOG.md) - [Commits](stefanzweifel/git-auto-commit-action@v4...v5) --- updated-dependencies: - dependency-name: stefanzweifel/git-auto-commit-action dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@substrate/connect](https://github.com/paritytech/substrate-connect) from 0.7.35 to 0.8.1. - [Changelog](https://github.com/paritytech/substrate-connect/blob/main/DEPLOY-RELEASE.md) - [Commits](https://github.com/paritytech/substrate-connect/commits) --- updated-dependencies: - dependency-name: "@substrate/connect" dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@fortawesome/fontawesome-svg-core](https://github.com/FortAwesome/Font-Awesome) from 6.4.2 to 6.5.1. - [Release notes](https://github.com/FortAwesome/Font-Awesome/releases) - [Changelog](https://github.com/FortAwesome/Font-Awesome/blob/6.x/CHANGELOG.md) - [Commits](FortAwesome/Font-Awesome@6.4.2...6.5.1) --- updated-dependencies: - dependency-name: "@fortawesome/fontawesome-svg-core" dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [eslint-config-prettier](https://github.com/prettier/eslint-config-prettier) from 9.0.0 to 9.1.0. - [Changelog](https://github.com/prettier/eslint-config-prettier/blob/main/CHANGELOG.md) - [Commits](prettier/eslint-config-prettier@v9.0.0...v9.1.0) --- updated-dependencies: - dependency-name: eslint-config-prettier dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) from 6.12.0 to 6.13.1. - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v6.13.1/packages/eslint-plugin) --- updated-dependencies: - dependency-name: "@typescript-eslint/eslint-plugin" dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [eslint](https://github.com/eslint/eslint) from 8.54.0 to 8.55.0. - [Release notes](https://github.com/eslint/eslint/releases) - [Changelog](https://github.com/eslint/eslint/blob/main/CHANGELOG.md) - [Commits](eslint/eslint@v8.54.0...v8.55.0) --- updated-dependencies: - dependency-name: eslint dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [rc-slider](https://github.com/react-component/slider) from 10.4.0 to 10.5.0. - [Release notes](https://github.com/react-component/slider/releases) - [Changelog](https://github.com/react-component/slider/blob/master/CHANGELOG.md) - [Commits](react-component/slider@v10.4.0...v10.5.0) --- updated-dependencies: - dependency-name: rc-slider dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@fortawesome/free-brands-svg-icons](https://github.com/FortAwesome/Font-Awesome) from 6.4.2 to 6.5.1. - [Release notes](https://github.com/FortAwesome/Font-Awesome/releases) - [Changelog](https://github.com/FortAwesome/Font-Awesome/blob/6.x/CHANGELOG.md) - [Commits](FortAwesome/Font-Awesome@6.4.2...6.5.1) --- updated-dependencies: - dependency-name: "@fortawesome/free-brands-svg-icons" dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) from 6.12.0 to 6.13.1. - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v6.13.1/packages/parser) --- updated-dependencies: - dependency-name: "@typescript-eslint/parser" dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@ledgerhq/logs](https://github.com/LedgerHQ/ledger-live) from 6.11.0 to 6.12.0. - [Release notes](https://github.com/LedgerHQ/ledger-live/releases) - [Commits](https://github.com/LedgerHQ/ledger-live/compare/@ledgerhq/logs@6.11.0...@ledgerhq/logs@6.12.0) --- updated-dependencies: - dependency-name: "@ledgerhq/logs" dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@polkadot/util-crypto](https://github.com/polkadot-js/common/tree/HEAD/packages/util-crypto) from 12.5.1 to 12.6.1. - [Release notes](https://github.com/polkadot-js/common/releases) - [Changelog](https://github.com/polkadot-js/common/blob/master/CHANGELOG.md) - [Commits](https://github.com/polkadot-js/common/commits/v12.6.1/packages/util-crypto) --- updated-dependencies: - dependency-name: "@polkadot/util-crypto" dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@ledgerhq/hw-transport-webhid](https://github.com/LedgerHQ/ledger-live) from 6.27.20 to 6.28.0. - [Release notes](https://github.com/LedgerHQ/ledger-live/releases) - [Commits](https://github.com/LedgerHQ/ledger-live/compare/@ledgerhq/hw-transport-webhid@6.27.20...@ledgerhq/hw-transport-webhid@6.28.0) --- updated-dependencies: - dependency-name: "@ledgerhq/hw-transport-webhid" dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
updates: - [github.com/pre-commit/pre-commit-hooks: v4.4.0 → v4.5.0](pre-commit/pre-commit-hooks@v4.4.0...v4.5.0)
Bumps [@fortawesome/free-solid-svg-icons](https://github.com/FortAwesome/Font-Awesome) from 6.4.2 to 6.5.1. - [Release notes](https://github.com/FortAwesome/Font-Awesome/releases) - [Changelog](https://github.com/FortAwesome/Font-Awesome/blob/6.x/CHANGELOG.md) - [Commits](FortAwesome/Font-Awesome@6.4.2...6.5.1) --- updated-dependencies: - dependency-name: "@fortawesome/free-solid-svg-icons" dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 4.5.0 to 5.0.5. - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v5.0.5/packages/vite) --- updated-dependencies: - dependency-name: vite dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
This reverts commit 8aa2536. Reverting because this instance of Creditcoin Staking Dashboard will be working only with Creditcoin 3 and we don't need the added overhead.
all of them start with `rpc.cc3-`! Note: reset the `subscanEndpoint` value for Testnet because this is still not deployed and we don't know what it is going to be.
This reverts commit 1b629d1. This is a new repository and we don't have the custom branches which we used to have when working inside https://github.com/gluwa/creditcoin-staking-dashboard/
because we're not upstream and we're not going to release npm packages but only Docker containers.
the way `yarn lint` is designed upstream it will automatically apply changes by eslint & reformat the source code but will always exit with zero.
Bumps [@fortawesome/free-regular-svg-icons](https://github.com/FortAwesome/Font-Awesome) from 6.4.2 to 6.5.1. - [Release notes](https://github.com/FortAwesome/Font-Awesome/releases) - [Changelog](https://github.com/FortAwesome/Font-Awesome/blob/6.x/CHANGELOG.md) - [Commits](FortAwesome/Font-Awesome@6.4.2...6.5.1) --- updated-dependencies: - dependency-name: "@fortawesome/free-regular-svg-icons" dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 0.34.6 to 1.0.1. - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Commits](https://github.com/vitest-dev/vitest/commits/v1.0.1/packages/vitest) --- updated-dependencies: - dependency-name: vitest dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…#178) * [SS-1313] Preserve domain notice dismissal state across CC3 migration Prevent domain change notice modal from reappearing after migration reload when user has checked "Do not show again" * [SS-1313] Extract clearLocalStorageExcept utility for better maintainability Consolidate localStorage preservation logic into a reusable helper function to prevent code fragmentation when additional logic is added in the future.
Co-authored-by: Juan Gallicchio <juan.gallicchio@gluwa.com>
Co-authored-by: Juan Gallicchio <juan.gallicchio@gluwa.com>
Co-authored-by: Juan Gallicchio <juan.gallicchio@gluwa.com>
Co-authored-by: Juan Gallicchio <juan.gallicchio@gluwa.com>
) * feat: replace SF Pro fonts with Inter fonts * feat: prepare for domain notice * Apply passed desgin changes to DomainChangeNotice modal * use px instead of rem for consistent spacing * chage varialbe name for storage key * Add external blog link for domain change notice * Add license header to Wrapper.ts * fix InterSemiBold to Inter-SB * Remove unessary transitions in DomainChangeNotice modal * Remove copyright header from DomainChangeNotice modal files * Remove 6-month expiry logic from domain notice hook * [pre-commit.ci] auto fixes from pre-commit.com hooks for more information, see https://pre-commit.ci --------- Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
…#178) * [SS-1313] Preserve domain notice dismissal state across CC3 migration Prevent domain change notice modal from reappearing after migration reload when user has checked "Do not show again" * [SS-1313] Extract clearLocalStorageExcept utility for better maintainability Consolidate localStorage preservation logic into a reusable helper function to prevent code fragmentation when additional logic is added in the future.
Co-authored-by: Juan Gallicchio <juan.gallicchio@gluwa.com>
Co-authored-by: Juan Gallicchio <juan.gallicchio@gluwa.com>
Co-authored-by: Juan Gallicchio <juan.gallicchio@gluwa.com>
Co-authored-by: Juan Gallicchio <juan.gallicchio@gluwa.com>
Master into Dev
…Docker Scout CI/CD - Dockerfile: pin node:24 (was node:21, non-LTS and fully EOL) and nginx:1.30.3-alpine (was 1.25.3-alpine, ~9mo stale) to digests. Verified node:22 vs node:24 produce byte-identical build output before choosing 24 for consistency with creditcoin3/attestor-operator. - Dockerfile: fix non-root (previously explicitly disabled via checkov:skip=CKV_DOCKER_3, ran as root). Keeps port 80 (the Container App's targetPort is hardcoded in staking-dashboard-IAC, so switching ports would need a coordinated infra change) by granting nginx the cap_net_bind_service capability instead. Also relocates the pid file to /tmp (default /run/nginx.pid isn't writable non-root at runtime) and makes /etc/nginx/conf.d writable (needed by the base image's own entrypoint script to add the IPv6 listener — without it nginx ends up IPv4-only and HEALTHCHECK fails, since it resolves localhost to ::1 first). Verified end to end: built, ran, confirmed non-root (uid 101), port 80 responding, HEALTHCHECK healthy. - creditcoin-staking-dashboard-ci.yml: add --sbom=true --provenance=mode=max to both Docker@2 build tasks (SSC attestation). Add an informational, non-blocking docker scout cves step after the builds. Add a new WeeklyScoutReport job (Mon 09:00 EDT schedule) that scans the published :latest image and posts to #noti-docker-scout via the Penguin Patrol webhook, reusing the PenguinPatrol variable group already set up for attestor-operator. AGPL audit (880 yarn packages, all resolved, none AGPL) done but SECURITY.md not committed here — held back for manual review, per user request, same as creditcoin3 and attestor-operator.
Two issues from 5b030e5 broke PR #195's checks: - YAML strings in the new schedules block used double quotes; this repo's Prettier config requires single quotes, failing yarn lint (GH Actions build matrix) and MegaLinter's YAML check. - Docker@2 build steps gained --sbom=true --provenance=mode=max, but Azure Pipelines' hosted agent defaults to the classic docker buildx driver, which doesn't support attestations ("Attestation is not supported for the docker driver"). Adds a step to create and switch to a docker-container builder before the build steps. MegaLinter's other failure (grype: "vulnerability database was built 17 weeks ago") is a stale-DB issue in the linter's own Docker image, unrelated to this PR - not fixed here.
The buildx builder created in the prior step wasn't picked up as the active builder by Docker@2's own docker invocation (it manages its own isolated Docker config for registry auth), so the build still fell back to the classic driver and failed the same way. Passing --builder=attestation-builder explicitly forces it.
--builder=attestation-builder still failed ("no builder found") -
Docker@2 isolates its own DOCKER_CONFIG for registry auth, separate
from the buildx state created in the prior step. Switched the two
build steps to plain script + docker buildx build (which shares the
same context as the buildx-create step); Docker@2 stays for the
push steps since those genuinely need the registry credentials.
--load pulls the result into the local image store so Scout and the
push steps can find it, matching the previous single-arch behavior.
Preserved the conditional $(releaseTag) tag on the prod build.
--load failed too: "docker exporter does not currently support exporting manifest lists" - --sbom/--provenance always produce a manifest list even for one platform, and buildx's docker-exporter (what --load uses) can't load those into the local image store. Pushing straight to the registry with --push is the supported path for attestations. Moved the Docker@2 login step earlier so the plain buildx script steps authenticate against the same default docker context; removed the now-redundant separate Docker@2 push steps since build now pushes directly.
…onger fetch a current vuln DB)
…actionlint: node16 runtimes too old)
…iance fix(DO-2221): pin base images, fix non-root, add SSC attestation and Docker Scout CI/CD
WeeklyScoutReport's Docker@2 login task left docker scout unauthenticated, so it posted "Policy UNKNOWN / Critical ? ..." to #noti-docker-scout every week. Switch to a plain-script docker login (dockerhub-gluwabot creds via PenguinPatrol variable group secrets), mirroring creditcoin3's working GitHub Actions equivalent. Also drop the invalid --exit-code flag from the BuildAndPush job's informational Scout CVE scan, which failed silently on every build.
fix: authenticate Docker Scout weekly report via plain docker login
[DO-2437] Decouple Weekly Docker Scout Report From CD Release Trigger
* Changes needed because of CC3's runtime upgrade. stable2409 -> stable2512 SDK bump * megalinter update * disabling new linters * fix: stop subtracting held stake from free balance After the Polkadot SDK 2512 upgrade, bonded CTC is a hold in reserved, so RPC free is already unbonded. TransferOptions was still subtracting the staking ledger from free, which zeroed additional bond. Include reserved in the Overview total, and treat an account as a stash when it has a ledger rather than a staking lock. * fix: support lock and hold staking balance math Read staking.palletVersion on connect and branch TransferOptions so bonded CTC is subtracted from free only on pallet < 16 or leftover staking locks. Extract the nominator math and cover v15, v16, and lazy-migration with tests. * chore: refactor 15 to FallbackStakingPalletVersion --------- Co-authored-by: Juan Gallicchio <juan.gallicchio@gluwa.com> Co-authored-by: Jake Edwards <edwardsjake@live.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.