mirror of https://github.com/meshcore-dev/MeshCore
10 changed files with 244 additions and 95 deletions
@ -0,0 +1,90 @@ |
|||||
|
name: Firmware Builder |
||||
|
|
||||
|
on: |
||||
|
workflow_call: |
||||
|
inputs: |
||||
|
firmware_type: |
||||
|
required: true |
||||
|
type: string |
||||
|
release_title_prefix: |
||||
|
required: true |
||||
|
type: string |
||||
|
|
||||
|
jobs: |
||||
|
|
||||
|
generate-build-matrix: |
||||
|
runs-on: ubuntu-latest |
||||
|
outputs: |
||||
|
targets: ${{ steps.get-build-targets.outputs.targets }} |
||||
|
steps: |
||||
|
|
||||
|
- name: Clone Repo |
||||
|
uses: actions/checkout@v6 |
||||
|
|
||||
|
- name: Setup Build Environment |
||||
|
uses: ./.github/actions/setup-build-environment |
||||
|
|
||||
|
- name: Get Build Targets |
||||
|
id: get-build-targets |
||||
|
run: | |
||||
|
# get list of firmwares to build |
||||
|
TARGET_LIST=$(/usr/bin/env bash build.sh get-${{ inputs.firmware_type }}-firmwares-to-build) |
||||
|
|
||||
|
# convert targets separated by new line into a json array string |
||||
|
JSON_ARRAY=$(echo "$TARGET_LIST" | jq -R -s -c 'split("\n") | map(select(length > 0))') |
||||
|
|
||||
|
# use json array as targets result |
||||
|
echo "targets=$JSON_ARRAY" >> $GITHUB_OUTPUT |
||||
|
|
||||
|
build: |
||||
|
needs: generate-build-matrix |
||||
|
runs-on: ubuntu-latest |
||||
|
continue-on-error: true # don't fail entire build if one board fails to build |
||||
|
strategy: |
||||
|
matrix: |
||||
|
target: ${{ fromJson(needs.generate-build-matrix.outputs.targets) }} |
||||
|
fail-fast: false # don't cancel other builds if one board fails to build |
||||
|
steps: |
||||
|
|
||||
|
- name: Clone Repo |
||||
|
uses: actions/checkout@v6 |
||||
|
|
||||
|
- name: Setup Build Environment |
||||
|
uses: ./.github/actions/setup-build-environment |
||||
|
|
||||
|
- name: Build Firmware |
||||
|
env: |
||||
|
FIRMWARE_VERSION: ${{ env.GIT_TAG_VERSION }} |
||||
|
run: /usr/bin/env bash build.sh build-firmware ${{ matrix.target }} |
||||
|
|
||||
|
- name: Upload Workflow Artifacts |
||||
|
uses: actions/upload-artifact@v7 |
||||
|
with: |
||||
|
name: "${{ matrix.target }}" |
||||
|
path: out |
||||
|
|
||||
|
create-release: |
||||
|
needs: build |
||||
|
runs-on: ubuntu-latest |
||||
|
if: startsWith(github.ref, 'refs/tags/') # only create release for tagged builds |
||||
|
steps: |
||||
|
|
||||
|
- name: Clone Repo |
||||
|
uses: actions/checkout@v6 |
||||
|
|
||||
|
- name: Setup Build Environment |
||||
|
uses: ./.github/actions/setup-build-environment |
||||
|
|
||||
|
- name: Download All Artifacts |
||||
|
uses: actions/download-artifact@v8 |
||||
|
with: |
||||
|
merge-multiple: true |
||||
|
path: out |
||||
|
|
||||
|
- name: Create Release |
||||
|
uses: softprops/action-gh-release@v3 |
||||
|
with: |
||||
|
name: "${{ inputs.release_title_prefix }} ${{ env.GIT_TAG_VERSION }}" |
||||
|
body: "" |
||||
|
draft: true |
||||
|
files: out/* |
||||
@ -0,0 +1,32 @@ |
|||||
|
name: 'Run Stale Bot' |
||||
|
on: |
||||
|
schedule: |
||||
|
- cron: '30 1 * * *' # daily at 1:30am |
||||
|
workflow_dispatch: {} |
||||
|
|
||||
|
permissions: |
||||
|
actions: write |
||||
|
issues: write |
||||
|
pull-requests: write |
||||
|
|
||||
|
jobs: |
||||
|
close-issues: |
||||
|
# only run on main repo, not forks |
||||
|
if: github.repository == 'meshcore-dev/MeshCore' |
||||
|
runs-on: ubuntu-latest |
||||
|
steps: |
||||
|
- name: Close Stale Issues |
||||
|
uses: actions/stale@v10 |
||||
|
with: |
||||
|
repo-token: ${{ secrets.GITHUB_TOKEN }} |
||||
|
# auto close issues |
||||
|
days-before-issue-stale: 60 |
||||
|
days-before-issue-close: 7 |
||||
|
exempt-issue-labels: "keep-open" |
||||
|
stale-issue-label: "stale" |
||||
|
stale-issue-message: "This issue is stale because it has been open for 60 days with no activity. Remove the stale label or add a comment if this issue is still relevant, otherwise this issue will automatically close in 7 days." |
||||
|
close-issue-message: "This issue was closed because it has been inactive for 7 days since being marked as stale." |
||||
|
# don't auto close prs |
||||
|
days-before-pr-stale: -1 |
||||
|
days-before-pr-close: -1 |
||||
|
|
||||
@ -0,0 +1,57 @@ |
|||||
|
# Security Policy |
||||
|
|
||||
|
## Supported Versions |
||||
|
|
||||
|
Security fixes are applied to the latest release only. We do not backport |
||||
|
fixes to older versions. |
||||
|
|
||||
|
| Version | Supported | |
||||
|
|---------|-----------| |
||||
|
| 1.15+ | ✅ | |
||||
|
| <1.15 | ❌ | |
||||
|
|
||||
|
## Reporting a Vulnerability |
||||
|
|
||||
|
**Please do not report security vulnerabilities through public GitHub issues.** |
||||
|
|
||||
|
Use GitHub's private vulnerability reporting instead: |
||||
|
1. Go to the **Security** tab of this repository |
||||
|
2. Click **Report a vulnerability** |
||||
|
3. Fill in the details and submit |
||||
|
|
||||
|
### What to include |
||||
|
|
||||
|
A useful report tells us: |
||||
|
- Which component or file is affected |
||||
|
- What an attacker can do (impact) and under what conditions |
||||
|
- A minimal reproduction case or proof-of-concept if you have one |
||||
|
- Whether you believe it is remotely exploitable |
||||
|
|
||||
|
You do not need a working exploit to report. An incomplete report is better |
||||
|
than no report. |
||||
|
|
||||
|
## What to expect |
||||
|
|
||||
|
This is a volunteer-maintained open-source project. We will do our best to |
||||
|
respond in a reasonable timeframe, but cannot commit to specific deadlines. |
||||
|
|
||||
|
We ask that you give us a fair opportunity to investigate and address the |
||||
|
issue before any public disclosure. If you have not heard back after |
||||
|
**90 days**, feel free to follow up or proceed with disclosure at your |
||||
|
discretion. |
||||
|
|
||||
|
## Scope |
||||
|
|
||||
|
In scope: |
||||
|
- Remote code execution, memory corruption, or denial-of-service via crafted |
||||
|
radio packets |
||||
|
- Authentication or encryption bypasses |
||||
|
- Vulnerabilities in the packet routing or path handling logic |
||||
|
|
||||
|
Out of scope: |
||||
|
- Physical access attacks (e.g., JTAG, UART extraction of keys) |
||||
|
- Regulatory compliance (duty cycle, frequency restrictions) |
||||
|
- Jamming or other physical-layer radio interference |
||||
|
- Issues in third-party libraries (RadioLib, Crypto, etc.) — report those |
||||
|
upstream |
||||
|
- "Best practice" suggestions without a demonstrated attack path |
||||
Loading…
Reference in new issue