From d2e5c40e63f9937c023182e8f4553802ca672b1e Mon Sep 17 00:00:00 2001 From: WilcoLouwerse Date: Fri, 2 Oct 2026 13:59:48 +0200 Subject: [PATCH] fix(ci): regenerate features.json and clear the CodeQL alerts on the beta promotion - docs/features.json: license-and-seat-tracking is stable in openspec/specs, so Features Extract (and with it the required Quality Report) failed. - e2e fixtures: RUN_ID uses crypto.randomUUID() instead of Math.random() (js/insecure-randomness, alerts 43, 44, 46 and 47). - documentation.yml: declare the permission ceiling the reusable workflow needs (actions/missing-workflow-permissions, alert 42). Refs: WOO-589 Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/documentation.yml | 7 +++++++ docs/features.json | 2 +- tests/e2e/workflows/_fixtures.ts | 3 ++- 3 files changed, 10 insertions(+), 2 deletions(-) diff --git a/.github/workflows/documentation.yml b/.github/workflows/documentation.yml index 98db0b547..4c664413e 100644 --- a/.github/workflows/documentation.yml +++ b/.github/workflows/documentation.yml @@ -14,6 +14,13 @@ on: jobs: deploy: + # Permission CEILING for the called workflow, not a grant: the callee's + # deploy job declares `contents: write` (gh-pages push) and its fallback + # image job `packages: write` (GHCR). A ceiling below what the callee + # declares makes the call fail to start. + permissions: + contents: write + packages: write uses: ConductionNL/.github/.github/workflows/documentation.yml@main # A reusable workflow receives NO secrets by default. Without this block the # callee's publish step finds CF_API_TOKEN empty, skips itself on its own diff --git a/docs/features.json b/docs/features.json index d880a6028..8f72e5197 100644 --- a/docs/features.json +++ b/docs/features.json @@ -150,7 +150,7 @@ "slug": "license-and-seat-tracking", "title": "License and seat tracking", "summary": "Track license models and seats next to your contracts.", - "status": "soon", + "status": "stable", "docsUrl": "openspec/specs/license-and-seat-tracking/spec.md", "title_nl": "Licentie- en seatregistratie", "summary_nl": "Houd licentiemodellen en seats bij naast je contracten." diff --git a/tests/e2e/workflows/_fixtures.ts b/tests/e2e/workflows/_fixtures.ts index ed688de99..d91fa5aff 100644 --- a/tests/e2e/workflows/_fixtures.ts +++ b/tests/e2e/workflows/_fixtures.ts @@ -26,6 +26,7 @@ import type { APIRequestContext } from '@playwright/test' import { request as playwrightRequest } from '@playwright/test' +import { randomUUID } from 'node:crypto' import { resolveBaseUrl } from '../base-url.ts' // Re-exported from the single central resolver (tests/e2e/base-url.ts). These @@ -36,7 +37,7 @@ export const NC_ADMIN_USER = process.env.NC_ADMIN_USER ?? 'admin' export const NC_ADMIN_PASS = process.env.NC_ADMIN_PASS ?? 'admin' /** Unique per Node process so parallel-ish runs never collide. */ -export const RUN_ID = `e2e-${Date.now().toString(36)}-${Math.random().toString(36).slice(2, 6)}` +export const RUN_ID = `e2e-${Date.now().toString(36)}-${randomUUID().slice(0, 4)}` export interface VoorzieningenConfig { register: string