mirror of
https://github.com/searxng/searxng.git
synced 2026-08-12 02:01:36 +00:00
Compare commits
5 Commits
f32fcb1243
...
48801dbc9a
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
48801dbc9a | ||
|
|
5451ab243a | ||
|
|
7ca24eee45 | ||
|
|
c6a70782b2 | ||
|
|
01a07f34b2 |
83
.github/workflows/data-update.yml
vendored
83
.github/workflows/data-update.yml
vendored
@@ -1,14 +1,27 @@
|
|||||||
name: "Update searx.data"
|
---
|
||||||
on: # yamllint disable-line rule:truthy
|
name: Update searx.data
|
||||||
|
|
||||||
|
# yamllint disable-line rule:truthy
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
schedule:
|
schedule:
|
||||||
- cron: "59 23 28 * *"
|
- cron: "59 23 28 * *"
|
||||||
workflow_dispatch:
|
|
||||||
|
concurrency:
|
||||||
|
group: ${{ github.workflow }}-${{ github.ref_name }}
|
||||||
|
cancel-in-progress: false
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
env:
|
||||||
|
PYTHON_VERSION: "3.13"
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
updateData:
|
data:
|
||||||
name: Update data - ${{ matrix.fetch }}
|
if: github.repository_owner == 'searxng'
|
||||||
runs-on: ubuntu-24.04
|
name: ${{ matrix.fetch }}
|
||||||
if: ${{ github.repository_owner == 'searxng'}}
|
runs-on: ubuntu-24.04-arm
|
||||||
strategy:
|
strategy:
|
||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
@@ -20,48 +33,48 @@ jobs:
|
|||||||
- update_engine_traits.py
|
- update_engine_traits.py
|
||||||
- update_wikidata_units.py
|
- update_wikidata_units.py
|
||||||
- update_engine_descriptions.py
|
- update_engine_descriptions.py
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
|
- name: Setup Python
|
||||||
|
uses: actions/setup-python@v5
|
||||||
|
with:
|
||||||
|
python-version: "${{ env.PYTHON_VERSION }}"
|
||||||
|
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: Install Ubuntu packages
|
- name: Setup cache Python
|
||||||
run: |
|
uses: actions/cache@v4
|
||||||
sudo ./utils/searxng.sh install packages
|
|
||||||
|
|
||||||
- name: Set up Python
|
|
||||||
uses: actions/setup-python@v5
|
|
||||||
with:
|
with:
|
||||||
python-version: '3.12'
|
key: "python-${{ env.PYTHON_VERSION }}-${{ runner.arch }}-${{ hashFiles('./requirements*.txt') }}"
|
||||||
architecture: 'x64'
|
restore-keys: "python-${{ env.PYTHON_VERSION }}-${{ runner.arch }}-"
|
||||||
|
path: "./local/"
|
||||||
|
|
||||||
- name: Install Python dependencies
|
- name: Setup venv
|
||||||
run: |
|
run: make V=1 install
|
||||||
make V=1 install
|
|
||||||
|
|
||||||
- name: Fetch data
|
- name: Fetch data
|
||||||
env:
|
run: V=1 ./manage pyenv.cmd python "./searxng_extra/update/${{ matrix.fetch }}"
|
||||||
FETCH_SCRIPT: ./searxng_extra/update/${{ matrix.fetch }}
|
|
||||||
run: |
|
|
||||||
V=1 ./manage pyenv.cmd python "$FETCH_SCRIPT"
|
|
||||||
|
|
||||||
- name: Create Pull Request
|
- name: Create PR
|
||||||
id: cpr
|
id: cpr
|
||||||
uses: peter-evans/create-pull-request@v6
|
uses: peter-evans/create-pull-request@v7
|
||||||
with:
|
with:
|
||||||
commit-message: '[data] update searx.data - ${{ matrix.fetch }}'
|
author: "${{ github.actor }} <${{ github.actor }}@users.noreply.github.com>"
|
||||||
committer: searxng-bot <noreply@github.com>
|
committer: "searxng-bot <searxng-bot@users.noreply.github.com>"
|
||||||
author: ${{ github.actor }} <${{ github.actor }}@users.noreply.github.com>
|
title: "[data] update searx.data - ${{ matrix.fetch }}"
|
||||||
signoff: false
|
commit-message: "[data] update searx.data - ${{ matrix.fetch }}"
|
||||||
branch: update_data_${{ matrix.fetch }}
|
branch: "update_data_${{ matrix.fetch }}"
|
||||||
delete-branch: true
|
delete-branch: "true"
|
||||||
draft: false
|
draft: "false"
|
||||||
title: '[data] update searx.data - ${{ matrix.fetch }}'
|
signoff: "false"
|
||||||
body: |
|
|
||||||
update searx.data - ${{ matrix.fetch }}
|
|
||||||
labels: |
|
labels: |
|
||||||
data
|
data
|
||||||
|
|
||||||
- name: Check outputs
|
- name: Display information
|
||||||
run: |
|
run: |
|
||||||
echo "Pull Request Number - ${{ steps.cpr.outputs.pull-request-number }}"
|
echo "Pull Request Number - ${{ steps.cpr.outputs.pull-request-number }}"
|
||||||
echo "Pull Request URL - ${{ steps.cpr.outputs.pull-request-url }}"
|
echo "Pull Request URL - ${{ steps.cpr.outputs.pull-request-url }}"
|
||||||
|
|||||||
67
.github/workflows/documentation.yml
vendored
Normal file
67
.github/workflows/documentation.yml
vendored
Normal file
@@ -0,0 +1,67 @@
|
|||||||
|
---
|
||||||
|
name: Documentation
|
||||||
|
|
||||||
|
# yamllint disable-line rule:truthy
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
workflow_run:
|
||||||
|
workflows:
|
||||||
|
- Integration
|
||||||
|
types:
|
||||||
|
- completed
|
||||||
|
branches:
|
||||||
|
- master
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: ${{ github.workflow }}-${{ github.ref_name }}
|
||||||
|
cancel-in-progress: false
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
env:
|
||||||
|
PYTHON_VERSION: "3.13"
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
release:
|
||||||
|
if: github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success'
|
||||||
|
name: Release
|
||||||
|
runs-on: ubuntu-24.04-arm
|
||||||
|
permissions:
|
||||||
|
# for JamesIves/github-pages-deploy-action to push
|
||||||
|
contents: write
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Setup Python
|
||||||
|
uses: actions/setup-python@v5
|
||||||
|
with:
|
||||||
|
python-version: "${{ env.PYTHON_VERSION }}"
|
||||||
|
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
persist-credentials: "false"
|
||||||
|
fetch-depth: "0"
|
||||||
|
|
||||||
|
- name: Setup cache Python
|
||||||
|
uses: actions/cache@v4
|
||||||
|
with:
|
||||||
|
key: "python-${{ env.PYTHON_VERSION }}-${{ runner.arch }}-${{ hashFiles('./requirements*.txt') }}"
|
||||||
|
restore-keys: "python-${{ env.PYTHON_VERSION }}-${{ runner.arch }}-"
|
||||||
|
path: "./local/"
|
||||||
|
|
||||||
|
- name: Setup venv
|
||||||
|
run: make V=1 install
|
||||||
|
|
||||||
|
- name: Build documentation
|
||||||
|
run: make V=1 docs.clean docs.html
|
||||||
|
|
||||||
|
- name: Release
|
||||||
|
uses: JamesIves/github-pages-deploy-action@v4
|
||||||
|
with:
|
||||||
|
folder: "dist/docs"
|
||||||
|
branch: "gh-pages"
|
||||||
|
commit-message: "[doc] build from commit ${{ github.sha }}"
|
||||||
|
# Automatically remove deleted files from the deploy branch
|
||||||
|
clean: "true"
|
||||||
|
single-commit: "true"
|
||||||
43
.github/workflows/integration.yml
vendored
43
.github/workflows/integration.yml
vendored
@@ -47,47 +47,6 @@ jobs:
|
|||||||
- name: Build themes
|
- name: Build themes
|
||||||
run: make themes.all
|
run: make themes.all
|
||||||
|
|
||||||
documentation:
|
|
||||||
name: Documentation
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
permissions:
|
|
||||||
contents: write # for JamesIves/github-pages-deploy-action to push changes in repo
|
|
||||||
steps:
|
|
||||||
- name: Checkout
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
with:
|
|
||||||
fetch-depth: '0'
|
|
||||||
persist-credentials: false
|
|
||||||
- name: Install Ubuntu packages
|
|
||||||
run: sudo ./utils/searxng.sh install buildhost
|
|
||||||
- name: Set up Python
|
|
||||||
uses: actions/setup-python@v5
|
|
||||||
with:
|
|
||||||
python-version: '3.12'
|
|
||||||
architecture: 'x64'
|
|
||||||
- name: Cache Python dependencies
|
|
||||||
id: cache-python
|
|
||||||
uses: actions/cache@v4
|
|
||||||
with:
|
|
||||||
path: |
|
|
||||||
./local
|
|
||||||
./.nvm
|
|
||||||
./node_modules
|
|
||||||
key: python-ubuntu-24.04-3.12-${{ hashFiles('requirements*.txt', 'setup.py','.nvmrc', 'package.json') }}
|
|
||||||
- name: Build documentation
|
|
||||||
run: |
|
|
||||||
make V=1 docs.clean docs.html
|
|
||||||
- name: Deploy
|
|
||||||
if: github.ref == 'refs/heads/master'
|
|
||||||
uses: JamesIves/github-pages-deploy-action@3.7.1
|
|
||||||
with:
|
|
||||||
GITHUB_TOKEN: ${{ github.token }}
|
|
||||||
BRANCH: gh-pages
|
|
||||||
FOLDER: dist/docs
|
|
||||||
CLEAN: true # Automatically remove deleted files from the deploy branch
|
|
||||||
SINGLE_COMMIT: true
|
|
||||||
COMMIT_MESSAGE: '[doc] build from commit ${{ github.sha }}'
|
|
||||||
|
|
||||||
babel:
|
babel:
|
||||||
name: Update translations branch
|
name: Update translations branch
|
||||||
runs-on: ubuntu-24.04
|
runs-on: ubuntu-24.04
|
||||||
@@ -95,7 +54,6 @@ jobs:
|
|||||||
needs:
|
needs:
|
||||||
- python
|
- python
|
||||||
- themes
|
- themes
|
||||||
- documentation
|
|
||||||
permissions:
|
permissions:
|
||||||
contents: write # for make V=1 weblate.push.translations
|
contents: write # for make V=1 weblate.push.translations
|
||||||
steps:
|
steps:
|
||||||
@@ -137,7 +95,6 @@ jobs:
|
|||||||
needs:
|
needs:
|
||||||
- python
|
- python
|
||||||
- themes
|
- themes
|
||||||
- documentation
|
|
||||||
env:
|
env:
|
||||||
DOCKERHUB_USERNAME: ${{ secrets.DOCKERHUB_USERNAME }}
|
DOCKERHUB_USERNAME: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||||
runs-on: ubuntu-24.04
|
runs-on: ubuntu-24.04
|
||||||
|
|||||||
51
.github/workflows/security.yml
vendored
51
.github/workflows/security.yml
vendored
@@ -1,28 +1,43 @@
|
|||||||
name: "Security checks"
|
---
|
||||||
on: # yamllint disable-line rule:truthy
|
name: Security
|
||||||
|
|
||||||
|
# yamllint disable-line rule:truthy
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
schedule:
|
schedule:
|
||||||
- cron: "42 05 * * *"
|
- cron: "42 05 * * *"
|
||||||
workflow_dispatch:
|
|
||||||
|
concurrency:
|
||||||
|
group: ${{ github.workflow }}-${{ github.ref_name }}
|
||||||
|
cancel-in-progress: false
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
dockers:
|
container:
|
||||||
name: Trivy ${{ matrix.image }}
|
name: Container
|
||||||
runs-on: ubuntu-24.04
|
runs-on: ubuntu-24.04-arm
|
||||||
|
permissions:
|
||||||
|
security-events: write
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: Run Trivy vulnerability scanner
|
|
||||||
uses: aquasecurity/trivy-action@master
|
|
||||||
with:
|
with:
|
||||||
image-ref: 'searxng/searxng:latest'
|
persist-credentials: "false"
|
||||||
ignore-unfixed: false
|
|
||||||
vuln-type: 'os,library'
|
|
||||||
severity: 'UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL'
|
|
||||||
format: 'sarif'
|
|
||||||
output: 'trivy-results.sarif'
|
|
||||||
|
|
||||||
- name: Upload Trivy scan results to GitHub Security tab
|
- name: Run Trivy scanner
|
||||||
uses: github/codeql-action/upload-sarif@v2
|
uses: aquasecurity/trivy-action@0.30.0
|
||||||
with:
|
with:
|
||||||
sarif_file: 'trivy-results.sarif'
|
image-ref: "docker.io/searxng/searxng:latest"
|
||||||
|
vuln-type: "os,library"
|
||||||
|
severity: "UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL"
|
||||||
|
ignore-unfixed: "false"
|
||||||
|
format: "sarif"
|
||||||
|
output: "./trivy-results.sarif"
|
||||||
|
|
||||||
|
- name: Upload SARIFs
|
||||||
|
uses: github/codeql-action/upload-sarif@v3
|
||||||
|
with:
|
||||||
|
sarif_file: "./trivy-results.sarif"
|
||||||
|
|||||||
Reference in New Issue
Block a user