From 20d316c3070faa673113f70ef99739046e73002c Mon Sep 17 00:00:00 2001 From: Armin Schrenk Date: Tue, 12 Dec 2023 15:43:54 +0100 Subject: [PATCH 01/16] update dependecy-check to 9.0.4 and refactor it to own workflow --- .github/workflows/build.yml | 4 +- .github/workflows/dependency-check.yml | 54 ++++++++++++++++++++++++++ pom.xml | 4 +- 3 files changed, 58 insertions(+), 4 deletions(-) create mode 100644 .github/workflows/dependency-check.yml diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 115aa2e..ddab543 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -17,10 +17,10 @@ jobs: if: startsWith(github.ref, 'refs/tags/') shell: bash run: | - mvn versions:set --file ./pom.xml -DnewVersion=${GITHUB_REF##*/} + mvn -B versions:set --file ./pom.xml -DnewVersion=${GITHUB_REF##*/} - name: Build and Test id: buildAndTest - run: mvn -B clean install -Pdependency-check + run: mvn -B clean install - uses: actions/upload-artifact@v3 with: name: artifacts diff --git a/.github/workflows/dependency-check.yml b/.github/workflows/dependency-check.yml new file mode 100644 index 0000000..b7742f9 --- /dev/null +++ b/.github/workflows/dependency-check.yml @@ -0,0 +1,54 @@ +name: OWASP Maven Dependency Check +on: + schedule: + - cron: '0 7 * * 0' + push: + branches: + - 'release/**' + workflow_dispatch: + + +jobs: + check-dependencies: + name: Check dependencies + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + with: + show-progress: false + - name: Setup Java + uses: actions/setup-java@v4 + with: + distribution: 'temurin' + java-version: 21 + cache: 'maven' + - name: Run org.owasp:dependency-check plugin + id: dependency-check + continue-on-error: true + run: mvn -B verify -Pdependency-check -DskipTests + env: + NVD_API_KEY: ${{ secrets.NVD_API_KEY }} + - name: Upload report on failure + if: steps.dependency-check.outcome == 'failure' + uses: actions/upload-artifact@v3 + with: + name: dependency-check-report + path: target/dependency-check-report.html + if-no-files-found: error + - name: Slack Notification on regular check + if: github.event_name == 'schedule' && steps.dependency-check.outcome == 'failure' + uses: rtCamp/action-slack-notify@v2 + env: + SLACK_WEBHOOK: ${{ secrets.SLACK_WEBHOOK_URL }} + SLACK_USERNAME: 'Cryptobot' + SLACK_ICON: false + SLACK_ICON_EMOJI: ':bot:' + SLACK_CHANNEL: 'cryptomator-desktop' + SLACK_TITLE: "Vulnerabilities in ${{ github.event.repository.name }} detected." + SLACK_MESSAGE: "Download the for more details." + SLACK_FOOTER: false + MSG_MINIMAL: true + - name: Failing workflow on release branch + if: github.event_name == 'push' && steps.dependency-check.outcome == 'failure' + shell: bash + run: exit 1 \ No newline at end of file diff --git a/pom.xml b/pom.xml index a8432c2..98228ab 100644 --- a/pom.xml +++ b/pom.xml @@ -50,7 +50,7 @@ 5.10.1 - 8.4.2 + 9.0.4 1.6.8 @@ -211,11 +211,11 @@ dependency-check-maven ${dependency-check.version} - 24 0 true true suppression.xml + ${env.NVD_API_KEY} From 2862383eb2a8393fa00f1f80b327cf8785c34ef1 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 12 Dec 2023 15:12:30 +0000 Subject: [PATCH 02/16] Bump the maven-build-plugins group with 2 updates (#51) --- pom.xml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pom.xml b/pom.xml index 98228ab..9a9e37d 100644 --- a/pom.xml +++ b/pom.xml @@ -105,7 +105,7 @@ org.apache.maven.plugins maven-surefire-plugin - 3.2.1 + 3.2.2 org.apache.maven.plugins @@ -143,7 +143,7 @@ maven-javadoc-plugin - 3.6.0 + 3.6.3 attach-javadocs From 0108454da847fc7e9f7fd6f632b8e4a914a3d2d4 Mon Sep 17 00:00:00 2001 From: Sebastian Stenzel Date: Wed, 13 Dec 2023 11:15:21 +0100 Subject: [PATCH 03/16] use separate cache key for dependency-check (use same restore key as "normal" setup-java as a backup) --- .github/workflows/dependency-check.yml | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/.github/workflows/dependency-check.yml b/.github/workflows/dependency-check.yml index b7742f9..57fbde3 100644 --- a/.github/workflows/dependency-check.yml +++ b/.github/workflows/dependency-check.yml @@ -21,7 +21,15 @@ jobs: with: distribution: 'temurin' java-version: 21 - cache: 'maven' + - uses: actions/cache@v3 + with: + path: ~/.m2/repository + key: ${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }}-dependency-check + restore-keys: | + ${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }} + ${{ runner.os }}-maven- + env: + SEGMENT_DOWNLOAD_TIMEOUT_MINS: 5 - name: Run org.owasp:dependency-check plugin id: dependency-check continue-on-error: true From 521504ebe06a615dbc5f7dfcc4f22abc17c9779d Mon Sep 17 00:00:00 2001 From: Sebastian Stenzel Date: Wed, 13 Dec 2023 11:17:14 +0100 Subject: [PATCH 04/16] fix syntax error --- .github/workflows/dependency-check.yml | 19 ++++++++++--------- 1 file changed, 10 insertions(+), 9 deletions(-) diff --git a/.github/workflows/dependency-check.yml b/.github/workflows/dependency-check.yml index 57fbde3..b47d3d6 100644 --- a/.github/workflows/dependency-check.yml +++ b/.github/workflows/dependency-check.yml @@ -21,15 +21,16 @@ jobs: with: distribution: 'temurin' java-version: 21 - - uses: actions/cache@v3 - with: - path: ~/.m2/repository - key: ${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }}-dependency-check - restore-keys: | - ${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }} - ${{ runner.os }}-maven- - env: - SEGMENT_DOWNLOAD_TIMEOUT_MINS: 5 + - name: Cache Maven Repository + uses: actions/cache@v3 + with: + path: ~/.m2/repository + key: ${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }}-dependency-check + restore-keys: | + ${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }} + ${{ runner.os }}-maven- + env: + SEGMENT_DOWNLOAD_TIMEOUT_MINS: 5 - name: Run org.owasp:dependency-check plugin id: dependency-check continue-on-error: true From 06cb66acb310d10369fd691a0a87617eb2dc9931 Mon Sep 17 00:00:00 2001 From: Sebastian Stenzel Date: Wed, 13 Dec 2023 11:18:11 +0100 Subject: [PATCH 05/16] fix another yml error --- .github/workflows/dependency-check.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/dependency-check.yml b/.github/workflows/dependency-check.yml index b47d3d6..b86c8a6 100644 --- a/.github/workflows/dependency-check.yml +++ b/.github/workflows/dependency-check.yml @@ -29,8 +29,8 @@ jobs: restore-keys: | ${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }} ${{ runner.os }}-maven- - env: - SEGMENT_DOWNLOAD_TIMEOUT_MINS: 5 + env: + SEGMENT_DOWNLOAD_TIMEOUT_MINS: 5 - name: Run org.owasp:dependency-check plugin id: dependency-check continue-on-error: true From 167b62131970fe5290a13660cedc722841f663b5 Mon Sep 17 00:00:00 2001 From: Sebastian Stenzel Date: Wed, 13 Dec 2023 11:20:22 +0100 Subject: [PATCH 06/16] fix restore-keys to restore from setup-java cache --- .github/workflows/dependency-check.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/dependency-check.yml b/.github/workflows/dependency-check.yml index b86c8a6..b6a7c84 100644 --- a/.github/workflows/dependency-check.yml +++ b/.github/workflows/dependency-check.yml @@ -27,8 +27,8 @@ jobs: path: ~/.m2/repository key: ${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }}-dependency-check restore-keys: | - ${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }} - ${{ runner.os }}-maven- + setup-java-${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }} + setup-java-${{ runner.os }}-maven- env: SEGMENT_DOWNLOAD_TIMEOUT_MINS: 5 - name: Run org.owasp:dependency-check plugin From f7ed1f66a5a5d62853984e14fff571f7734441c0 Mon Sep 17 00:00:00 2001 From: Sebastian Stenzel Date: Wed, 13 Dec 2023 11:52:38 +0100 Subject: [PATCH 07/16] use separate cache for dependency-cache data --- .github/workflows/dependency-check.yml | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/dependency-check.yml b/.github/workflows/dependency-check.yml index b6a7c84..b925365 100644 --- a/.github/workflows/dependency-check.yml +++ b/.github/workflows/dependency-check.yml @@ -21,14 +21,14 @@ jobs: with: distribution: 'temurin' java-version: 21 - - name: Cache Maven Repository + cache: 'maven' + - name: Cache NVD DB uses: actions/cache@v3 with: - path: ~/.m2/repository - key: ${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }}-dependency-check + path: ~/.m2/repository/org/owasp/dependency-check-data/ + key: dependency-check-${{ github.run_id }} restore-keys: | - setup-java-${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }} - setup-java-${{ runner.os }}-maven- + dependency-check env: SEGMENT_DOWNLOAD_TIMEOUT_MINS: 5 - name: Run org.owasp:dependency-check plugin From 042d56c5fef6d1c408e29b0f7f01ecce73122a35 Mon Sep 17 00:00:00 2001 From: Armin Schrenk Date: Wed, 13 Dec 2023 16:55:43 +0100 Subject: [PATCH 08/16] adjust dependency check plugin --- .github/workflows/dependency-check.yml | 2 +- pom.xml | 2 ++ 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/dependency-check.yml b/.github/workflows/dependency-check.yml index b925365..344093d 100644 --- a/.github/workflows/dependency-check.yml +++ b/.github/workflows/dependency-check.yml @@ -34,7 +34,7 @@ jobs: - name: Run org.owasp:dependency-check plugin id: dependency-check continue-on-error: true - run: mvn -B verify -Pdependency-check -DskipTests + run: mvn -B validate -Pdependency-check env: NVD_API_KEY: ${{ secrets.NVD_API_KEY }} - name: Upload report on failure diff --git a/pom.xml b/pom.xml index 9a9e37d..8a0ec83 100644 --- a/pom.xml +++ b/pom.xml @@ -211,6 +211,7 @@ dependency-check-maven ${dependency-check.version} + 24 0 true true @@ -222,6 +223,7 @@ check + validate From e8fd9f1c133c8200b6f92140fe4f7d8ea0f7b37b Mon Sep 17 00:00:00 2001 From: Armin Schrenk Date: Mon, 18 Dec 2023 10:51:24 +0100 Subject: [PATCH 09/16] Update dependency-check.yml to not run into 403 due to rate limit --- .github/workflows/dependency-check.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/dependency-check.yml b/.github/workflows/dependency-check.yml index 344093d..90896a3 100644 --- a/.github/workflows/dependency-check.yml +++ b/.github/workflows/dependency-check.yml @@ -1,7 +1,7 @@ name: OWASP Maven Dependency Check on: schedule: - - cron: '0 7 * * 0' + - cron: '0 11 * * 0' push: branches: - 'release/**' @@ -60,4 +60,4 @@ jobs: - name: Failing workflow on release branch if: github.event_name == 'push' && steps.dependency-check.outcome == 'failure' shell: bash - run: exit 1 \ No newline at end of file + run: exit 1 From 5eb75740e1870ca117e1a8f86934485018523ac6 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 18 Jan 2024 09:51:06 +0000 Subject: [PATCH 10/16] Bump the maven-build-plugins group with 3 updates (#53) --- pom.xml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pom.xml b/pom.xml index 8a0ec83..f10aef7 100644 --- a/pom.xml +++ b/pom.xml @@ -50,7 +50,7 @@ 5.10.1 - 9.0.4 + 9.0.7 1.6.8 @@ -94,7 +94,7 @@ org.apache.maven.plugins maven-compiler-plugin - 3.11.0 + 3.12.1 ${project.jdk.version} @@ -105,7 +105,7 @@ org.apache.maven.plugins maven-surefire-plugin - 3.2.2 + 3.2.3 org.apache.maven.plugins From 6fa6352f782b73d699ac772d008077add8334528 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 18 Jan 2024 09:52:25 +0000 Subject: [PATCH 11/16] Bump the github-actions group with 2 updates (#55) --- .github/workflows/build.yml | 2 +- .github/workflows/codeql-analysis.yml | 4 ++-- .github/workflows/dependency-check.yml | 2 +- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index ddab543..2612eef 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -21,7 +21,7 @@ jobs: - name: Build and Test id: buildAndTest run: mvn -B clean install - - uses: actions/upload-artifact@v3 + - uses: actions/upload-artifact@v4 with: name: artifacts path: target/*.jar diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index d587876..e979d17 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -25,10 +25,10 @@ jobs: java-version: 21 cache: 'maven' - name: Initialize CodeQL - uses: github/codeql-action/init@v2 + uses: github/codeql-action/init@v3 with: languages: java - name: Build run: mvn -B compile - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v2 \ No newline at end of file + uses: github/codeql-action/analyze@v3 \ No newline at end of file diff --git a/.github/workflows/dependency-check.yml b/.github/workflows/dependency-check.yml index 90896a3..04a9e0a 100644 --- a/.github/workflows/dependency-check.yml +++ b/.github/workflows/dependency-check.yml @@ -39,7 +39,7 @@ jobs: NVD_API_KEY: ${{ secrets.NVD_API_KEY }} - name: Upload report on failure if: steps.dependency-check.outcome == 'failure' - uses: actions/upload-artifact@v3 + uses: actions/upload-artifact@v4 with: name: dependency-check-report path: target/dependency-check-report.html From 61fa4b343c3e6f004dec0aebb4c4f78f1db4afea Mon Sep 17 00:00:00 2001 From: Armin Schrenk Date: Thu, 18 Jan 2024 11:13:03 +0100 Subject: [PATCH 12/16] only execute KWallet test, if DISPLAY env variable is present --- .../linux/keychain/KDEWalletKeychainAccessTest.java | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/src/test/java/org/cryptomator/linux/keychain/KDEWalletKeychainAccessTest.java b/src/test/java/org/cryptomator/linux/keychain/KDEWalletKeychainAccessTest.java index f5539a0..e300c74 100644 --- a/src/test/java/org/cryptomator/linux/keychain/KDEWalletKeychainAccessTest.java +++ b/src/test/java/org/cryptomator/linux/keychain/KDEWalletKeychainAccessTest.java @@ -3,6 +3,7 @@ import org.junit.jupiter.api.Assertions; import org.junit.jupiter.api.BeforeAll; import org.junit.jupiter.api.Test; +import org.junit.jupiter.api.condition.EnabledIf; import org.junit.jupiter.api.condition.EnabledOnOs; import org.junit.jupiter.api.condition.OS; @@ -14,6 +15,7 @@ * Unit tests for KWallet access via DBUS. */ @EnabledOnOs(OS.LINUX) +@EnabledIf("osEnvironmentSuitable") public class KDEWalletKeychainAccessTest { private static boolean isInstalled; @@ -40,4 +42,9 @@ public void testIsSupported() { KDEWalletKeychainAccess keychainAccess = new KDEWalletKeychainAccess(); Assertions.assertEquals(isInstalled, keychainAccess.isSupported()); } + + + private static boolean osEnvironmentSuitable() { + return System.getenv().containsKey("DISPLAY"); + } } From 234a04aec000c2d18bb7c6827346299658a4989e Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 18 Jan 2024 10:48:16 +0000 Subject: [PATCH 13/16] Bump the java-production-dependencies group with 1 update (#58) --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index f10aef7..c8d76f6 100644 --- a/pom.xml +++ b/pom.xml @@ -44,7 +44,7 @@ 2.0.0-alpha 1.3.3 1.3.6 - 2.0.9 + 2.0.11 5.10.1 From a09e14a2bf1bfcc5c648dd504ec491758c9b895a Mon Sep 17 00:00:00 2001 From: Armin Schrenk Date: Thu, 18 Jan 2024 11:54:22 +0100 Subject: [PATCH 14/16] closes #56 --- .../linux/keychain/SecretServiceKeychainAccess.java | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/src/main/java/org/cryptomator/linux/keychain/SecretServiceKeychainAccess.java b/src/main/java/org/cryptomator/linux/keychain/SecretServiceKeychainAccess.java index d52df08..28ead2a 100644 --- a/src/main/java/org/cryptomator/linux/keychain/SecretServiceKeychainAccess.java +++ b/src/main/java/org/cryptomator/linux/keychain/SecretServiceKeychainAccess.java @@ -6,6 +6,8 @@ import org.cryptomator.integrations.keychain.KeychainAccessException; import org.cryptomator.integrations.keychain.KeychainAccessProvider; import org.freedesktop.dbus.exceptions.DBusExecutionException; +import org.slf4j.Logger; +import org.slf4j.LoggerFactory; import java.io.IOException; import java.util.List; @@ -15,6 +17,8 @@ @OperatingSystem(OperatingSystem.Value.LINUX) public class SecretServiceKeychainAccess implements KeychainAccessProvider { + private static Logger LOG = LoggerFactory.getLogger(SecretServiceKeychainAccess.class); + private final String LABEL_FOR_SECRET_IN_KEYRING = "Cryptomator"; @Override @@ -27,12 +31,8 @@ public boolean isSupported() { try { return SimpleCollection.isAvailable(); } catch (ExceptionInInitializerError e) { - //TODO: remove try-catch once secret-service lib is fixed - if(e.getException() instanceof DBusExecutionException) { - return false; - } else { - throw e; - } + LOG.warn("Initializing secret service keychain access failed", e.getException()); + return false; } } From 570647656137323347b500b2e521d277f3c05c04 Mon Sep 17 00:00:00 2001 From: Armin Schrenk Date: Thu, 18 Jan 2024 11:55:32 +0100 Subject: [PATCH 15/16] remove unused import --- .../cryptomator/linux/keychain/SecretServiceKeychainAccess.java | 1 - 1 file changed, 1 deletion(-) diff --git a/src/main/java/org/cryptomator/linux/keychain/SecretServiceKeychainAccess.java b/src/main/java/org/cryptomator/linux/keychain/SecretServiceKeychainAccess.java index 28ead2a..500c212 100644 --- a/src/main/java/org/cryptomator/linux/keychain/SecretServiceKeychainAccess.java +++ b/src/main/java/org/cryptomator/linux/keychain/SecretServiceKeychainAccess.java @@ -5,7 +5,6 @@ import org.cryptomator.integrations.common.Priority; import org.cryptomator.integrations.keychain.KeychainAccessException; import org.cryptomator.integrations.keychain.KeychainAccessProvider; -import org.freedesktop.dbus.exceptions.DBusExecutionException; import org.slf4j.Logger; import org.slf4j.LoggerFactory; From 6a5b909a17bbf187f269ea93b152b69d7097733e Mon Sep 17 00:00:00 2001 From: Armin Schrenk Date: Thu, 18 Jan 2024 12:01:17 +0100 Subject: [PATCH 16/16] prepare 1.4.1 --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index c8d76f6..daa77bf 100644 --- a/pom.xml +++ b/pom.xml @@ -5,7 +5,7 @@ 4.0.0 org.cryptomator integrations-linux - 1.5.0-SNAPSHOT + 1.4.1 integrations-linux Provides optional Linux services used by Cryptomator