Compare commits
14
Commits
52964e28f0
...
v1.0.1
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f4160df1d7
|
||
|
|
3f5f18d98f
|
||
|
|
85e9046768
|
||
|
|
5728649c79
|
||
|
|
8eb0048606
|
||
|
|
d92cb57d87
|
||
|
|
884f2dfec1
|
||
|
|
e7407da5b4
|
||
|
|
0f28e1bdbc
|
||
|
|
bab42a5e88
|
||
|
|
65785eac76
|
||
|
|
47c6567ec7
|
||
|
|
966bcc3778
|
||
|
|
01e511cdbb
|
Generated
+1
-1
@@ -866,7 +866,7 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "mirror-package"
|
name = "mirror-package"
|
||||||
version = "0.1.1"
|
version = "1.0.1"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"anyhow",
|
"anyhow",
|
||||||
"clap",
|
"clap",
|
||||||
|
|||||||
+14
-6
@@ -1,6 +1,6 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "mirror-package"
|
name = "mirror-package"
|
||||||
version = "0.1.1"
|
version = "1.0.1"
|
||||||
edition = "2024"
|
edition = "2024"
|
||||||
authors = ['DragonSlayer_14']
|
authors = ['DragonSlayer_14']
|
||||||
readme = "README.md"
|
readme = "README.md"
|
||||||
@@ -29,18 +29,26 @@ maintainer = "DragonSlayer_14"
|
|||||||
copyright = "2026 DragonSlayer_14"
|
copyright = "2026 DragonSlayer_14"
|
||||||
section = "utils"
|
section = "utils"
|
||||||
priority = "optional"
|
priority = "optional"
|
||||||
depends = "$auto"
|
depends = "$auto, ca-certificates"
|
||||||
extended-description = """\
|
extended-description = """\
|
||||||
Spiegelt vorkompilierte Linux-Pakete (.deb, .rpm, .pkg.tar.zst) aus GitHub-Releases in Gitea-Paket-Registries.\
|
Spiegelt vorkompilierte Linux-Pakete (.deb, .rpm, .pkg.tar.zst) aus GitHub-Releases in Gitea-Paket-Registries.\
|
||||||
"""
|
"""
|
||||||
assets = []
|
assets = [
|
||||||
|
["target/release/mirror-package", "usr/bin/mirror-package", "755"],
|
||||||
|
["README.md", "usr/share/doc/mirror-package/README.md", "644"],
|
||||||
|
["LICENSE", "usr/share/doc/mirror-package/copyright", "644"],
|
||||||
|
]
|
||||||
|
|
||||||
[package.metadata.generate-rpm]
|
[package.metadata.generate-rpm]
|
||||||
assets = []
|
assets = [
|
||||||
requires = { }
|
{ source = "target/release/mirror-package", dest = "/usr/bin/mirror-package", mode = "755" },
|
||||||
|
{ source = "README.md", dest = "/usr/share/doc/mirror-package/README.md", mode = "644", doc = true },
|
||||||
|
{ source = "LICENSE", dest = "/usr/share/licenses/mirror-package/LICENSE", mode = "644", license = true },
|
||||||
|
]
|
||||||
|
requires = { "ca-certificates" = "*", "glibc" = "*" }
|
||||||
|
|
||||||
[package.metadata.arch]
|
[package.metadata.arch]
|
||||||
pkgrel = "1"
|
pkgrel = "1"
|
||||||
arch = "x86_64"
|
arch = "x86_64"
|
||||||
depends = ["gcc-libs", "glibc"]
|
depends = ["gcc-libs", "glibc", "ca-certificates"]
|
||||||
optdepends = []
|
optdepends = []
|
||||||
|
|||||||
+1
-1
@@ -1,7 +1,7 @@
|
|||||||
# syntax=docker/dockerfile:1
|
# syntax=docker/dockerfile:1
|
||||||
|
|
||||||
# Minimales und gehärtetes Runtime-Image
|
# Minimales und gehärtetes Runtime-Image
|
||||||
FROM debian:bookworm-slim AS runtime
|
FROM debian:trixie-slim AS runtime
|
||||||
|
|
||||||
# CA-Zertifikate und minimale dynamische Laufzeitbibliotheken installieren
|
# CA-Zertifikate und minimale dynamische Laufzeitbibliotheken installieren
|
||||||
RUN apt-get update && \
|
RUN apt-get update && \
|
||||||
|
|||||||
@@ -120,7 +120,7 @@ Der Container wurde nach höchsten Sicherheitsstandards aufgebaut:
|
|||||||
- **Read-Only Root-Dateisystem**: Voll funktionsfähig mit `--read-only` / `read_only: true`.
|
- **Read-Only Root-Dateisystem**: Voll funktionsfähig mit `--read-only` / `read_only: true`.
|
||||||
- **Keine Capabilities**: Sämtliche Linux-Capabilities können sicher entzogen werden (`--cap-drop=ALL`).
|
- **Keine Capabilities**: Sämtliche Linux-Capabilities können sicher entzogen werden (`--cap-drop=ALL`).
|
||||||
- **Keine Rechteausweitung**: Erzwingt `no-new-privileges:true`.
|
- **Keine Rechteausweitung**: Erzwingt `no-new-privileges:true`.
|
||||||
- **Minimale Image-Größe**: Basiert auf Debian Bookworm Slim und enthält nur CA-Zertifikate und notwendige dynamische Bibliotheken (~40 MB).
|
- **Minimale Image-Größe**: Basiert auf Debian Trixie Slim und enthält nur CA-Zertifikate und notwendige dynamische Bibliotheken (~40 MB).
|
||||||
|
|
||||||
### 4. Ausführung über Docker CLI
|
### 4. Ausführung über Docker CLI
|
||||||
|
|
||||||
|
|||||||
+50
@@ -0,0 +1,50 @@
|
|||||||
|
#-------------------------------------------------------------------------------#
|
||||||
|
# Qodana analysis is configured by qodana.yaml file #
|
||||||
|
# https://www.jetbrains.com/help/qodana/qodana-yaml.html #
|
||||||
|
#-------------------------------------------------------------------------------#
|
||||||
|
|
||||||
|
#################################################################################
|
||||||
|
# WARNING: Do not store sensitive information in this file, #
|
||||||
|
# as its contents will be included in the Qodana report. #
|
||||||
|
#################################################################################
|
||||||
|
version: "1.0"
|
||||||
|
|
||||||
|
#Specify inspection profile for code analysis
|
||||||
|
profile:
|
||||||
|
name: qodana.starter
|
||||||
|
|
||||||
|
#Enable inspections
|
||||||
|
#include:
|
||||||
|
# - name: <SomeEnabledInspectionId>
|
||||||
|
|
||||||
|
#Disable inspections
|
||||||
|
#exclude:
|
||||||
|
# - name: <SomeDisabledInspectionId>
|
||||||
|
# paths:
|
||||||
|
# - <path/where/not/run/inspection>
|
||||||
|
|
||||||
|
#Execute shell command before Qodana execution (Applied in CI/CD pipeline)
|
||||||
|
#bootstrap: sh ./prepare-qodana.sh
|
||||||
|
|
||||||
|
#Install IDE plugins before Qodana execution (Applied in CI/CD pipeline)
|
||||||
|
#plugins:
|
||||||
|
# - id: <plugin.id> #(plugin id can be found at https://plugins.jetbrains.com)
|
||||||
|
|
||||||
|
# Quality gate. Will fail the CI/CD pipeline if any condition is not met
|
||||||
|
# severityThresholds - configures maximum thresholds for different problem severities
|
||||||
|
# testCoverageThresholds - configures minimum code coverage on a whole project and newly added code
|
||||||
|
# dependencyLicenses - fails the run on prohibited or unknown dependency licenses
|
||||||
|
# Code Coverage is available in Ultimate and Ultimate Plus plans
|
||||||
|
#failureConditions:
|
||||||
|
# severityThresholds:
|
||||||
|
# any: 15
|
||||||
|
# critical: 5
|
||||||
|
# testCoverageThresholds:
|
||||||
|
# fresh: 70
|
||||||
|
# total: 50
|
||||||
|
# dependencyLicenses:
|
||||||
|
# failOnProhibited: true
|
||||||
|
# failOnUnknown: false
|
||||||
|
|
||||||
|
#Specify Qodana linter for analysis (Applied in CI/CD pipeline)
|
||||||
|
linter: jetbrains/qodana-<linter>:2026.2
|
||||||
Reference in New Issue
Block a user