Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 19 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
* text=auto eol=lf

# Keep the Composer archive to what a consumer needs: no tests, no CI, no
# tooling. Everything below stays in the repository and out of the dist.
/.github export-ignore
/tests export-ignore
/.gitattributes export-ignore
/.gitignore export-ignore
/.editorconfig export-ignore
/phpunit.xml export-ignore
/phpunit.xml.dist export-ignore
/phpstan.neon export-ignore
/phpstan.neon.dist export-ignore
/pint.json export-ignore
/.php-cs-fixer.php export-ignore
/.php-cs-fixer.dist.php export-ignore
/CHANGELOG.md export-ignore
/CONTRIBUTING.md export-ignore
/docs export-ignore
31 changes: 31 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
version: 2

updates:
- package-ecosystem: composer
directory: /
schedule:
interval: weekly
# Wait a week before adopting a fresh release: a compromised or broken
# upstream tag is usually caught in that window.
cooldown:
default-days: 7
open-pull-requests-limit: 5
labels:
- dependencies
groups:
php-dependencies:
patterns:
- '*'

- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
cooldown:
default-days: 7
labels:
- dependencies
groups:
github-actions:
patterns:
- '*'
15 changes: 7 additions & 8 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,17 +15,17 @@ jobs:
test-type: ['phpstan', 'phpunit-unit']

steps:
- uses: actions/checkout@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4

- name: Setup PHP
uses: shivammathur/setup-php@v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
with:
php-version: ${{ matrix.php-version }}
extensions: ${{ env.PHP_EXTENSIONS }}
tools: composer:v2,phpstan,phpunit

- name: Cache Composer dependencies
uses: actions/cache@v4
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4
with:
path: vendor
key: ${{ runner.os }}-composer-${{ hashFiles('**/composer.lock') }}
Expand Down Expand Up @@ -64,17 +64,17 @@ jobs:
php-version: ['8.0', '8.5']

steps:
- uses: actions/checkout@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4

- name: Setup PHP
uses: shivammathur/setup-php@v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
with:
php-version: ${{ matrix.php-version }}
extensions: ${{ env.PHP_EXTENSIONS }}
tools: composer:v2,phpunit

- name: Cache Composer dependencies
uses: actions/cache@v4
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4
with:
path: vendor
key: ${{ runner.os }}-composer-${{ hashFiles('**/composer.lock') }}
Expand All @@ -96,5 +96,4 @@ jobs:
TBAI_GIPUZKOA_APP_LICENSE: ${{ secrets.TBAI_GIPUZKOA_APP_LICENSE }}
TBAI_GIPUZKOA_APP_DEVELOPER_NIF: ${{ secrets.TBAI_GIPUZKOA_APP_DEVELOPER_NIF }}
TBAI_GIPUZKOA_ISSUER_NIF: ${{ secrets.TBAI_GIPUZKOA_ISSUER_NIF }}
run: phpunit -c phpunit.xml.dist --testsuite api

run: phpunit -c phpunit.xml.dist --testsuite api
43 changes: 0 additions & 43 deletions .github/workflows/static.yml

This file was deleted.

39 changes: 39 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
# Security Policy

## Supported versions

Security fixes land on the latest tagged release of this package. Older
tags are not patched.

## Reporting a vulnerability

Report privately, never in a public issue: open a
[security advisory](../../security/advisories/new) on this repository, or
write to **security@kommasofthouse.com**.

Please include the affected version, the steps to reproduce it, and what
an attacker could obtain or alter. A proof of concept helps, but a clear
description is enough.

What to expect:

- Acknowledgement within 3 working days.
- An assessment, with severity and a fix window, within 10 working days.
- Credit in the release notes when the fix ships, unless you prefer not to
be named.

Please give us a reasonable window to release a fix before disclosing
publicly.

## Scope

This package builds, signs or submits fiscal documents to a Spanish tax
administration. Reports about the following are especially welcome:

- Anything that lets a signed or chained record be altered without the
signature or hash changing.
- Anything that exposes certificates, private keys or passphrases in
storage, logs or responses.
- Injection or path traversal reachable from user-supplied invoice data.

Out of scope: vulnerabilities in the tax administrations' own services.
Loading