diff --git a/.gitattributes b/.gitattributes index 6313b56..060fba8 100644 --- a/.gitattributes +++ b/.gitattributes @@ -1 +1,19 @@ * text=auto eol=lf + +# Keep the Composer archive to what a consumer needs: no tests, no CI, no +# tooling. Everything below stays in the repository and out of the dist. +/.github export-ignore +/tests export-ignore +/.gitattributes export-ignore +/.gitignore export-ignore +/.editorconfig export-ignore +/phpunit.xml export-ignore +/phpunit.xml.dist export-ignore +/phpstan.neon export-ignore +/phpstan.neon.dist export-ignore +/pint.json export-ignore +/.php-cs-fixer.php export-ignore +/.php-cs-fixer.dist.php export-ignore +/CHANGELOG.md export-ignore +/CONTRIBUTING.md export-ignore +/docs export-ignore diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..6ce7137 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,31 @@ +version: 2 + +updates: + - package-ecosystem: composer + directory: / + schedule: + interval: weekly + # Wait a week before adopting a fresh release: a compromised or broken + # upstream tag is usually caught in that window. + cooldown: + default-days: 7 + open-pull-requests-limit: 5 + labels: + - dependencies + groups: + php-dependencies: + patterns: + - '*' + + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly + cooldown: + default-days: 7 + labels: + - dependencies + groups: + github-actions: + patterns: + - '*' diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index bf36099..568b133 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -20,7 +20,7 @@ jobs: steps: # Download code from repository - name: Checkout code - uses: actions/checkout@v6 + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6 # Get Composer cache directory - name: Get Composer cache directory @@ -29,7 +29,7 @@ jobs: # Cache dependencies - name: Cache dependencies - uses: actions/cache@v4 + uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4 with: path: ${{ steps.composer-cache.outputs.dir }} key: ${{ runner.os }}-composer-${{ hashFiles('**/composer.json') }} @@ -37,7 +37,7 @@ jobs: # Setup PHP - name: Setup PHP - uses: shivammathur/setup-php@v2 + uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2 with: php-version: ${{ matrix.php-version }} coverage: none diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml deleted file mode 100644 index 0047673..0000000 --- a/.github/workflows/docs.yml +++ /dev/null @@ -1,40 +0,0 @@ -name: Documentation - -on: - push: - branches: [main] - -permissions: - contents: write - -jobs: - docs: - name: Build docs - runs-on: ubuntu-latest - steps: - # Download code from repository - - name: Checkout code - uses: actions/checkout@v6 - - # Setup PHP - - name: Setup PHP - uses: shivammathur/setup-php@v2 - with: - php-version: 8.5 - coverage: none - - # Setup Composer - - name: Setup Composer - run: composer install - - # Build documentation - - name: Build documentation - run: composer docs - - # Deploy documentation - - name: Deploy documentation - uses: JamesIves/github-pages-deploy-action@v4 - with: - branch: gh-pages - folder: build/docs - clean: true diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..ddae75a --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,39 @@ +# Security Policy + +## Supported versions + +Security fixes land on the latest tagged release of this package. Older +tags are not patched. + +## Reporting a vulnerability + +Report privately, never in a public issue: open a +[security advisory](../../security/advisories/new) on this repository, or +write to **security@kommasofthouse.com**. + +Please include the affected version, the steps to reproduce it, and what +an attacker could obtain or alter. A proof of concept helps, but a clear +description is enough. + +What to expect: + +- Acknowledgement within 3 working days. +- An assessment, with severity and a fix window, within 10 working days. +- Credit in the release notes when the fix ships, unless you prefer not to + be named. + +Please give us a reasonable window to release a fix before disclosing +publicly. + +## Scope + +This package builds, signs or submits fiscal documents to a Spanish tax +administration. Reports about the following are especially welcome: + +- Anything that lets a signed or chained record be altered without the + signature or hash changing. +- Anything that exposes certificates, private keys or passphrases in + storage, logs or responses. +- Injection or path traversal reachable from user-supplied invoice data. + +Out of scope: vulnerabilities in the tax administrations' own services.