17 Commits

Author SHA1 Message Date
hikari 4437762002 chore: replace .npmrc with pnpm-workspace.yaml
Node.js CI / CI (push) Failing after 17s
Security Scan and Upload / Security & DefectDojo Upload (push) Failing after 14m33s
2026-03-02 16:28:54 -08:00
hikari f9761d19e1 docs: update feedback section to use support forum
Node.js CI / CI (push) Failing after 9s
Security Scan and Upload / Security & DefectDojo Upload (push) Successful in 1m32s
2026-01-26 12:37:45 -08:00
naomi 0178959397 feat: automated upload of .gitea/workflows/ci.yml
Node.js CI / CI (push) Failing after 10s
Security Scan and Upload / Security & DefectDojo Upload (push) Successful in 1m1s
2025-12-22 19:43:27 +01:00
naomi ec9fe32c88 feat: automated upload of .gitea/workflows/ci.yml
Node.js CI / CI (push) Has been cancelled
Security Scan and Upload / Security & DefectDojo Upload (push) Has been cancelled
2025-12-22 19:36:57 +01:00
naomi a0d814dbb1 feat: automated upload of .gitea/workflows/ci.yml
Node.js CI / Lint and Test (push) Has been cancelled
Security Scan and Upload / Security & DefectDojo Upload (push) Has been cancelled
2025-12-22 19:26:36 +01:00
naomi a06e61b48f feat: automated upload of .npmrc
Node.js CI / Lint and Test (push) Has been cancelled
Security Scan and Upload / Security & DefectDojo Upload (push) Has been cancelled
2025-12-22 19:17:27 +01:00
naomi 13567644ff feat: automated upload of .gitea/workflows/security.yml
Node.js CI / Lint and Test (push) Successful in 19s
Security Scan and Upload / Security & DefectDojo Upload (push) Successful in 1m39s
2025-12-18 03:09:53 +01:00
naomi 276cbb845a release: v0.0.6
Node.js CI / Lint and Test (push) Successful in 29s
2025-10-08 15:06:14 -07:00
naomi 9afe0d55c2 fix: cron every day not hour 2025-10-08 15:05:56 -07:00
naomi a6ab06eac4 release: v0.0.5
Node.js CI / Lint and Test (push) Successful in 34s
2025-10-07 18:10:45 -07:00
naomi db4d125613 feat: no flatten at all, let the analytic server handle that 2025-10-07 18:10:26 -07:00
naomi 113afe9d11 release: v0.0.4
Node.js CI / Lint and Test (push) Successful in 35s
2025-10-07 18:06:50 -07:00
naomi ebf60041ad fix: use someone else's flatten package 2025-10-07 18:06:02 -07:00
naomi 351810856a release: v0.0.3 2025-10-07 17:43:18 -07:00
naomi 6c08d431b7 chore(tools): lint and build before publishing 2025-10-07 17:42:56 -07:00
naomi 7ee03a413d release: v0.0.2 2025-10-07 17:40:38 -07:00
naomi f838a89663 feat: user-provided logger 2025-10-07 17:40:19 -07:00
6 changed files with 229 additions and 80 deletions
+14 -5
View File
@@ -8,22 +8,31 @@ on:
- main
jobs:
lint:
name: Lint and Test
ci:
name: CI
runs-on: ubuntu-latest
steps:
- name: Checkout Source Files
uses: actions/checkout@v4
- name: Use Node.js v22
- name: Use Node.js v24
uses: actions/setup-node@v4
with:
node-version: 22
node-version: 24
- name: Setup pnpm
uses: pnpm/action-setup@v2
with:
version: 9
version: 10
- name: Ensure Dependencies are Pinned
uses: naomi-lgbt/dependency-pin-check@main
with:
language: javascript
dev-dependencies: true
peer-dependencies: true
optional-dependencies: true
- name: Install Dependencies
run: pnpm install
+177
View File
@@ -0,0 +1,177 @@
name: Security Scan and Upload
on:
push:
branches: [ main ]
pull_request:
branches: [ main ]
schedule:
- cron: '0 0 * * 1'
workflow_dispatch:
jobs:
security-audit:
name: Security & DefectDojo Upload
runs-on: ubuntu-latest
continue-on-error: true
steps:
- name: Checkout code
uses: actions/checkout@v4
# --- AUTO-SETUP PROJECT ---
- name: Ensure DefectDojo Product Exists
env:
DD_URL: ${{ secrets.DD_URL }}
DD_TOKEN: ${{ secrets.DD_TOKEN }}
PRODUCT_NAME: ${{ github.repository }}
PRODUCT_TYPE_ID: 1
run: |
sudo apt-get install jq -y > /dev/null
echo "Checking connection to $DD_URL..."
# Check if product exists - capture HTTP code to debug connection issues
RESPONSE=$(curl --write-out "%{http_code}" --silent --output /tmp/response.json \
-H "Authorization: Token $DD_TOKEN" \
"$DD_URL/api/v2/products/?name=$PRODUCT_NAME")
# If response is not 200, print error
if [ "$RESPONSE" != "200" ]; then
echo "::error::Failed to query DefectDojo. HTTP Code: $RESPONSE"
cat /tmp/response.json
exit 1
fi
COUNT=$(cat /tmp/response.json | jq -r '.count')
if [ "$COUNT" = "0" ]; then
echo "Creating product '$PRODUCT_NAME'..."
curl -s -X POST "$DD_URL/api/v2/products/" \
-H "Authorization: Token $DD_TOKEN" \
-H "Content-Type: application/json" \
-d '{ "name": "'"$PRODUCT_NAME"'", "description": "Auto-created by Gitea Actions", "prod_type": '$PRODUCT_TYPE_ID' }'
else
echo "Product '$PRODUCT_NAME' already exists."
fi
# --- 1. TRIVY (Dependencies & Misconfig) ---
- name: Install Trivy
run: |
sudo apt-get install wget apt-transport-https gnupg lsb-release -y
wget -qO - https://aquasecurity.github.io/trivy-repo/deb/public.key | sudo apt-key add -
echo "deb https://aquasecurity.github.io/trivy-repo/deb $(lsb_release -sc) main" | sudo tee -a /etc/apt/sources.list.d/trivy.list
sudo apt-get update && sudo apt-get install trivy -y
- name: Run Trivy (FS Scan)
run: |
trivy fs . --scanners vuln,misconfig --format json --output trivy-results.json --exit-code 0
- name: Upload Trivy to DefectDojo
env:
DD_URL: ${{ secrets.DD_URL }}
DD_TOKEN: ${{ secrets.DD_TOKEN }}
run: |
echo "Uploading Trivy results..."
# Generate today's date in YYYY-MM-DD format
TODAY=$(date +%Y-%m-%d)
HTTP_CODE=$(curl --write-out "%{http_code}" --output response.txt --silent -X POST "$DD_URL/api/v2/import-scan/" \
-H "Authorization: Token $DD_TOKEN" \
-F "active=true" \
-F "verified=true" \
-F "scan_type=Trivy Scan" \
-F "engagement_name=CI/CD Pipeline" \
-F "product_name=${{ github.repository }}" \
-F "scan_date=$TODAY" \
-F "auto_create_context=true" \
-F "file=@trivy-results.json")
if [[ "$HTTP_CODE" != "200" && "$HTTP_CODE" != "201" ]]; then
echo "::error::Upload Failed with HTTP $HTTP_CODE"
echo "--- SERVER RESPONSE ---"
cat response.txt
echo "-----------------------"
exit 1
else
echo "Upload Success!"
fi
# --- 2. GITLEAKS (Secrets) ---
- name: Install Gitleaks
run: |
wget -qO gitleaks.tar.gz https://github.com/gitleaks/gitleaks/releases/download/v8.18.0/gitleaks_8.18.0_linux_x64.tar.gz
tar -xzf gitleaks.tar.gz
sudo mv gitleaks /usr/local/bin/ && chmod +x /usr/local/bin/gitleaks
- name: Run Gitleaks
run: gitleaks detect --source . -v --report-path gitleaks-results.json --report-format json --no-git || true
- name: Upload Gitleaks to DefectDojo
env:
DD_URL: ${{ secrets.DD_URL }}
DD_TOKEN: ${{ secrets.DD_TOKEN }}
run: |
echo "Uploading Gitleaks results..."
TODAY=$(date +%Y-%m-%d)
HTTP_CODE=$(curl --write-out "%{http_code}" --output response.txt --silent -X POST "$DD_URL/api/v2/import-scan/" \
-H "Authorization: Token $DD_TOKEN" \
-F "active=true" \
-F "verified=true" \
-F "scan_type=Gitleaks Scan" \
-F "engagement_name=CI/CD Pipeline" \
-F "product_name=${{ github.repository }}" \
-F "scan_date=$TODAY" \
-F "auto_create_context=true" \
-F "file=@gitleaks-results.json")
if [[ "$HTTP_CODE" != "200" && "$HTTP_CODE" != "201" ]]; then
echo "::error::Upload Failed with HTTP $HTTP_CODE"
echo "--- SERVER RESPONSE ---"
cat response.txt
echo "-----------------------"
exit 1
else
echo "Upload Success!"
fi
# --- 3. SEMGREP (SAST) ---
- name: Install Semgrep (via pipx)
run: |
sudo apt-get install pipx -y
pipx install semgrep
# Add pipx binary path to GITHUB_PATH so next steps can see 'semgrep'
echo "$HOME/.local/bin" >> $GITHUB_PATH
- name: Run Semgrep
run: semgrep scan --config=p/security-audit --config=p/owasp-top-ten --json --output semgrep-results.json . || true
- name: Upload Semgrep to DefectDojo
env:
DD_URL: ${{ secrets.DD_URL }}
DD_TOKEN: ${{ secrets.DD_TOKEN }}
run: |
echo "Uploading Semgrep results..."
TODAY=$(date +%Y-%m-%d)
HTTP_CODE=$(curl --write-out "%{http_code}" --output response.txt --silent -X POST "$DD_URL/api/v2/import-scan/" \
-H "Authorization: Token $DD_TOKEN" \
-F "active=true" \
-F "verified=true" \
-F "scan_type=Semgrep JSON Report" \
-F "engagement_name=CI/CD Pipeline" \
-F "product_name=${{ github.repository }}" \
-F "scan_date=$TODAY" \
-F "auto_create_context=true" \
-F "file=@semgrep-results.json")
if [[ "$HTTP_CODE" != "200" && "$HTTP_CODE" != "201" ]]; then
echo "::error::Upload Failed with HTTP $HTTP_CODE"
echo "--- SERVER RESPONSE ---"
cat response.txt
echo "-----------------------"
exit 1
else
echo "Upload Success!"
fi
+1 -1
View File
@@ -8,7 +8,7 @@ This page is currently deployed. [View the live website.](https://www.npmjs.com/
## Feedback and Bugs
If you have feedback or a bug report, please feel free to open a GitHub issue!
If you have feedback or a bug report, please [log a ticket on our forum](https://support.nhcarrigan.com).
## Contributing
+4 -3
View File
@@ -1,11 +1,12 @@
{
"name": "@nhcarrigan/discord-analytics",
"version": "0.0.1",
"version": "0.0.6",
"description": "Package that pairs with our logging tool to provide analytics for our Discord bots.",
"type": "module",
"private": false,
"main": "prod/index.js",
"scripts": {
"prepublish": "pnpm run lint && pnpm run build",
"lint": "eslint src --max-warnings 0",
"build": "rm -rf prod && tsc",
"test": "echo \"Error: no test specified\" && exit 0"
@@ -23,8 +24,8 @@
"typescript": "5.9.3"
},
"peerDependencies": {
"discord.js": "^14.0.0",
"@nhcarrigan/logger": ">=1.1.0-hotfix"
"@nhcarrigan/logger": ">=1.1.0-hotfix",
"discord.js": "^14.0.0"
},
"dependencies": {
"node-schedule": "2.1.1"
+21
View File
@@ -0,0 +1,21 @@
# Security
# Do not execute any scripts of installed packages (project scripts still run)
ignoreDepScripts: true
# Do not automatically run pre/post scripts (e.g. preinstall, postbuild)
enablePrePostScripts: false
# Only allow packages published at least 10 days ago (reduces risk of compromised packages)
minimumReleaseAge: 14400
# Fail if a package's trust level has decreased compared to previous releases
trustPolicy: no-downgrade
# Ignore trust policy for packages published more than 1 year ago (predates provenance signing)
trustPolicyIgnoreAfter: 525960
# Fail if there are missing or invalid peer dependencies
strictPeerDependencies: true
# Prevent transitive dependencies from using exotic sources (git repos, direct tarball URLs)
blockExoticSubdeps: true
# Lockfile
# Allow the lockfile to be updated during install (set to true in CI for stricter reproducibility)
preferFrozenLockfile: false
+11 -70
View File
@@ -4,89 +4,25 @@
* @author Naomi Carrigan
*/
import { Logger } from "@nhcarrigan/logger";
import { scheduleJob, type Job } from "node-schedule";
import type { Logger } from "@nhcarrigan/logger";
import type { Events, Client } from "discord.js";
// eslint-disable-next-line complexity, max-lines-per-function, max-statements -- Justified
const flatten = (
object: Record<string, unknown>,
): Record<string, string | number | boolean> => {
const result: Record<string, string | number | boolean> = {};
for (const key in object) {
const value = object[key];
if (value === null || value === undefined) {
continue;
}
if (
typeof value === "string"
|| typeof value === "number"
|| typeof value === "boolean"
) {
result[key] = value;
continue;
}
if (typeof value === "object" && !Array.isArray(value)) {
// eslint-disable-next-line @typescript-eslint/consistent-type-assertions -- Justified
const nested = flatten(value as Record<string, unknown>);
for (const nestedKey in nested) {
const nestedValue = nested[nestedKey];
if (nestedValue === undefined) {
continue;
}
result[`${key}_${nestedKey}`] = nestedValue;
}
continue;
}
if (Array.isArray(value)) {
for (const [ index, arrayValue ] of value.entries()) {
if (
typeof arrayValue === "string"
|| typeof arrayValue === "number"
|| typeof arrayValue === "boolean"
) {
result[`${key}_${index.toString()}`] = arrayValue;
continue;
}
if (typeof arrayValue === "object" && arrayValue !== null) {
// eslint-disable-next-line @typescript-eslint/consistent-type-assertions -- Justified
const nested = flatten(arrayValue as Record<string, unknown>);
for (const nestedKey in nested) {
const nestedValue = nested[nestedKey];
// eslint-disable-next-line max-depth -- Justified
if (nestedValue === undefined) {
continue;
}
result[`${key}_${index.toString()}_${nestedKey}`] = nestedValue;
}
}
}
continue;
}
}
return result;
};
/**
* A class for logging Discord bot analytics.
*/
export class DiscordAnalytics {
private readonly logger: Logger;
private job: Job | null = null;
/**
* Creates a new instance of the DiscordAnalytics class.
* @param client -- The Discord client to monitor.
* @param name -- The name of the application.
* @param logToken -- Auth token for our logging service.
* @param logger -- Instance of @nhcarrigan/logger to use for logging.
*/
public constructor(
private readonly client: Client,
name: string,
logToken: string,
) {
this.logger = new Logger(name, logToken);
}
private readonly logger: Logger,
) {}
/**
* Starts a CRON job to run at midnight (system time) daily.
@@ -98,7 +34,7 @@ export class DiscordAnalytics {
if (this.job) {
return;
}
this.job = scheduleJob("metrics", "0 * * * *", async() => {
this.job = scheduleJob("metrics", "0 0 * * *", async() => {
try {
const fakeGuilds = await this.client.guilds.fetch();
const guilds = await Promise.all(
@@ -150,6 +86,11 @@ export class DiscordAnalytics {
event: Events,
payload: Record<string, unknown>,
): Promise<void> {
await this.logger.metric(event, 1, flatten(payload));
await this.logger.metric(
event,
1,
// eslint-disable-next-line @typescript-eslint/consistent-type-assertions -- We want to cast this to a specific type.
payload as Record<string, string | number>,
);
}
}