Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
204 commits
Select commit Hold shift + click to select a range
bc51605
Fix #92: Detail tabs now update correctly when switching between enti…
github-actions[bot] Apr 17, 2026
5e976f7
Fix #94: Org Chart now shows all departments when scrolled
github-actions[bot] Apr 17, 2026
7b28d5f
Fix #96: Display Extended Attributes objects as formatted JSON instea…
github-actions[bot] Apr 17, 2026
dfdd122
Merge branch 'main' into bugfixes/autofix-issue-92-switching-between-…
TaekeK Apr 17, 2026
31f7acb
Merge pull request #93 from Fortigi/bugfixes/autofix-issue-92-switchi…
TaekeK Apr 17, 2026
58a2e74
Merge branch 'main' into bugfixes/autofix-issue-94-org-chart-ui-does-…
TaekeK Apr 17, 2026
0dac1c0
Merge branch 'main' into bugfixes/autofix-issue-96-sign-in-activity-d…
TaekeK Apr 17, 2026
af0a56a
Merge pull request #95 from Fortigi/bugfixes/autofix-issue-94-org-cha…
TaekeK Apr 17, 2026
5ae37b7
Merge branch 'main' into bugfixes/autofix-issue-96-sign-in-activity-d…
TaekeK Apr 17, 2026
813e6bb
Merge pull request #97 from Fortigi/bugfixes/autofix-issue-96-sign-in…
TaekeK Apr 17, 2026
305af67
Fix bump-version workflow to use VERSION_BUMP_PAT to bypass branch pr…
Apr 17, 2026
2cc2c21
Add changelog fragment for bump-version PAT fix
Apr 17, 2026
3a0df9b
Merge pull request #99 from Fortigi/bugfixes/fix-bump-version-pat
TaekeK Apr 17, 2026
c9cb6b7
chore: bump version to 5.1.20260417.1306
github-actions[bot] Apr 17, 2026
91b6e54
feat: add stable release branch strategy with edge/latest channels
Apr 17, 2026
8f2bb3c
Merge pull request #102 from Fortigi/feature/release-branch-strategy
WimvandenHeijkant Apr 18, 2026
7ff0c84
chore: bump version to 5.2.20260418.0620
github-actions[bot] Apr 18, 2026
db77ce1
Fix Users/Resources filter dropdown after Postgres migration
WimvandenHeijkant Apr 18, 2026
8313cf0
Add regression tests for column discovery casing
WimvandenHeijkant Apr 18, 2026
43f1750
Allow filtering on extendedAttributes keys
WimvandenHeijkant Apr 18, 2026
584f2e4
Merge pull request #103 from Fortigi/bugfixes/fix-user-resource-filte…
TaekeK Apr 18, 2026
f6ccbf3
chore: bump version to 5.3.20260418.1029
github-actions[bot] Apr 18, 2026
f86d036
Sync Entra service principals as Principals
WimvandenHeijkant Apr 18, 2026
2fdc24b
Detect Entra Agent ID SPs as AIAgent
WimvandenHeijkant Apr 18, 2026
ffaea49
Add principalType sub-tabs to the Users page
WimvandenHeijkant Apr 18, 2026
6c326e9
Show principalType filter on the 'All' users tab
WimvandenHeijkant Apr 18, 2026
8c0903c
Raise ingest body limit to 50MB
WimvandenHeijkant Apr 18, 2026
ee9f7cf
Add Excel Power Query workbook export
WimvandenHeijkant Apr 19, 2026
274eeb6
bugfix: use portable [0-9] instead of \d in cut-release version regex
TaekeK Apr 19, 2026
47efe13
Merge pull request #107 from Fortigi/bugfixes/fix-cut-release-version…
TaekeK Apr 19, 2026
62b0431
chore: bump version to 5.4.20260419.0803
github-actions[bot] Apr 19, 2026
f0aef7c
Merge pull request #105 from Fortigi/feature/entraid-service-principals
TaekeK Apr 19, 2026
86b7fb1
chore: bump version to 5.5.20260419.0804
github-actions[bot] Apr 19, 2026
f9fa78c
feat: add About page with license and software BOM
TaekeK Apr 19, 2026
14ed718
fix: restore full copyright line in About page to match LICENSE file
TaekeK Apr 19, 2026
db80514
docs: documentation consistency pass
TaekeK Apr 19, 2026
990f5cf
feat: replace release branches with tag-based release model
TaekeK Apr 19, 2026
5fe62d8
docs: update release model documentation for tag-based releases
TaekeK Apr 19, 2026
79f8587
Merge pull request #108 from Fortigi/feature/about-page-sbom
WimvandenHeijkant Apr 19, 2026
e8ad596
chore: bump version to 5.6.20260419.0909
github-actions[bot] Apr 19, 2026
c2394f3
Merge branch 'main' into feature/docs-consistency-pass
WimvandenHeijkant Apr 19, 2026
eb9f50a
Merge pull request #110 from Fortigi/feature/docs-consistency-pass
WimvandenHeijkant Apr 19, 2026
64aee60
chore: bump version to 5.7.20260419.0910
github-actions[bot] Apr 19, 2026
0e3db5c
Merge branch 'main' into feature/tag-based-releases
WimvandenHeijkant Apr 19, 2026
f74fbd9
Merge pull request #112 from Fortigi/feature/tag-based-releases
WimvandenHeijkant Apr 19, 2026
76ba27f
chore: bump version to 5.8.20260419.0912
github-actions[bot] Apr 19, 2026
6c1f76b
docs: add Release & Branching Strategy to mkdocs nav
TaekeK Apr 19, 2026
95be93f
Merge pull request #113 from Fortigi/feature/mkdocs-branching-strateg…
TaekeK Apr 19, 2026
bab0a30
chore: bump version to 5.9.20260419.0919
github-actions[bot] Apr 19, 2026
f4d18a8
feat: move About page from main nav into Admin sub-tab
TaekeK Apr 19, 2026
7918118
Import useCallback used by PowerQueryExportSection
WimvandenHeijkant Apr 19, 2026
953b54c
Fix #115: Add Windows PowerShell syntax for switching to edge image c…
github-actions[bot] Apr 19, 2026
5b39c86
Merge pull request #114 from Fortigi/feature/about-in-admin
WimvandenHeijkant Apr 19, 2026
fb61d16
chore: bump version to 5.10.20260419.1050
github-actions[bot] Apr 19, 2026
46b568c
Fix pagination cap + auto-expand extendedAttributes in M code
WimvandenHeijkant Apr 19, 2026
0767980
Return extendedAttributes (and the rest) on /users and /resources
WimvandenHeijkant Apr 19, 2026
6b56ed2
Raise /users + /resources page cap to 10k; harden M to track actual rows
WimvandenHeijkant Apr 19, 2026
100d0b7
Emit the tail partial page (7,000 → 7,911 on Principals)
WimvandenHeijkant Apr 19, 2026
64ac867
Escape backticks in M-comment JS template literal
WimvandenHeijkant Apr 19, 2026
ffce645
Docs + auth-middleware test for the Power Query feature
WimvandenHeijkant Apr 19, 2026
052a346
docs
WimvandenHeijkant Apr 19, 2026
cb7a4be
Merge branch 'main' into feature/excel-powerquery-export
WimvandenHeijkant Apr 19, 2026
bc0d1db
Merge pull request #116 from Fortigi/bugfixes/autofix-issue-115-quick…
TaekeK Apr 19, 2026
414258e
chore: bump version to 5.11.20260419.1409
github-actions[bot] Apr 19, 2026
1aca5c1
fix: docker-publish workflow not triggering after PR merges to main
TaekeK Apr 19, 2026
42fdb97
Merge pull request #117 from Fortigi/bugfixes/fix-docker-publish-trigger
WimvandenHeijkant Apr 19, 2026
ca07a72
chore: bump version to 5.12.20260419.1437
github-actions[bot] Apr 19, 2026
6cf337e
Merge branch 'main' into feature/excel-powerquery-export
WimvandenHeijkant Apr 20, 2026
d3088dc
Merge pull request #106 from Fortigi/feature/excel-powerquery-export
WimvandenHeijkant Apr 20, 2026
879b919
chore: bump version to 5.13.20260420.0626
github-actions[bot] Apr 20, 2026
8f3f840
Add calculated Link + OuPath fields to Entra-synced objects
WimvandenHeijkant Apr 20, 2026
52f2e99
Abort orphaned crawls on server-side 409 (self-heal)
WimvandenHeijkant Apr 20, 2026
92ec5ce
Add per-phase timing to the Entra ID crawler
WimvandenHeijkant Apr 20, 2026
0ca89c0
Replace hardcoded "Open in Entra ID" button with clickable ext.Link
WimvandenHeijkant Apr 20, 2026
284cf89
Merge pull request #119 from Fortigi/feature/entra-calculated-attrs
TaekeK Apr 20, 2026
09f27fc
chore: bump version to 5.14.20260420.1129
github-actions[bot] Apr 20, 2026
7c17c7c
Merge pull request #124 from Fortigi/feature/entra-portal-link-from-data
TaekeK Apr 20, 2026
59b0028
Match running crawler jobs to their config, not their type
WimvandenHeijkant Apr 20, 2026
43a00c4
Render one progress card per running crawler, not one shared card
WimvandenHeijkant Apr 20, 2026
d6aab01
Add PrincipalActivity table + user/SP/sign-in-log activity sync
WimvandenHeijkant Apr 19, 2026
efe5417
Adding OAuthGrants
WimvandenHeijkant Apr 19, 2026
c1b9a4d
Merge pull request #125 from Fortigi/feature/entra-calculated-attrs
WimvandenHeijkant Apr 20, 2026
f0742b6
chore: bump version to 5.15.20260420.1311
github-actions[bot] Apr 20, 2026
c4e95a9
context redesign docs
WimvandenHeijkant Apr 21, 2026
352205c
Phase 1 — context redesign schema + core API
WimvandenHeijkant Apr 21, 2026
2c049fd
Phase 2 — crawler integration for v6 contexts
WimvandenHeijkant Apr 21, 2026
82af2f6
Phase 3 — context-algorithm plugin framework + two initial plugins
WimvandenHeijkant Apr 21, 2026
6fe906f
Phase 4 — Contexts UI foundations
WimvandenHeijkant Apr 21, 2026
40ee054
Phase 5 (WIP) — CreateManualTreeModal component
WimvandenHeijkant Apr 21, 2026
2b194fa
docs: handover note for context-redesign branch
WimvandenHeijkant Apr 21, 2026
545815e
Make HSTS + CSP upgrade-insecure-requests opt-in via BEHIND_TLS=true
WimvandenHeijkant Apr 21, 2026
48816be
Phase 5 — authoring contexts from the UI
WimvandenHeijkant Apr 21, 2026
a0c34a6
Phase 6 — Matrix filtering by context
WimvandenHeijkant Apr 21, 2026
c286e24
Phase 7 — replace Risk-Scoring Clusters with a plugin
WimvandenHeijkant Apr 21, 2026
63b23fa
Phase 8 — tags as contexts
WimvandenHeijkant Apr 21, 2026
a51d3b8
Phase 8 follow-up — supply explicit id in Contexts INSERT
WimvandenHeijkant Apr 21, 2026
1590693
Phase 9 — three more context-algorithm plugins
WimvandenHeijkant Apr 21, 2026
303110d
Phase 10 — cleanup
WimvandenHeijkant Apr 21, 2026
8173fbd
test: correct stem test expectations for env-before-role strip order
WimvandenHeijkant Apr 21, 2026
67c18a0
Phase 6-9 follow-ups — fix plugin runs against real Entra data
WimvandenHeijkant Apr 21, 2026
f7ae150
Plugin fixes part 2 — externalId uniqueness + regex flag stripping
WimvandenHeijkant Apr 21, 2026
ea6a077
Plugin + tree-view polish on top of the Entra run
WimvandenHeijkant Apr 21, 2026
6ab3ee3
feat(ui): entity detail redesign with relationship graph
WimvandenHeijkant Apr 21, 2026
1d2fcfe
fix(api): use email column on Principals for identity assignments
WimvandenHeijkant Apr 21, 2026
d268b1f
Fix #128: Business role assignments not displaying
github-actions[bot] Apr 21, 2026
add26b6
Fix #127: Remove invalid ValidTo filtering from org chart queries
github-actions[bot] Apr 21, 2026
dabfc01
Token-based resource clustering
WimvandenHeijkant Apr 22, 2026
95c5cb0
test: fix tokenize expectations to match stopword set
WimvandenHeijkant Apr 22, 2026
f50cc2a
tokenize: paren/bracket/punct separators + Dutch stopwords + more EN …
WimvandenHeijkant Apr 22, 2026
d3e8de4
test: tokenize NL connectives — 'rol' is tenant-specific, not default
WimvandenHeijkant Apr 22, 2026
4d5fa55
feat: add dark mode to the entire UI
ItsIndig0 Apr 22, 2026
a7cb987
fix(api): make HSTS + CSP upgrade-insecure-requests opt-in via BEHIND…
WimvandenHeijkant Apr 22, 2026
e3a1e93
Manual-context parent picker + delete for generated contexts
WimvandenHeijkant Apr 22, 2026
ede74ac
fix(api): surface displayName/UPN for identity members and quote came…
WimvandenHeijkant Apr 22, 2026
92dbc52
feat(ui): apply entity-detail graph layout to Access Package detail page
WimvandenHeijkant Apr 22, 2026
dfbdadf
docs + tests: resource-cluster algorithm explainer + run() integratio…
WimvandenHeijkant Apr 22, 2026
94a3e7e
Crawler correctness fixes and ingest performance improvements
WimvandenHeijkant Apr 22, 2026
3c3d212
Crawlers: Export / Import configuration as JSON
WimvandenHeijkant Apr 22, 2026
91e5d7e
Gate upgrade-insecure-requests + HSTS behind BEHIND_TLS env var
WimvandenHeijkant Apr 22, 2026
dfef544
style(ui): unify EntityGraph palette to dashboard's lime/green
WimvandenHeijkant Apr 22, 2026
1238c30
Fix /api/users 500 + allow member writes on generated contexts
WimvandenHeijkant Apr 22, 2026
dc79d58
Merge pull request #131 from Fortigi/feature/dark-mode
WimvandenHeijkant Apr 22, 2026
ef5508e
chore: bump version to 5.16.20260422.1245
github-actions[bot] Apr 22, 2026
649a1fd
Merge branch 'main' into bugfixes/autofix-issue-128-business-rollen-t…
WimvandenHeijkant Apr 22, 2026
36955ac
Merge pull request #129 from Fortigi/bugfixes/autofix-issue-128-busin…
WimvandenHeijkant Apr 22, 2026
143f68d
chore: bump version to 5.17.20260422.1255
github-actions[bot] Apr 22, 2026
2c9658f
Merge branch 'main' into bugfixes/autofix-issue-127-niemand-heeft-dir…
WimvandenHeijkant Apr 22, 2026
5296bf6
manager-hierarchy: excludeNamePatterns to drop admin-only managers
WimvandenHeijkant Apr 22, 2026
f51f156
fix(api): quote every mixed-case SQL alias and repair two broken queries
WimvandenHeijkant Apr 22, 2026
4823371
ContextTreeView: rounded pills + tree connectors + variant bubbles
WimvandenHeijkant Apr 22, 2026
3a25cc9
fix(api): remove v4 temporal-table WHERE clauses from orgChart queries
WimvandenHeijkant Apr 22, 2026
880fab9
fix(api): quote Postgres identifiers throughout orgChart queries
WimvandenHeijkant Apr 22, 2026
b6d44f9
Merge pull request #130 from Fortigi/bugfixes/autofix-issue-127-niema…
WimvandenHeijkant Apr 22, 2026
60de89e
chore: bump version to 5.18.20260422.1330
github-actions[bot] Apr 22, 2026
39ab24f
Merge remote-tracking branch 'origin/main' into feature/entity-detail…
WimvandenHeijkant Apr 22, 2026
2ce5191
Merge remote-tracking branch 'origin/main' into feature/context-redesign
WimvandenHeijkant Apr 22, 2026
47aa092
Merge remote-tracking branch 'origin/main' into bugfixes/crawler-fixe…
WimvandenHeijkant Apr 22, 2026
d38ce93
fix(api): drop reintroduced a.id from ap-assignments after merge
WimvandenHeijkant Apr 22, 2026
a892f02
style(ui): add dark mode classes to rewritten entity detail components
WimvandenHeijkant Apr 22, 2026
35e8eef
dark-mode: patch context files kept from feature branch during merge
WimvandenHeijkant Apr 22, 2026
4ec341d
fix(ui): extract attributes from /api/contexts/:id response
WimvandenHeijkant Apr 23, 2026
0abdf84
Drop two plugins + add per-tree delete in the Contexts header
WimvandenHeijkant Apr 23, 2026
8490b3d
Drop department-tree plugin — manager-hierarchy covers the org-chart …
WimvandenHeijkant Apr 23, 2026
7544556
feat(identities): simplify Identities tab into a Resources-style tag/…
WimvandenHeijkant Apr 23, 2026
a687e5b
Unified ContextPicker — same UX in parent picker + matrix filter
WimvandenHeijkant Apr 23, 2026
6a6612a
Group all Tag contexts under a synthetic "Tags" root per targetType
WimvandenHeijkant Apr 23, 2026
0a57c5b
Fix: tag assign/unassign didn't refresh directMember/totalMember counts
WimvandenHeijkant Apr 23, 2026
1a87c2b
feat(ui): fan out the entity-detail graph when a node is clicked
WimvandenHeijkant Apr 23, 2026
5fc216f
Fix scheduled crawler failures: delta upserts, visibility, resilience
WimvandenHeijkant Apr 23, 2026
a263cd9
feat(ui): recent-changes timeline + graph styling for relationship ch…
WimvandenHeijkant Apr 23, 2026
2fe438c
Merge pull request #133 from Fortigi/feature/entity-detail-graphs
WimvandenHeijkant Apr 23, 2026
74028f2
chore: bump version to 5.19.20260423.0827
github-actions[bot] Apr 23, 2026
1443a42
Merge remote-tracking branch 'origin/main' into feature/context-redesign
WimvandenHeijkant Apr 23, 2026
4d0af6d
Merge remote-tracking branch 'origin/main' into bugfixes/crawler-fixe…
WimvandenHeijkant Apr 23, 2026
8c9863a
Fix entity-detail attributes layout + restore /api/org-chart for graph
WimvandenHeijkant Apr 23, 2026
796eeef
Entity-detail graph: many-to-many context links (v6)
WimvandenHeijkant Apr 23, 2026
a2e0cfa
AttributesTable: remove max-h scroll, let the panel grow naturally
WimvandenHeijkant Apr 23, 2026
6d545cc
EntityGraph: pan + wheel zoom + Reset view
WimvandenHeijkant Apr 23, 2026
5cd2122
test: add memberCounts + tag-roots unit tests
WimvandenHeijkant Apr 23, 2026
fea52f8
docs: rewrite changelog to match what actually shipped
WimvandenHeijkant Apr 23, 2026
5807fab
fix(ui): EntityGraph pan/zoom — drop useCallback wrappers so React Co…
WimvandenHeijkant Apr 23, 2026
7b16453
fix(tests): demo dataset v6 schema + Playwright nav strict-mode
WimvandenHeijkant Apr 23, 2026
1b9806c
fix(e2e): matrix.spec navigates to #matrix in beforeEach
WimvandenHeijkant Apr 23, 2026
65bf9e7
fix(matrix): push context filter into top-N subquery
WimvandenHeijkant Apr 23, 2026
a2ef0c3
fix(e2e): matrix filter test asserts <select> visibility, not option …
WimvandenHeijkant Apr 23, 2026
1b63a67
fix(ui): show full context displayName on mouseover
WimvandenHeijkant Apr 23, 2026
e0326e6
Merge pull request #134 from Fortigi/feature/context-redesign
WimvandenHeijkant Apr 23, 2026
1892252
chore: bump version to 5.20.20260423.1145
github-actions[bot] Apr 23, 2026
cc9ed9c
Merge remote-tracking branch 'origin/main' into bugfixes/crawler-fixe…
WimvandenHeijkant Apr 23, 2026
2669df1
docs: Sizing guide — RAM/disk by tenant shape, activity as growth driver
WimvandenHeijkant Apr 23, 2026
f4bc471
Crawler Trace tab: live transcript capture per job
WimvandenHeijkant Apr 23, 2026
249a65e
Fix AccessReviews phase dropping every definition
WimvandenHeijkant Apr 23, 2026
b8b80b0
Drop \$top=999 on /accessReviews/decisions — Graph caps at 100
WimvandenHeijkant Apr 23, 2026
3253539
Reach the Trace tab on running jobs + heartbeat AccessReviews progress
WimvandenHeijkant Apr 23, 2026
1c0f364
Fix "records must be an array" on 1-item delta batches
WimvandenHeijkant Apr 24, 2026
42a6531
Per-schedule full/delta + Mode badge on jobs
WimvandenHeijkant Apr 24, 2026
1c1b6c3
Run Delta / Run Full buttons, drop the force-full toggle
WimvandenHeijkant Apr 24, 2026
12245a1
Update stale validateEnvelope test for null-records leniency
WimvandenHeijkant Apr 24, 2026
b7392e2
Merge pull request #135 from Fortigi/bugfixes/crawler-fixes-and-perf
WimvandenHeijkant Apr 24, 2026
c4f8676
chore: bump version to 5.21.20260424.0802
github-actions[bot] Apr 24, 2026
a576a26
fix: point What is new link to installed version changelog
TaekeK Apr 30, 2026
14070ec
Merge pull request #137 from Fortigi/bugfixes/fix-whats-new-link-to-main
TaekeK Apr 30, 2026
34835be
chore: bump version to 5.22.20260430.1104
github-actions[bot] Apr 30, 2026
ec56147
Fix #138: version link now navigates to Admin->About from admin pages
github-actions[bot] Apr 30, 2026
b8a8ce2
Fix #138: address CI failures
github-actions[bot] Apr 30, 2026
dff75e9
Merge pull request #139 from Fortigi/bugfixes/autofix-issue-138-ident…
TaekeK Apr 30, 2026
ce4ae48
chore: bump version to 5.23.20260430.1132
github-actions[bot] Apr 30, 2026
36284a6
chore: update GitHub Actions to Node.js 24 runtime
TaekeK Apr 30, 2026
7baf857
Merge pull request #141 from Fortigi/bugfixes/fix-whats-new-link-to-main
TaekeK Apr 30, 2026
c731a10
chore: bump version to 5.24.20260430.1224
github-actions[bot] Apr 30, 2026
c89fbf6
feat: add CodeQL static analysis on PRs (#142)
TaekeK Apr 30, 2026
cc21e68
chore: bump version to 5.25.20260430.1406
github-actions[bot] Apr 30, 2026
0f120d4
feat: use GitHub App token for CI automation pushes (#143)
TaekeK Apr 30, 2026
effc789
chore: bump version to 5.26.20260430.1421
github-actions[bot] Apr 30, 2026
aed951e
chore: normalize line endings to LF via .gitattributes (#145)
TaekeK May 4, 2026
5c6092d
chore: bump version to 5.27.20260504.0804
github-actions[bot] May 4, 2026
605b711
feat: three-way theme toggle (Light/Auto/Dark) + WCAG 2.0 tag colors …
TaekeK May 12, 2026
93dcf74
chore: bump version to 5.28.20260512.0922
github-actions[bot] May 12, 2026
ecaa2f0
docs: split CLAUDE.md into per-area subdirectory guides (#144)
TaekeK May 12, 2026
ff353a7
chore: bump version to 5.29.20260512.0951
github-actions[bot] May 12, 2026
ef6a93b
Matrix: all assignment types + Entra app-roles + postgres-migration c…
WimvandenHeijkant May 18, 2026
3a499d4
chore: bump version to 5.30.20260518.1154
github-actions[bot] May 18, 2026
70d0cd4
Dashboard: Trends tab with daily snapshots + % governed over time (#149)
WimvandenHeijkant May 18, 2026
2fb2d08
chore: bump version to 5.31.20260518.1457
github-actions[bot] May 18, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
# Normalize all text files to LF in the repo and working tree.
# git's auto-detection keeps binary files untouched.
* text=auto eol=lf
24 changes: 17 additions & 7 deletions .github/workflows/bump-version.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,23 +2,26 @@
# On every PR merge to main this workflow:
# 1. Collects all fragment files from changes/*.md and prepends them to
# CHANGES.md, then deletes the fragments.
# 2. Increments the Minor version in setup/IdentityAtlas.psd1 and updates
# the timestamp.
# 2. Increments Minor and updates the timestamp → Major.Minor.yyyyMMdd.HHmm
#
# Branches never touch CHANGES.md or the version file directly — each branch
# creates a uniquely named fragment file in changes/ instead, so merge
# conflicts on those two files are eliminated.
#
# After the commit lands, docker-publish.yml is triggered via workflow_run
# so Docker images are always tagged with the new (post-bump) version.
# so Docker images are always tagged with the new (post-bump) version (:edge).
#
# Releases are handled separately via git tags (Actions → Cut Release),
# not by this workflow.
# ─────────────────────────────────────────────────────────────────────────────

name: Bump version on PR merge

on:
pull_request:
types: [closed]
branches: [main]
branches:
- main

jobs:
bump-version:
Expand All @@ -28,10 +31,17 @@ jobs:
contents: write

steps:
- uses: actions/checkout@v4
- name: Generate bot token
id: bot-token
uses: actions/create-github-app-token@v1
with:
app-id: ${{ secrets.BOT_APP_ID }}
private-key: ${{ secrets.BOT_PRIVATE_KEY }}

- uses: actions/checkout@v6
with:
ref: main
token: ${{ secrets.GITHUB_TOKEN }}
token: ${{ steps.bot-token.outputs.token }}

- name: Merge changelog fragments and bump version
shell: pwsh
Expand All @@ -49,7 +59,7 @@ jobs:
Write-Host "No changelog fragments found in changes/ -- skipping CHANGES.md update"
}

# ── 2. Bump Minor version in setup/IdentityAtlas.psd1 ─────────────
# ── 2. Increment Minor + update timestamp → Major.Minor.yyyyMMdd.HHmm
$content = Get-Content setup/IdentityAtlas.psd1 -Raw
if ($content -match "ModuleVersion\s*=\s*'(\d+)\.(\d+)\.\d+\.\d+'") {
$major = $Matches[1]
Expand Down
35 changes: 35 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
name: CodeQL

on:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
- cron: '0 2 * * 1' # Weekly on Monday at 02:00 UTC

jobs:
analyze:
name: Analyze (javascript)
runs-on: ubuntu-latest
permissions:
security-events: write
actions: read
contents: read

steps:
- uses: actions/checkout@v6

- name: Initialize CodeQL
uses: github/codeql-action/init@v4
with:
languages: javascript-typescript
queries: security-and-quality

- name: Autobuild
uses: github/codeql-action/autobuild@v4

- name: Perform CodeQL analysis
uses: github/codeql-action/analyze@v4
with:
category: /language:javascript-typescript
85 changes: 85 additions & 0 deletions .github/workflows/cut-hotfix.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,85 @@
# ─── Cut a Hotfix Release ─────────────────────────────────────────────────────
# Manually triggered. Tags the HEAD of a hotfix branch with a new patch version,
# triggering docker-publish to build :latest + :X.Y.Z.0.
#
# Usage:
# 1. git checkout -b bugfixes/fix-foo v5.2.0 ← branch from the release tag
# 2. Fix the bug, push the branch
# 3. Go to Actions → Cut Hotfix → Run workflow
# 4. Enter the branch name and new version (e.g. "5.2.1")
# 5. After the hotfix ships, open a PR to cherry-pick the fix into main
# ─────────────────────────────────────────────────────────────────────────────

name: Cut Hotfix

on:
workflow_dispatch:
inputs:
branch:
description: 'Hotfix branch name (e.g. bugfixes/fix-login-crash)'
required: true
version:
description: 'New version (major.minor.patch, e.g. "5.2.1")'
required: true

jobs:
cut-hotfix:
runs-on: ubuntu-latest
permissions:
contents: write

steps:
- name: Validate version input
run: |
if ! echo "${{ github.event.inputs.version }}" | grep -qE '^[0-9]+\.[0-9]+\.[0-9]+$'; then
echo "::error::Version must be in Major.Minor.Patch format (e.g. 5.2.1)"
exit 1
fi

- name: Generate bot token
id: bot-token
uses: actions/create-github-app-token@v1
with:
app-id: ${{ secrets.BOT_APP_ID }}
private-key: ${{ secrets.BOT_PRIVATE_KEY }}

- uses: actions/checkout@v6
with:
ref: ${{ github.event.inputs.branch }}
token: ${{ steps.bot-token.outputs.token }}

- name: Create and push hotfix tag
run: |
VERSION="${{ github.event.inputs.version }}"
TAG="v${VERSION}"
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
git tag -a "$TAG" -m "Hotfix release $TAG"
git push origin "$TAG"
echo "TAG=$TAG" >> "$GITHUB_ENV"
echo "VERSION=$VERSION" >> "$GITHUB_ENV"
COMMIT=$(git rev-parse --short HEAD)
echo "COMMIT=$COMMIT" >> "$GITHUB_ENV"
echo "✅ Tagged ${TAG} on ${COMMIT}"

- name: Post run summary
run: |
cat >> "$GITHUB_STEP_SUMMARY" << EOF
## ✅ Hotfix tagged

| | |
|---|---|
| **Tag** | \`${TAG}\` |
| **Version** | \`${VERSION}.0\` |
| **Branch** | \`${{ github.event.inputs.branch }}\` |
| **Commit** | \`${COMMIT}\` |

docker-publish is now building \`:latest\` + \`:${VERSION}.0\` — check the [Actions tab](../../actions) for progress.

### Next step — cherry-pick to main
\`\`\`bash
git checkout main && git pull
git cherry-pick ${COMMIT}
gh pr create --base main --title "fix: cherry-pick hotfix from ${TAG}"
\`\`\`
EOF
84 changes: 84 additions & 0 deletions .github/workflows/cut-release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,84 @@
# ─── Cut a Release ────────────────────────────────────────────────────────────
# Manually triggered. Tags the current main HEAD with vX.Y.Z and lets
# docker-publish (triggered by the tag push) build and push :latest + :X.Y.Z.0.
#
# Usage:
# 1. Go to Actions → Cut Release → Run workflow
# 2. Enter the version (e.g. "5.2.0" — major.minor.patch)
# 3. The workflow creates tag v5.2.0 on the current main HEAD
# 4. docker-publish builds and pushes :latest + :5.2.0.0
#
# Hotfixes (shipping a bugfix without including features already on main):
# 1. git checkout -b bugfixes/fix-foo v5.2.0 ← branch from the tag, not main
# 2. Fix the bug, push the branch
# 3. Run Actions → Cut Hotfix with the branch name and new version (e.g. 5.2.1)
# ─────────────────────────────────────────────────────────────────────────────

name: Cut Release

on:
workflow_dispatch:
inputs:
version:
description: 'Release version (major.minor.patch, e.g. "5.2.0")'
required: true

jobs:
cut-release:
runs-on: ubuntu-latest
permissions:
contents: write

steps:
- name: Validate version input
run: |
if ! echo "${{ github.event.inputs.version }}" | grep -qE '^[0-9]+\.[0-9]+\.[0-9]+$'; then
echo "::error::Version must be in Major.Minor.Patch format (e.g. 5.2.0)"
exit 1
fi

- name: Generate bot token
id: bot-token
uses: actions/create-github-app-token@v1
with:
app-id: ${{ secrets.BOT_APP_ID }}
private-key: ${{ secrets.BOT_PRIVATE_KEY }}

- uses: actions/checkout@v6
with:
ref: main
token: ${{ steps.bot-token.outputs.token }}

- name: Create and push release tag
run: |
VERSION="${{ github.event.inputs.version }}"
TAG="v${VERSION}"
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
git tag -a "$TAG" -m "Release $TAG"
git push origin "$TAG"
echo "TAG=$TAG" >> "$GITHUB_ENV"
echo "VERSION=$VERSION" >> "$GITHUB_ENV"
echo "✅ Tagged ${TAG} on $(git rev-parse --short HEAD)"

- name: Post run summary
run: |
cat >> "$GITHUB_STEP_SUMMARY" << EOF
## ✅ Release tagged

| | |
|---|---|
| **Tag** | \`${TAG}\` |
| **Version** | \`${VERSION}.0\` |
| **Commit** | \`$(git rev-parse --short HEAD)\` |

docker-publish is now building \`:latest\` + \`:${VERSION}.0\` — check the [Actions tab](../../actions) for progress.

### Hotfix workflow (if a bug is found in this release)
\`\`\`bash
git checkout -b bugfixes/fix-foo ${TAG} # branch from the tag, not main
# fix the bug, commit, push
git push origin bugfixes/fix-foo
# then run Actions → Cut Hotfix
\`\`\`
EOF
Loading
Loading