daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

sync-mirrors.yml (1519B)


      1 name: Sync upstream mirrors
      2 
      3 # Mirrors swisskyrepo's PayloadsAllTheThings and InternalAllTheThings into the
      4 # site and pushes straight to main. No review gate: the build and the test suite
      5 # are what stand between upstream and the live site, so a sync that breaks
      6 # either one fails here and never lands.
      7 
      8 on:
      9   schedule:
     10     - cron: '17 6 * * *'   # daily 06:17 UTC
     11   workflow_dispatch:
     12 
     13 permissions:
     14   contents: write
     15 
     16 concurrency:
     17   group: sync-mirrors
     18   cancel-in-progress: false
     19 
     20 jobs:
     21   sync:
     22     runs-on: ubuntu-latest
     23     steps:
     24       - name: Checkout site
     25         uses: actions/checkout@v4
     26         with:
     27           # Full history so the push can rebase if main moved during the build.
     28           fetch-depth: 0
     29 
     30       - name: Setup Node
     31         uses: actions/setup-node@v4
     32         with:
     33           node-version: 22
     34           cache: npm
     35 
     36       # Everything the sync does lives in the script, so running it locally
     37       # and running it here are the same thing. It clones both upstreams,
     38       # regenerates the mirrors, refuses to publish anything that fails
     39       # `npm run build` or `node --test`, and commits one commit per upstream
     40       # for whichever trees actually moved.
     41       - name: Sync, validate and push
     42         id: push
     43         run: scripts/sync-mirrors.sh --push
     44 
     45       # No deploy step: Cloudflare Workers is the only host and it deploys
     46       # manually via `npm run deploy:workers`. A sync lands commits on main and
     47       # nothing more, so synced content goes live at the next manual deploy.