upstream-drift.yml (2740B)
1 # Weekly freshness check. The dataset is regenerated by hand (`npm run data` 2 # needs the vendored upstreams), so nothing would otherwise tell us that 3 # GTFOBins / LOLBAS / WADComs moved on. This compares each upstream's current 4 # HEAD against the short hash recorded in src/data/facets.json and opens (or 5 # updates) a single tracking issue when any of them drifted. 6 name: Upstream drift 7 8 on: 9 schedule: 10 - cron: '17 6 * * 1' # Mondays 06:17 UTC 11 workflow_dispatch: 12 13 permissions: 14 contents: read 15 issues: write 16 17 jobs: 18 drift: 19 runs-on: ubuntu-latest 20 steps: 21 - uses: actions/checkout@v4 22 - name: Compare upstream HEADs with facets.json 23 id: cmp 24 shell: bash 25 run: | 26 set -euo pipefail 27 declare -A REPO=( 28 [gtfobins]=https://github.com/GTFOBins/GTFOBins.github.io 29 [lolbas]=https://github.com/LOLBAS-Project/LOLBAS 30 [wadcoms]=https://github.com/WADComs/WADComs.github.io 31 ) 32 drift=0; body="" 33 for name in gtfobins lolbas wadcoms; do 34 pinned=$(node -p "require('./src/data/facets.json').commits.$name || ''") 35 head=$(git ls-remote "${REPO[$name]}" HEAD | cut -c1-7) 36 if [ -z "$pinned" ]; then 37 body+="- **$name**: no pinned commit recorded (upstream HEAD \`$head\`)"$'\n'; drift=1 38 elif [ "$pinned" != "$head" ]; then 39 body+="- **$name**: pinned \`$pinned\`, upstream HEAD \`$head\` — ${REPO[$name]}/compare/$pinned...$head"$'\n'; drift=1 40 else 41 body+="- $name: up to date (\`$pinned\`)"$'\n' 42 fi 43 done 44 echo "drift=$drift" >> "$GITHUB_OUTPUT" 45 { echo 'body<<EOF'; echo "$body"; echo 'EOF'; } >> "$GITHUB_OUTPUT" 46 - name: Open or update the tracking issue 47 if: steps.cmp.outputs.drift == '1' 48 env: 49 GH_TOKEN: ${{ github.token }} 50 BODY: ${{ steps.cmp.outputs.body }} 51 run: | 52 title="Upstream drift: dataset is behind GTFOBins / LOLBAS / WADComs" 53 text="$(printf '%s\n\n%s\n\n%s' "Detected by the weekly drift check on $(date -u +%F)." "$BODY" 'Refresh with `git submodule update --remote vendor/gtfobins vendor/lolbas vendor/wadcoms && npm run data`, then commit `src/data/*.json`.')" 54 existing=$(gh issue list --label upstream-drift --state open --json number --jq '.[0].number // empty') 55 if [ -n "$existing" ]; then 56 gh issue comment "$existing" --body "$text" 57 else 58 gh label create upstream-drift --color c4a7e7 --description "Dataset behind an upstream" 2>/dev/null || true 59 gh issue create --title "$title" --label upstream-drift --body "$text" 60 fi