From fa51a4ca29dfb11271d0915908732d334a0b1de1 Mon Sep 17 00:00:00 2001 From: Marc Deniel Date: Wed, 16 Sep 2026 15:33:20 +0800 Subject: [PATCH 1/2] Add Hadolint workflow for Dockerfile linting This workflow runs Hadolint to analyze Dockerfiles and uploads results to GitHub. --- .github/workflows/hadolint.yml | 47 ++++++++++++++++++++++++++++++++++ 1 file changed, 47 insertions(+) create mode 100644 .github/workflows/hadolint.yml diff --git a/.github/workflows/hadolint.yml b/.github/workflows/hadolint.yml new file mode 100644 index 0000000..e0fdd9e --- /dev/null +++ b/.github/workflows/hadolint.yml @@ -0,0 +1,47 @@ +# This workflow uses actions that are not certified by GitHub. +# They are provided by a third-party and are governed by +# separate terms of service, privacy policy, and support +# documentation. +# hadoint is a Dockerfile linter written in Haskell +# that helps you build best practice Docker images. +# More details at https://github.com/hadolint/hadolint + +name: Hadolint + +on: + push: + branches: [ "main" ] + pull_request: + # The branches below must be a subset of the branches above + branches: [ "main" ] + schedule: + - cron: '25 2 * * 2' + +permissions: + contents: read + +jobs: + hadolint: + name: Run hadolint scanning + runs-on: ubuntu-latest + permissions: + contents: read # for actions/checkout to fetch code + security-events: write # for github/codeql-action/upload-sarif to upload SARIF results + actions: read # only required for a private repository by github/codeql-action/upload-sarif to get the Action run status + steps: + - name: Checkout code + uses: actions/checkout@v4 + + - name: Run hadolint + uses: hadolint/hadolint-action@f988afea3da57ee48710a9795b6bb677cc901183 + with: + dockerfile: ./Dockerfile + format: sarif + output-file: hadolint-results.sarif + no-fail: true + + - name: Upload analysis results to GitHub + uses: github/codeql-action/upload-sarif@v3 + with: + sarif_file: hadolint-results.sarif + wait-for-processing: true From fad48afdee8ba693e70222fdb2d56e5a2e7af6c0 Mon Sep 17 00:00:00 2001 From: Marc Deniel Date: Wed, 16 Sep 2026 16:12:19 +0800 Subject: [PATCH 2/2] Potential fix for code scanning alert no. 1: Workflow does not contain permissions MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit GramIO's core package explicitly supports Deno before committing to the import-map approach: Confirmed: GramIO explicitly advertises "🌐 Multi-runtime - Works on Node.js, Bun and Deno." Good — I can proceed confidently with a Deno setup, using an import map so the source stays identical across runtimes. Now update db/init.ts to drop the Node-only process.argv self-invocation check in favor of a cross-runtime one: Now update package.json to drop the dotenv dependency (no longer needed) and use --env-file for Node: No real errors (grep found nothing beyond expected missing-dependency noise). Now let's update the README with Deno instructions and repackage: Now let's repackage the zip with all the changes: Updated. What changed: - **.env loading** — dropped the dotenv package entirely. Both runtimes load it natively now via --env-file=.env (Node 20.6+, Deno 1.44+), wired into the npm/Deno task scripts. - **deno.json** — added with an import map (gramio, @gramio/auto-answer-callback-query, better-sqlite3 → their npm: equivalents) so the exact same src/ files run under deno task dev / deno task start with zero code forking. GramIO itself explicitly advertises Node/Deno/Bun support, so this should be solid. - **src/env.ts** — small helper that reads Deno.env.get or process.env depending on which runtime is present, used everywhere instead of raw process.env. - **src/index.ts / src/db/init.ts** — swapped Node-only bits (process.argv, process.on) for cross-runtime equivalents. One caveat, flagged in the README: better-sqlite3 is a native addon, and while Deno's npm compatibility generally supports native modules, I can't 100% guarantee it for this specific package on every Deno version — if it gives you trouble, the README points to swapping in jsr:@db/sqlite (same schema, same SQL, different wrapper) as a quick fix. To run: cp .env.example .env → fill in BOT_TOKEN/OWNER_ID → deno task dev. Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- .github/workflows/docker-image.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/docker-image.yml b/.github/workflows/docker-image.yml index 3f53646..9256486 100644 --- a/.github/workflows/docker-image.yml +++ b/.github/workflows/docker-image.yml @@ -6,6 +6,9 @@ on: pull_request: branches: [ "main" ] +permissions: + contents: read + jobs: build: