Skip to content

Resolve Dependabot alerts and build Pages with GitHub Actions - #93

Merged
judeallred merged 4 commits into
mainfrom
resolve-dependabot-alerts
Sep 30, 2026
Merged

judeallred merged 4 commits into
mainfrom
resolve-dependabot-alerts

Conversation

@judeallred

@judeallred judeallred commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Type of Change

  • Other site update (dependency / security fixes, build pipeline)

Other updates

Resolves both open Dependabot alerts and moves the GitHub Pages build to GitHub Actions, so the site is built with the gems in Gemfile.lock instead of GitHub's fixed legacy environment.

Alerts:

  • rubyzip 2.4.1, high severity, path traversal (GHSA-47m2-wp7j-p9vc). This couldn't be fixed with a normal bump: github-pages pins jekyll-remote-theme to 0.4.3, which requires rubyzip < 3.0.
  • json 2.20.0, low severity (GHSA-9hj4-r449-hfvc). Now 2.21.2.

Changes:

  • Gemfile / Gemfile.lock: replace the github-pages gem with jekyll ~> 4.4 (from 3.10) and the just-the-docs 0.12.0 theme gem. This removes rubyzip, nokogiri, and about 40 other unused gems, plus the activesupport pin that only patched a github-pages sub-dependency.
  • _config.yml: change remote_theme: just-the-docs/just-the-docs to theme: just-the-docs, so the theme version is locked in Gemfile.lock instead of pulling the theme's latest main on every build. Adds a sass: block to disable source maps and silence the theme's Dart Sass deprecation warnings.
  • .github/workflows/pages.yml (new): builds in the official ruby:3.3 container with bundle exec jekyll build (gems cached with actions/cache), then deploys with actions/upload-pages-artifact and actions/deploy-pages. The container is used because ruby/setup-ruby isn't on the org's Actions allowlist. Pull requests run the build as a check; only pushes to main deploy. Actions are pinned to commit SHAs, and the job token is read-only except for the deploy job.
  • .github/dependabot.yml (new): monthly grouped version updates for bundler and GitHub Actions.
  • _layouts/blank.html: deleted. No page uses it, and it was the only thing loading jQuery 3.6.0 and jQuery UI 1.13.1 (CVE-2022-31160).
  • ecosystem.md: percent-encode spaces in the map image links, which Jekyll 4 otherwise renders as raw spaces.
  • README.md: the hosting section said DigitalOcean. The site is served by GitHub Pages behind Cloudflare.

⚠️ Rollout order (required)

The Pages source is currently Deploy from a branch (legacy build). Legacy builds ignore the Gemfile and don't allow the just-the-docs theme gem, so merging this while that setting is active would break the live site.

  1. Settings → Pages → Build and deployment → Source: GitHub Actions. This alone doesn't change the live site; the current deployment stays up.
  2. Merge this PR. The workflow builds and deploys main.
  3. Check https://chialinks.com (see Post-deploy check below).
  4. Rollback: set the source back to Deploy from a branch (main, /) and revert this PR.

The custom domain (chialinks.com) is kept in the Pages settings, so it carries over.

Expected result: verified against the live site

A production build of this branch (rebased on main at 5f5c4d2, which includes #91) was compared file by file with what https://chialinks.com serves today.

  • 117 of 123 files are identical, ignoring the following. Items marked (Cloudflare) are added at the Cloudflare edge as pages are served, so they will continue after the switch:
    • the SEO-tag block and Jekyll generator version in each page's <head>, and the feed timestamp;
    • (Cloudflare) the Web Analytics script at the end of every page;
    • (Cloudflare) http:// links rewritten to https:// by Automatic HTTPS Rewrites.
  • The 6 differing files are all expected:
    • README.md: the hosting docs update.
    • ecosystem/: image links are now consistently %20-escaped.
    • 4 theme CSS files: from moving to the Just the Docs v0.12.0 release and Dart Sass.
  • The CSS change is visually a no-op. All 33 pages were screenshotted in headless Chrome at 1280 px and 390 px wide, with the new CSS and with the live CSS on otherwise identical HTML.
    • Phone width: every page is pixel-identical.
    • Desktop width: the only visible difference is the Roadmap icon in the top navigation sitting about 1 px higher. Everything else is sub-threshold anti-aliasing.
  • The build also emits a CNAME file that the legacy build didn't. It's harmless: Actions deployments take the custom domain from the Pages settings.

Not testable before merge

The switch itself: the Actions deployment serving the custom domain and HTTPS.

Post-deploy check

Right after the first Actions deploy, rerun the same comparison against live (fetch every file in the built _site from https://chialinks.com). Expect all 123 files to match once the same normalization is applied. If the site is broken, roll back as in step 4.

Verification (local, Ruby 3.3 in Docker, linux/amd64)

  • bundler-audit: 2 vulnerabilities on main, none on this branch.
  • actionlint passes on the workflow, and the Build and deploy site check passes on this PR (deploy is skipped for PRs).
  • The production build (JEKYLL_ENV=production, frozen lock file) passes, and so does jekyll serve.
  • Compared against the live site: see Expected result above.
  • Theme note: the live site currently uses the theme's main branch, 63 commits past v0.12.0. This moves it to the v0.12.0 release. The CSS is about 14 KB larger, but renders the same (see the screenshot comparison above).

Once merged, #89, #81 and #78 are superseded and can be closed.

Reviewers/Approvers


Note

Medium Risk
Changes production hosting and a major Jekyll upgrade; rollout requires switching Pages to GitHub Actions before merge to avoid breaking the live site.

Overview
Replaces the legacy github-pages stack with Jekyll 4.4 and a pinned just-the-docs 0.12.0 gem, shrinking Gemfile.lock and clearing Dependabot issues (notably rubyzip via dropping jekyll-remote-theme, and json bumped to 2.21.2). _config.yml switches from remote_theme to theme, adds Sass quieting for Dart Sass, moves the footer into _includes/footer_custom.html, and drops the built-in ga_tracking block.

Adds GitHub Actions–based Pages delivery: .github/workflows/pages.yml builds in a ruby:3.3 container with a frozen bundle (PRs build only; main deploys), and .github/dependabot.yml schedules monthly grouped Bundler and Actions updates.

Site/content tweaks: removes unused _layouts/blank.html (jQuery/jQuery UI), percent-encodes ecosystem map image URLs for Jekyll 4, and updates README to document GitHub Pages + Cloudflare and the required Pages GitHub Actions source setting before merge.

Reviewed by Cursor Bugbot for commit 74fe299. Bugbot is set up for automated code reviews on this repo. Configure here.

@socket-security

socket-security Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedjekyll@​3.10.0 ⏵ 4.4.184 -1100100100100
Addedjust-the-docs@​0.12.099100100100100

View full report

@judeallred
judeallred marked this pull request as draft September 28, 2026 21:00
@judeallred

Copy link
Copy Markdown
Collaborator Author

Converted to draft: chialinks.com is served by GitHub Pages (legacy build from main), not DigitalOcean as the README says. Legacy Pages builds ignore the Gemfile and only support whitelisted themes, so replacing remote_theme with theme: just-the-docs would break the live site. Needs either a switch to a GitHub Actions Pages build or a rework that keeps github-pages.

@judeallred judeallred changed the title Resolve Dependabot alerts by dropping github-pages gem Resolve Dependabot alerts and build Pages with GitHub Actions Sep 28, 2026
@judeallred

Copy link
Copy Markdown
Collaborator Author

Update: the PR now builds and deploys Pages with GitHub Actions (.github/workflows/pages.yml), and the build check passes. Before merging, set Settings → Pages → Source to GitHub Actions; see the rollout order in the PR description.

@judeallred
judeallred force-pushed the resolve-dependabot-alerts branch from 15c6e9a to cfae4de Compare September 28, 2026 21:16
Replace the github-pages gem with Jekyll 4.4 and the just-the-docs 0.12.0
theme gem. github-pages pinned jekyll-remote-theme 0.4.3, which capped
rubyzip below 3.0 and blocked the fix for GHSA-47m2-wp7j-p9vc. Using the
theme gem removes rubyzip entirely and pins the theme version in
Gemfile.lock.

- Bump json to 2.21.2 (GHSA-9hj4-r449-hfvc)
- Remove unused blank layout that loaded jQuery UI 1.13.1
- Percent-encode spaces in ecosystem map links
- Disable Sass source maps and silence theme deprecation warnings
Legacy Pages builds ignore the Gemfile and only allow whitelisted
themes, so build the site with the locked gems in a workflow and deploy
it with actions/deploy-pages. Pull requests run the build as a check.

- Pin actions to commit SHAs and add Dependabot updates for bundler and
  github-actions
- Add .ruby-version (3.3)
- Correct README hosting section: the site is on GitHub Pages
ruby/setup-ruby is not on the Chia-Network Actions allowlist, which
caused a startup failure. Run the build job in the official Ruby image
and cache gems with actions/cache.
Universal Analytics (UA- IDs) stopped collecting data in July 2024, so the
gtag script only added a third-party request. Cloudflare Web Analytics
already covers the site.

Move the footer from the deprecated footer_content setting to
_includes/footer_custom.html and render the copyright end year from the
build date.
@judeallred
judeallred marked this pull request as ready for review September 30, 2026 01:41
@judeallred
judeallred force-pushed the resolve-dependabot-alerts branch from 28083f1 to 74fe299 Compare September 30, 2026 01:43

@BrandtH22 BrandtH22 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@judeallred
judeallred merged commit 5de812c into main Sep 30, 2026
8 checks passed
@judeallred
judeallred deleted the resolve-dependabot-alerts branch September 30, 2026 16:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants