Resolve Dependabot alerts and build Pages with GitHub Actions - #93
Merged
Merged
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
judeallred
marked this pull request as draft
September 28, 2026 21:00
Collaborator
Author
|
Converted to draft: chialinks.com is served by GitHub Pages (legacy build from |
Collaborator
Author
|
Update: the PR now builds and deploys Pages with GitHub Actions ( |
judeallred
force-pushed
the
resolve-dependabot-alerts
branch
from
September 28, 2026 21:16
15c6e9a to
cfae4de
Compare
Replace the github-pages gem with Jekyll 4.4 and the just-the-docs 0.12.0 theme gem. github-pages pinned jekyll-remote-theme 0.4.3, which capped rubyzip below 3.0 and blocked the fix for GHSA-47m2-wp7j-p9vc. Using the theme gem removes rubyzip entirely and pins the theme version in Gemfile.lock. - Bump json to 2.21.2 (GHSA-9hj4-r449-hfvc) - Remove unused blank layout that loaded jQuery UI 1.13.1 - Percent-encode spaces in ecosystem map links - Disable Sass source maps and silence theme deprecation warnings
Legacy Pages builds ignore the Gemfile and only allow whitelisted themes, so build the site with the locked gems in a workflow and deploy it with actions/deploy-pages. Pull requests run the build as a check. - Pin actions to commit SHAs and add Dependabot updates for bundler and github-actions - Add .ruby-version (3.3) - Correct README hosting section: the site is on GitHub Pages
ruby/setup-ruby is not on the Chia-Network Actions allowlist, which caused a startup failure. Run the build job in the official Ruby image and cache gems with actions/cache.
Universal Analytics (UA- IDs) stopped collecting data in July 2024, so the gtag script only added a third-party request. Cloudflare Web Analytics already covers the site. Move the footer from the deprecated footer_content setting to _includes/footer_custom.html and render the copyright end year from the build date.
judeallred
marked this pull request as ready for review
September 30, 2026 01:41
judeallred
force-pushed
the
resolve-dependabot-alerts
branch
from
September 30, 2026 01:43
28083f1 to
74fe299
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Type of Change
Other updates
Resolves both open Dependabot alerts and moves the GitHub Pages build to GitHub Actions, so the site is built with the gems in
Gemfile.lockinstead of GitHub's fixed legacy environment.Alerts:
github-pagespinsjekyll-remote-themeto 0.4.3, which requiresrubyzip < 3.0.Changes:
Gemfile/Gemfile.lock: replace thegithub-pagesgem withjekyll ~> 4.4(from 3.10) and thejust-the-docs0.12.0 theme gem. This removesrubyzip,nokogiri, and about 40 other unused gems, plus theactivesupportpin that only patched agithub-pagessub-dependency._config.yml: changeremote_theme: just-the-docs/just-the-docstotheme: just-the-docs, so the theme version is locked inGemfile.lockinstead of pulling the theme's latestmainon every build. Adds asass:block to disable source maps and silence the theme's Dart Sass deprecation warnings..github/workflows/pages.yml(new): builds in the officialruby:3.3container withbundle exec jekyll build(gems cached withactions/cache), then deploys withactions/upload-pages-artifactandactions/deploy-pages. The container is used becauseruby/setup-rubyisn't on the org's Actions allowlist. Pull requests run the build as a check; only pushes tomaindeploy. Actions are pinned to commit SHAs, and the job token is read-only except for the deploy job..github/dependabot.yml(new): monthly grouped version updates for bundler and GitHub Actions._layouts/blank.html: deleted. No page uses it, and it was the only thing loading jQuery 3.6.0 and jQuery UI 1.13.1 (CVE-2022-31160).ecosystem.md: percent-encode spaces in the map image links, which Jekyll 4 otherwise renders as raw spaces.README.md: the hosting section said DigitalOcean. The site is served by GitHub Pages behind Cloudflare.The Pages source is currently Deploy from a branch (legacy build). Legacy builds ignore the Gemfile and don't allow the
just-the-docstheme gem, so merging this while that setting is active would break the live site.main.main,/) and revert this PR.The custom domain (
chialinks.com) is kept in the Pages settings, so it carries over.Expected result: verified against the live site
A production build of this branch (rebased on
mainat 5f5c4d2, which includes #91) was compared file by file with what https://chialinks.com serves today.<head>, and the feed timestamp;http://links rewritten tohttps://by Automatic HTTPS Rewrites.README.md: the hosting docs update.ecosystem/: image links are now consistently%20-escaped.CNAMEfile that the legacy build didn't. It's harmless: Actions deployments take the custom domain from the Pages settings.Not testable before merge
The switch itself: the Actions deployment serving the custom domain and HTTPS.
Post-deploy check
Right after the first Actions deploy, rerun the same comparison against live (fetch every file in the built
_sitefrom https://chialinks.com). Expect all 123 files to match once the same normalization is applied. If the site is broken, roll back as in step 4.Verification (local, Ruby 3.3 in Docker, linux/amd64)
bundler-audit: 2 vulnerabilities onmain, none on this branch.actionlintpasses on the workflow, and the Build and deploy site check passes on this PR (deploy is skipped for PRs).JEKYLL_ENV=production, frozen lock file) passes, and so doesjekyll serve.mainbranch, 63 commits past v0.12.0. This moves it to the v0.12.0 release. The CSS is about 14 KB larger, but renders the same (see the screenshot comparison above).Once merged, #89, #81 and #78 are superseded and can be closed.
Reviewers/Approvers
Note
Medium Risk
Changes production hosting and a major Jekyll upgrade; rollout requires switching Pages to GitHub Actions before merge to avoid breaking the live site.
Overview
Replaces the legacy
github-pagesstack with Jekyll 4.4 and a pinnedjust-the-docs0.12.0 gem, shrinkingGemfile.lockand clearing Dependabot issues (notablyrubyzipvia droppingjekyll-remote-theme, andjsonbumped to 2.21.2)._config.ymlswitches fromremote_themetotheme, adds Sass quieting for Dart Sass, moves the footer into_includes/footer_custom.html, and drops the built-inga_trackingblock.Adds GitHub Actions–based Pages delivery:
.github/workflows/pages.ymlbuilds in aruby:3.3container with a frozen bundle (PRs build only;maindeploys), and.github/dependabot.ymlschedules monthly grouped Bundler and Actions updates.Site/content tweaks: removes unused
_layouts/blank.html(jQuery/jQuery UI), percent-encodes ecosystem map image URLs for Jekyll 4, and updates README to document GitHub Pages + Cloudflare and the required Pages GitHub Actions source setting before merge.Reviewed by Cursor Bugbot for commit 74fe299. Bugbot is set up for automated code reviews on this repo. Configure here.