From 9efe099c448bc565edd3010353e3702c465ca4aa Mon Sep 17 00:00:00 2001 From: Tomas Dvorak Date: Fri, 18 Sep 2026 16:46:06 +0200 Subject: [PATCH] chore: phase A maintenance automation and dev infrastructure - dependabot.yml: weekly Go/npm/cargo/Actions dependency PRs - upstream-sync.yml: weekly upstream->fork merge PR so security fixes keep landing automatically - docker-compose.dev.yml: postgres + redis + backend from source - NOTICE: upstream attribution and independent implementation note - build-assets.sh: tolerate empty version arg (snapshot builds) Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> --- .build/build-assets.sh | 2 +- .github/dependabot.yml | 45 +++++++++++++++++++++++ .github/workflows/upstream-sync.yml | 57 +++++++++++++++++++++++++++++ NOTICE | 23 ++++++++++++ ROADMAP.md | 10 +++-- docker-compose.dev.yml | 45 +++++++++++++++++++++++ 6 files changed, 177 insertions(+), 5 deletions(-) create mode 100644 .github/dependabot.yml create mode 100644 .github/workflows/upstream-sync.yml create mode 100644 NOTICE create mode 100644 docker-compose.dev.yml diff --git a/.build/build-assets.sh b/.build/build-assets.sh index fa7cf3c4..cb41084f 100755 --- a/.build/build-assets.sh +++ b/.build/build-assets.sh @@ -6,7 +6,7 @@ export NODE_OPTIONS="--max-old-space-size=8192" cd frontend rm -rf build yarn install --network-timeout 1000000 -yarn version --new-version $1 --no-git-tag-version +yarn version --new-version "${1:-0.0.0-dev}" --no-git-tag-version yarn run build # Copy the build files to the application directory. diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 00000000..5b8c56fa --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,45 @@ +version: 2 +updates: + - package-ecosystem: gomod + directory: / + schedule: + interval: weekly + open-pull-requests-limit: 10 + labels: + - dependencies + - go + + - package-ecosystem: npm + directory: /frontend + schedule: + interval: weekly + open-pull-requests-limit: 10 + labels: + - dependencies + - frontend + + - package-ecosystem: cargo + directory: /desktop + schedule: + interval: weekly + open-pull-requests-limit: 10 + labels: + - dependencies + - desktop + + - package-ecosystem: npm + directory: /desktop/ui + schedule: + interval: weekly + open-pull-requests-limit: 10 + labels: + - dependencies + - desktop + + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly + labels: + - dependencies + - ci diff --git a/.github/workflows/upstream-sync.yml b/.github/workflows/upstream-sync.yml new file mode 100644 index 00000000..a26465de --- /dev/null +++ b/.github/workflows/upstream-sync.yml @@ -0,0 +1,57 @@ +name: Upstream Sync + +on: + schedule: + - cron: "0 6 * * 1" # Mondays 06:00 UTC + workflow_dispatch: + +permissions: + contents: write + pull-requests: write + +jobs: + sync: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Fetch upstream + run: | + git remote add upstream https://github.com/cloudreve/cloudreve.git + git fetch upstream master + + - name: Check divergence + id: check + run: | + BEHIND=$(git rev-list --count HEAD..upstream/master) + echo "behind=$BEHIND" >> "$GITHUB_OUTPUT" + if [ "$BEHIND" -eq 0 ]; then + echo "Already up to date with upstream." + fi + + - name: Create sync PR + if: steps.check.outputs.behind != '0' + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + BRANCH="sync/upstream-$(date +%Y%m%d)" + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git checkout -b "$BRANCH" + git merge upstream/master --no-edit -m "chore: sync upstream master ($(date +%Y-%m-%d))" || { + echo "Merge conflicts detected — opening PR for manual resolution." + git merge --abort + git checkout upstream/master -b "$BRANCH" + } + git push origin "$BRANCH" + gh pr create \ + --title "chore: sync upstream master ($(date +%Y-%m-%d))" \ + --body "$(cat <<'EOF' + Weekly upstream synchronization. ${{ steps.check.outputs.behind }} commits behind upstream/master. + + Review the diff before merging — upstream changes may conflict with local modifications. + EOF + )" \ + --label "upstream-sync" || echo "PR may already exist for this branch." diff --git a/NOTICE b/NOTICE new file mode 100644 index 00000000..e94cb52e --- /dev/null +++ b/NOTICE @@ -0,0 +1,23 @@ +Cloudreve — community-maintained open-source distribution +========================================================= + +This repository is a fork of Cloudreve, originally created and +maintained by the Cloudreve authors: + + https://github.com/cloudreve/cloudreve + https://cloudreve.org + +Upstream components vendored into this repository: + + frontend/ — Cloudreve Web UI (github.com/cloudreve/frontend) + desktop/ — Cloudreve Desktop (github.com/cloudreve/desktop) + +All upstream code remains under its original license (GPLv3 unless +otherwise noted in the component). Original copyright notices are +preserved in the respective source trees. + +This distribution is maintained independently and is not affiliated +with or endorsed by the original Cloudreve authors. Functionality +equivalent to Cloudreve Pro is implemented independently in this +repository and released under the same open-source license — no +private Pro code is used. diff --git a/ROADMAP.md b/ROADMAP.md index b253843c..ed55bdbd 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -112,10 +112,12 @@ cloudreve/ Go backend (existing code, repo root) ## 3. Phase A — foundation hardening (first weeks) -- Sync-upstream automation: weekly `upstream → fork` merge workflow so security fixes keep landing -- Dependabot/renovate on the fork (Go, npm, cargo) -- `docker-compose` dev stack (postgres + app + frontend hot reload) -- Remove `ProDialog`/`ProChip` gates in `frontend/` — UI skeleton already exists, backend fills it +- [x] Sync-upstream automation: weekly `upstream → fork` merge workflow (`.github/workflows/upstream-sync.yml`) +- [x] Dependabot on the fork (Go, npm, cargo — `.github/dependabot.yml`) +- [x] `docker-compose.dev.yml` dev stack (postgres + redis + backend built from source; frontend via `yarn dev` hot reload) +- [x] Remove `ProDialog`/`ProChip` gates in `frontend/` — all upsell interception stripped, `ProDialog.tsx` deleted (backend feature work remains, Phase B) +- [x] `NOTICE` attribution file — upstream authorship + independent-Pro-implementation statement +- [x] `go vet ./...` clean (upstream lint debt repaired: lock-by-value receivers, unkeyed literals, GobDecode signature) ## 4. Phase B — Pro features, free (the big one) diff --git a/docker-compose.dev.yml b/docker-compose.dev.yml new file mode 100644 index 00000000..b4d68ca8 --- /dev/null +++ b/docker-compose.dev.yml @@ -0,0 +1,45 @@ +# Development stack: backend built from source + postgres + redis. +# Usage: docker compose -f docker-compose.dev.yml up +# For frontend hot reload, run `yarn dev` in ./frontend separately and +# point it at the backend on :5212. +services: + backend: + build: + context: . + dockerfile: Dockerfile + container_name: cloudreve-dev-backend + depends_on: + - postgresql + - redis + ports: + - 5212:5212 + environment: + - CR_CONF_Database.Type=postgres + - CR_CONF_Database.Host=postgresql + - CR_CONF_Database.User=cloudreve + - CR_CONF_Database.Name=cloudreve + - CR_CONF_Database.Port=5432 + - CR_CONF_Redis.Server=redis:6379 + volumes: + - backend_data:/cloudreve/data + + postgresql: + image: postgres:17 + container_name: cloudreve-dev-postgres + environment: + - POSTGRES_USER=cloudreve + - POSTGRES_DB=cloudreve + - POSTGRES_HOST_AUTH_METHOD=trust + volumes: + - database_postgres:/var/lib/postgresql/data + + redis: + image: redis:7 + container_name: cloudreve-dev-redis + volumes: + - redis_data:/data + +volumes: + backend_data: + database_postgres: + redis_data: