Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
73 commits
Select commit Hold shift + click to select a range
9243d08
schedule actionlint at 04:05 monday-friday
ejcsid Jul 15, 2026
16d6533
build.yml runs at 04:10, Monday through Friday and on pushes to sps-t…
ejcsid Jul 15, 2026
f13953c
codeql.ml runs at 04:15, Monday through Friday and an pushes to sps-t…
ejcsid Jul 15, 2026
90bf9c9
dependency-review.yml runs at 04:20, Monday through Friday
ejcsid Jul 15, 2026
0ff02ce
timezone: "Europe/Berlin"
ejcsid Jul 15, 2026
2c221c7
Add schedule triggers for all workflows
ejcsid Jul 15, 2026
7343d5b
Handle failures (send notifications to webex)
ejcsid Jul 16, 2026
714c3ee
Changed ReadMe.md for sps-test intention and usage.
ejcsid Jul 16, 2026
c57702e
Fixed typos
ejcsid Jul 16, 2026
405cdc5
schedule npm for timezone Europe/Berlin, added defaults for inputs in…
ejcsid Jul 16, 2026
3d616c7
chore(frontend): bump version to v0.0.1
invalid-email-address Jul 17, 2026
0ce8a3a
Merge pull request #5 from it-at-m/release-frontend-v0.0.1
ejcsid Jul 17, 2026
04a7b2f
Added env vars as default for input vars if running scheduled
ejcsid Jul 17, 2026
5134e50
Merge branch 'sps-test-main' of https://github.com/it-at-m/sps-test i…
ejcsid Jul 17, 2026
1298741
schedule not possible as it has to run on a pull_request.
ejcsid Jul 17, 2026
212ae0f
default values for scheduled trigger
ejcsid Jul 17, 2026
e2528ef
added codeql-origin.yml
ejcsid Jul 17, 2026
9fab506
env DEFAULT_APP_PATH: "backend"
ejcsid Jul 20, 2026
c7f4d61
Delete .github/workflows/codeql.yml
ejcsid Jul 20, 2026
95c7d3a
Create codeql.yml
ejcsid Jul 20, 2026
87d7fc5
Delete .github/workflows/codeql-origin.yml
ejcsid Jul 20, 2026
794e8da
Create codeql-origin.yml
ejcsid Jul 20, 2026
d37040e
Delete .github/workflows/codeql-origin.yml
ejcsid Jul 20, 2026
4c2e2e4
Delete .github/workflows/codeql.yml
ejcsid Jul 20, 2026
334202c
Create codeql.yml
ejcsid Jul 20, 2026
45bb3ab
Create codeql-origin.yml
ejcsid Jul 20, 2026
50b3d24
Delete .github/workflows/codeql-origin.yml
ejcsid Jul 20, 2026
098418c
Create codeql-origin.yml
ejcsid Jul 20, 2026
fbaf98d
Delete .github/workflows/codeql-origin.yml
ejcsid Jul 20, 2026
2c40547
Update actionlint.yml
hupling Jul 21, 2026
9c6282d
Update Webex notification message format
hupling Jul 21, 2026
db7c4e8
Update Webex notification message format
hupling Jul 21, 2026
b9ecf23
Update actionlint.yml
hupling Jul 21, 2026
2165f32
Update build.yml
hupling Jul 21, 2026
9b5cfa4
Update dependency-review.yml
hupling Jul 21, 2026
115aaef
Update deploy-docs.yml
hupling Jul 21, 2026
b3134f2
Update Webex notification message format
hupling Jul 21, 2026
9912d36
Update pr-labeler.yml
hupling Jul 21, 2026
0aee285
Update Webex notification message format
hupling Jul 21, 2026
5d73a4a
Update Webex notification message format
hupling Jul 21, 2026
b2e0f84
Update trivy.yml
hupling Jul 21, 2026
700cfde
Apply suggestions from code review
hupling Jul 21, 2026
d18a557
Update build.yml
hupling Jul 21, 2026
69f8508
Update build.yml
hupling Jul 21, 2026
64e834a
Update build.yml
hupling Jul 21, 2026
e5d560b
Update actionlint.yml
hupling Jul 21, 2026
95a9fb0
Update CodeQL workflow condition for failure
hupling Jul 21, 2026
dbe7cef
Update dependency-review.yml
hupling Jul 21, 2026
f09a670
Update deploy-docs.yml
hupling Jul 21, 2026
b4edbc2
Update dockercompose-healthcheck.yml
hupling Jul 21, 2026
1d858ab
Update failure condition for handlefailure job
hupling Jul 21, 2026
94fd488
Update release-maven.yml
hupling Jul 21, 2026
a6cd790
Update release-npm.yml
hupling Jul 21, 2026
67d9124
Update trivy.yml
hupling Jul 21, 2026
0505933
Merge pull request #8 from it-at-m/change-webex
hupling Jul 21, 2026
aecbe90
Merge branch 'main' into sps-test-main
ejcsid Jul 21, 2026
6b412c8
Add permissions block to handlefailure-Job in workflows
ejcsid Jul 21, 2026
9cf11cc
add env-default-values to lhm_actions actions calls
ejcsid Jul 22, 2026
cc97034
add env-default values to lhm_actions actions calls
ejcsid Jul 22, 2026
3922de2
Apply suggestions from code review
ejcsid Jul 22, 2026
de4cd2b
Apply suggestion from @ejcsid
ejcsid Jul 22, 2026
bac5839
Apply suggestion from @ejcsid
ejcsid Jul 22, 2026
9523cf0
fix(workflows): Add missing env-defaults to action calls
ejcsid Jul 23, 2026
704820f
[maven-release-plugin] prepare release refarch-backend-0.0.3
invalid-email-address Jul 24, 2026
6931ccf
[maven-release-plugin] prepare for next development iteration
invalid-email-address Jul 24, 2026
a109776
Merge pull request #14 from it-at-m/release-backend-0.0.4-SNAPSHOT
ejcsid Jul 24, 2026
6f4970f
chore(workflows): removing schedule block from release-maven
ejcsid Jul 24, 2026
5c0e8ac
chore(workflows): removing schedule block from release-maven
ejcsid Jul 24, 2026
ab49d36
Merge branch 'main' into sps-test-main
hupling Jul 29, 2026
d3114d3
Update build.yml
hupling Jul 29, 2026
b878258
Update release-maven.yml
hupling Jul 29, 2026
e7d9f80
Update dependency in handlefailure job
hupling Jul 29, 2026
887fec6
Merge pull request #18 from it-at-m/fix-lint
hupling Jul 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
33 changes: 15 additions & 18 deletions .github/README.md
Original file line number Diff line number Diff line change
@@ -1,19 +1,17 @@
<!-- General project links -->
[open-issues]: https://github.com/it-at-m/refarch-templates/issues
[new-issue]: https://github.com/it-at-m/refarch-templates/issues/new/choose
[milestones]: https://github.com/it-at-m/refarch-templates/milestones
[project-board]: https://github.com/orgs/it-at-m/projects/16
[documentation]: https://refarch.oss.muenchen.de/templates
[open-issues]: https://github.com/it-at-m/sps-test/issues
[new-issue]: https://github.com/it-at-m/sps-test/issues/new/choose
[project-board]: https://github.com/orgs/it-at-m/projects/19
[documentation]: https://github.com/it-at-m/sps-test/
[contribution-documentation]: https://refarch.oss.muenchen.de/contribute
[itm-opensource]: https://opensource.muenchen.de/
[license]: ../LICENSE
[code-of-conduct]: ./CODE_OF_CONDUCT.md

<!-- Project specific links -->
[refarch-documentation]: https://refarch.oss.muenchen.de/
[refarch-code]: https://github.com/it-at-m/refarch
[spring-documentation]: https://spring.io/
[vuejs-documentation]: https://vuejs.org/
[refarch-templates]: https://github.com/it-at-m/refarch-templates
[lhm_actions]: https://github.com/it-at-m/lhm_actions
[getting-started-documentation]: https://refarch.oss.muenchen.de/templates/getting-started
[develop-documentation]: https://refarch.oss.muenchen.de/templates/develop
[document-documentation]: https://refarch.oss.muenchen.de/templates/document
Expand All @@ -23,31 +21,30 @@
[documentation-shield]: https://img.shields.io/badge/documentation-blue?style=for-the-badge
[new-issue-shield]: https://img.shields.io/badge/new%20issue-blue?style=for-the-badge
[made-with-love-shield]: https://img.shields.io/badge/made%20with%20%E2%9D%A4%20by-it%40M-yellow?style=for-the-badge
[license-shield]: https://img.shields.io/github/license/it-at-m/refarch-templates?style=for-the-badge
[license-shield]: https://img.shields.io/github/license/it-at-m/sps-test?style=for-the-badge

# RefArch Templates
# SPS Test (a fork of RefArch Templates)

[![Documentation][documentation-shield]][documentation]
[![New issue][new-issue-shield]][new-issue]
[![Made with love by it@M][made-with-love-shield]][itm-opensource]
[![GitHub license][license-shield]][license]

This project acts as a template and provides starter files for web application projects based on the RefArch (reference architecture) of it@M.
This project if a fork forked of [it-at-m/refarch-templates][refarch-templates]. It is named SPS which is an abbreviation for **S**oftware**p**roduktions**s**traße -
it@m internally used for their CI/CD Pipelines and everything what's going with it.

To learn more about the architecture itself, checkout its [documentation][refarch-documentation] or [code][refarch-code].

The templates are based on [Spring][spring-documentation] and [Vue.js][vuejs-documentation].
sps-test is used to test it@m's GitHub Actions implemented in repository [it-at-m/lhm_actions][lhm_actions]
and RefArch template workflows implemented in repository [it-at-m/refarch-templates][refarch-templates].

## Usages

To get set up and learn more about the templates, please check out the [Getting Started][getting-started-documentation] page.
If you want to setup and learn more about the RefArch templates, please check out the [Getting Started][getting-started-documentation] page.
Also check the respective pages with suggestions on how to [develop][develop-documentation], [document][document-documentation] and [organize][organize-documentation] your project.

## Roadmap

See the [open issues][open-issues] for a full list of proposed features (and known issues).
To get a better overview on what's currently being worked on, check out our [project board][project-board].
We often also plan our issues in [milestones][milestones].
To get a better overview on what's currently being worked on it@m's GitHub Actions and RefArch Templates Workflows,
check out our [project board][project-board].

## Contributing

Expand Down
16 changes: 16 additions & 0 deletions .github/workflows/actionlint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,9 @@ name: actionlint

on:
pull_request:
schedule:
- cron: "5 4 * * 1-5"
timezone: "Europe/Berlin"

jobs:
actionlint:
Expand All @@ -11,3 +14,16 @@ jobs:
contents: read
steps:
- uses: it-at-m/lhm_actions/action-templates/actions/action-actionlint@4ed8f906bab8111fbd9a7af8e3f4129f9b721757 # v1.2.3

handlefailure:
needs:
- actionlint
runs-on: ubuntu-latest
permissions: {}
if: failure() && (github.event_name == 'schedule' || github.ref == format('refs/heads/{0}', github.event.repository.default_branch))
steps:
- name: Notify Webex
run: |
curl -X POST -H "Content-Type: application/json" \
-d '{"markdown" : "${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} ${{ github.workflow }} failed"}' \
"https://webexapis.com/v1/webhooks/incoming/${{ secrets.WEBEX_TOKEN }}"
Comment thread
ejcsid marked this conversation as resolved.
Dismissed
19 changes: 18 additions & 1 deletion .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,10 @@ on:
pull_request:
push:
branches:
- "main"
- "sps-test-main"
schedule:
- cron: "10 4 * * 1-5"
timezone: "Europe/Berlin"

jobs:
# JOB to run change detection
Expand Down Expand Up @@ -74,3 +77,17 @@ jobs:
registry-username: ${{ github.actor }}
image-tags: |
type=raw,value=dev
handlefailure:
needs:
- build-check-changed-files
- build
runs-on: ubuntu-latest
permissions: {}
if: failure() && (github.event_name == 'schedule' || github.ref == format('refs/heads/{0}', github.event.repository.default_branch))
steps:
- name: Notify Webex
run: |
curl -X POST -H "Content-Type: application/json" \
-d '{"markdown" : "${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} ${{ github.workflow }} failed"}' \
"https://webexapis.com/v1/webhooks/incoming/${{ secrets.WEBEX_TOKEN }}"
Comment thread
ejcsid marked this conversation as resolved.
Dismissed
21 changes: 20 additions & 1 deletion .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,10 @@ on:
pull_request:
push:
branches:
- "main" # Runs on main in order to keep the regular scanning by GitHub working
- "sps-test-main"
schedule:
- cron: "15 4 * * 1-5"
timezone: "Europe/Berlin"

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
Expand Down Expand Up @@ -88,3 +91,19 @@ jobs:
with:
codeql-language: python
codeql-query: ${{ env.analysis-query }}

handlefailure:
needs:
- codeql-check-changed-files
- codeql-java
- codeql-javascript-typescript-vue
- codeql-python
runs-on: ubuntu-latest
permissions: {}
if: failure() && (github.event_name == 'schedule' || github.ref == format('refs/heads/{0}', github.event.repository.default_branch))
steps:
- name: Notify Webex
run: |
curl -X POST -H "Content-Type: application/json" \
-d '{"markdown" : "${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} ${{ github.workflow }} failed"}' \
"https://webexapis.com/v1/webhooks/incoming/${{ secrets.WEBEX_TOKEN }}"
13 changes: 13 additions & 0 deletions .github/workflows/dependency-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,3 +12,16 @@ jobs:
pull-requests: write
steps:
- uses: it-at-m/lhm_actions/action-templates/actions/action-dependency-review@4ed8f906bab8111fbd9a7af8e3f4129f9b721757 # v1.2.3

handlefailure:
needs:
- dependency-review
runs-on: ubuntu-latest
permissions: {}
if: failure() && (github.event_name == 'schedule' || github.ref == format('refs/heads/{0}', github.event.repository.default_branch))
steps:
- name: Notify Webex
run: |
curl -X POST -H "Content-Type: application/json" \
-d '{"markdown" : "${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} ${{ github.workflow }} failed"}' \
"https://webexapis.com/v1/webhooks/incoming/${{ secrets.WEBEX_TOKEN }}"
Comment thread
ejcsid marked this conversation as resolved.
Dismissed
18 changes: 17 additions & 1 deletion .github/workflows/deploy-docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,14 +5,17 @@ on:
# Runs on pushes to any branch when changes are made to docs or workflow
push:
branches:
- main
- sps-test-main
paths:
- "docs/**"
- ".github/workflows/deploy-docs.yml"
Comment on lines +8 to 11

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Do not authorize Pages deployment from the test branch unintentionally.

Pushes to sps-test-main now reach a job with pages: write and id-token: write permissions, while Line 29 still states that deployment is restricted to main. Keep deployment restricted to the production branch, or add an explicit environment/condition for test-branch deployments.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/deploy-docs.yml around lines 8 - 11, Update the workflow
trigger and deployment authorization around the production-branch restriction so
pushes to sps-test-main cannot run the Pages deployment job with pages: write or
id-token: write permissions. Keep deployment limited to main, or add an explicit
environment and condition that prevents unintended test-branch deployments.

pull_request:
paths:
- "docs/**"
- ".github/workflows/deploy-docs.yml"
schedule:
- cron: "25 4 * * 1-5"
timezone: "Europe/Berlin"

jobs:
deploy-docs:
Expand All @@ -25,3 +28,16 @@ jobs:
- uses: it-at-m/lhm_actions/action-templates/actions/action-build-docs@4ed8f906bab8111fbd9a7af8e3f4129f9b721757 # v1.2.3
# Only deploy documentation from the main branch to prevent unauthorized changes
- uses: it-at-m/lhm_actions/action-templates/actions/action-deploy-docs@4ed8f906bab8111fbd9a7af8e3f4129f9b721757 # v1.2.3

handlefailure:
needs:
- deploy-docs
runs-on: ubuntu-latest
permissions: {}
if: failure() && (github.event_name == 'schedule' || github.ref == format('refs/heads/{0}', github.event.repository.default_branch))
steps:
- name: Notify Webex
run: |
curl -X POST -H "Content-Type: application/json" \
-d '{"markdown" : "${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} ${{ github.workflow }} failed"}' \
"https://webexapis.com/v1/webhooks/incoming/${{ secrets.WEBEX_TOKEN }}"
Comment thread
ejcsid marked this conversation as resolved.
Dismissed
16 changes: 16 additions & 0 deletions .github/workflows/dockercompose-healthcheck.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,9 @@ name: dockercompose-healthcheck

on:
pull_request:
schedule:
- cron: "30 4 * * 1-5"
timezone: "Europe/Berlin"

jobs:
dockercompose-healthcheck:
Expand All @@ -14,3 +17,16 @@ jobs:
with:
skip-exited: true # required for keycloakmigration init container
compose-file-path: "./stack/"

handlefailure:
needs:
- dockercompose-healthcheck
runs-on: ubuntu-latest
permissions: {}
if: failure() && (github.event_name == 'schedule' || github.ref == format('refs/heads/{0}', github.event.repository.default_branch))
steps:
- name: Notify Webex
run: |
curl -X POST -H "Content-Type: application/json" \
-d '{"markdown" : "${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} ${{ github.workflow }} failed"}' \
"https://webexapis.com/v1/webhooks/incoming/${{ secrets.WEBEX_TOKEN }}"
Comment thread
ejcsid marked this conversation as resolved.
Dismissed
18 changes: 17 additions & 1 deletion .github/workflows/pr-labeler.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,10 @@
# Workflow to assign appropriate labels to PRs
name: pr-labeler
on:
- pull_request_target
pull_request_target:
schedule:
- cron: "35 4 * * 1-5"
timezone: "Europe/Berlin"

jobs:
pr-labeler:
Expand All @@ -12,3 +15,16 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: it-at-m/lhm_actions/action-templates/actions/action-pr-labeler@4ed8f906bab8111fbd9a7af8e3f4129f9b721757 # v1.2.3

handlefailure:
needs:
- pr-labeler
runs-on: ubuntu-latest
permissions: {}
if: failure() && (github.event_name == 'schedule' || github.ref == format('refs/heads/{0}', github.event.repository.default_branch))
steps:
- name: Notify Webex
run: |
curl -X POST -H "Content-Type: application/json" \
-d '{"markdown" : "${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} ${{ github.workflow }} failed"}' \
"https://webexapis.com/v1/webhooks/incoming/${{ secrets.WEBEX_TOKEN }}"
Comment thread
ejcsid marked this conversation as resolved.
Dismissed
39 changes: 31 additions & 8 deletions .github/workflows/release-maven.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,14 @@ on:
options: # Add or modify paths according to your project structure
- backend
- eai
# schedule:
# - cron: "40 4 * * 1-5"
# timezone: "Europe/Berlin"

env:
DEFAULT_RELEASE_VERSION: "0.0.3"
DEFAULT_DEVELOPMENT_VERSION: "0.0.4-SNAPSHOT"
DEFAULT_APP_PATH: "backend"

jobs:
release-maven-artifact:
Expand All @@ -33,9 +41,9 @@ jobs:
- id: release-maven-artifact
uses: it-at-m/lhm_actions/action-templates/actions/action-maven-release@4ed8f906bab8111fbd9a7af8e3f4129f9b721757 # v1.2.3
with:
app-path: ${{ inputs.app-path }}
releaseVersion: ${{ inputs.release-version }}
developmentVersion: ${{ inputs.development-version }}
app-path: ${{ inputs.app-path || env.DEFAULT_APP_PATH }}
releaseVersion: ${{ inputs.release-version || env.DEFAULT_RELEASE_VERSION }}
developmentVersion: ${{ inputs.development-version || env.DEFAULT_DEVELOPMENT_VERSION }}
use-pr: "true"
# the following variables are necessary to publish the packages to maven central
# docs: https://it-at-m.github.io/lhm_actions/workflows.html#maven-central
Expand All @@ -53,11 +61,11 @@ jobs:
steps:
- uses: it-at-m/lhm_actions/action-templates/actions/action-build-image@4ed8f906bab8111fbd9a7af8e3f4129f9b721757 # v1.2.3
with:
path: ${{ inputs.app-path }}
path: ${{ github.event.inputs.app-path || env.DEFAULT_APP_PATH }}
artifact-name: ${{ needs.release-maven-artifact.outputs.ARTIFACT_NAME }}
image-name: ${{ inputs.app-path }}
image-name: ${{ inputs.app-path || env.DEFAULT_APP_PATH }}
image-tags: |
type=semver,pattern={{version}},value=${{ inputs.release-version }}
type=semver,pattern={{version}},value=${{ inputs.release-version || env.DEFAULT_RELEASE_VERSION }}
type=raw,value=latest
registry-username: ${{ github.actor }}
registry-password: ${{ secrets.GITHUB_TOKEN }}
Expand All @@ -71,6 +79,21 @@ jobs:
- uses: it-at-m/lhm_actions/action-templates/actions/action-create-github-release@4ed8f906bab8111fbd9a7af8e3f4129f9b721757 # v1.2.3
with:
artifact-name: ${{ needs.release-maven-artifact.outputs.ARTIFACT_NAME }}
artifact-path: ${{ inputs.app-path }}/target/*.jar
tag-name: ${{ inputs.app-path }}-${{ inputs.release-version }}
tag-name: ${{ inputs.app-path || env.DEFAULT_APP_PATH }}-${{ inputs.release-version || env.DEFAULT_RELEASE_VERSION }}
generate-release-notes: true
artifact-path: ${{ github.event.inputs.app-path || env.DEFAULT_APP_PATH }}/target/*.jar

handlefailure:
needs:
- release-maven-artifact
- release-maven-image
- release-maven-github
runs-on: ubuntu-latest
permissions: {}
if: failure() && (github.event_name == 'schedule' || github.ref == format('refs/heads/{0}', github.event.repository.default_branch))
steps:
- name: Notify Webex
run: |
curl -X POST -H "Content-Type: application/json" \
-d '{"markdown" : "${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} ${{ github.workflow }} failed"}' \
"https://webexapis.com/v1/webhooks/incoming/${{ secrets.WEBEX_TOKEN }}"
Comment thread
ejcsid marked this conversation as resolved.
Dismissed
Loading
Loading