Commit Graph

7635 Commits

Author SHA1 Message Date
Yelninei 8686820c1a CMake (Hurd): Define O_PATH to O_NORW.
This is a noop because O_RW is 0 but O_NORW is the correct constant to
open a file without read/write permissions.
2026-08-07 02:23:29 -05:00
Carter Li 39b3dc001a CMake: adds C23 feature detection and compatibility workarounds for Apple clang 17 2026-08-07 11:00:12 +08:00
Carter Li ba60d7975c Camera (macOS): simplifies code 2026-08-07 09:37:39 +08:00
Carter Li 51a4f34bb5 Codec (macOS): fixes a symbol not found error when running on 10.15 2026-08-07 09:37:39 +08:00
Carter Li 01bb73b9e8 Packaging: updates debian stuff [ci skip] 2026-08-06 16:40:38 +08:00
Carter Li 56da8f8110 Merge pull request #2497 from fastfetch-cli/dev 2.67.0 2026-08-06 03:07:26 -05:00
dependabot[bot] 6d6302e327 CI: Bump the github-actions group with 2 updates
Bumps the github-actions group with 2 updates: [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) and [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request).


Updates `docker/setup-qemu-action` from 4.1.0 to 4.2.0
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](https://github.com/docker/setup-qemu-action/compare/06116385d9baf250c9f4dcb4858b16962ea869c3...96fe6ef7f33517b61c61be40b68a1882f3264fb8)

Updates `signpath/github-action-submit-signing-request` from 1.3 to 2.2
- [Release notes](https://github.com/signpath/github-action-submit-signing-request/releases)
- [Commits](https://github.com/signpath/github-action-submit-signing-request/compare/ced31329c0317e779dad2eec2a7c3bb46ea1343e...b9d91eadd323de506c0c81cf0c7fe7438f3360fd)

---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: signpath/github-action-submit-signing-request
  dependency-version: '2.2'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-05 21:28:37 -05:00
Carter Li 20277b9ee9 CI: adds dependabot.yml 2026-08-06 10:17:14 +08:00
Thibaud-Vdb b6d95a0ce5 CI: declares least-privilege token permissions
Jobs without a permissions block get the repository's default token
scope, and reusable workflow calls pass the caller's grants straight
through. Scopes are now derived from what each workflow actually does
with the token:

- every build workflow declares contents: read; none of them writes
  through the GITHUB_TOKEN.
- build-linux-hosts.yml keeps security-events: write for the CodeQL
  upload; the other callers had that grant too but never upload
  scanning results, so they drop it.
- build-windows-hosts.yml gets actions: read, which the SignPath
  action documents needing to read job details and download the
  unsigned artifact.
- build-release.yml declares contents: write, matching the grant its
  caller already makes for creating the release.

Runs that execute pull request code now hold a token that can do
nothing but read the repository.
2026-08-05 20:59:02 -05:00
Thibaud-Vdb daf5421be7 CI: passes only the secret each reusable workflow needs
Every reusable workflow call used 'secrets: inherit', which hands the
caller's whole secret set to the called workflow, but the only secret
any of them reads is SIGNPATH_API_TOKEN in build-windows-hosts.yml.
Passing that one secret explicitly and dropping inherit everywhere else
means a compromised step in, say, a BSD build VM has no signing token
to steal, and the workflow files now show exactly which secret flows
where.

The secret is declared optional in the reusable workflow so runs
without it (pull requests, forks) behave as before; the signing step
is already guarded to upstream push events.
2026-08-05 20:59:02 -05:00
Thibaud-Vdb b739dfee0b CI: pins actions to commit SHAs
A version tag like @v1 or a branch like @master is a movable pointer:
whoever controls the action repository can re-point it, and the next
run executes whatever it points at. Several of these actions run in
jobs whose outputs ship to users: build-release.yml creates the GitHub
release with the downloadable binaries, and build-windows-hosts.yml
holds the SignPath signing token, so a re-pointed tag there could ship
a tampered or wrongly signed release. This is exactly how the
tj-actions/changed-files compromise propagated (CVE-2025-30066).

Pinning by full commit SHA makes the reviewed code the code that runs,
the same way docker/setup-qemu-action is already pinned in
build-linux-vms.yml. Refs that pointed at master (cross-platform-actions,
setup-alpine, get-latest-release) are pinned to their latest release
tag. Every pin keeps a version comment, and each SHA was resolved from
the upstream repository and cross-checked against its release tag.
2026-08-05 20:59:02 -05:00
Carter Li 80101a5803 GenConfig: simplifes code 2026-08-05 15:47:42 +08:00
Carter Li cf33bef128 CI: fixes building 2026-08-05 15:30:32 +08:00
Carter Li 7e786bee31 GenConfig: optimises code 2026-08-05 15:21:39 +08:00
Carter Li cbea6c3cb1 Presets (neofetch): shows board name as host name
... when the real host name is not available
2026-08-05 15:02:47 +08:00
Carter Li 48a234d742 GenConfig: removes unused fflush 2026-08-05 14:49:29 +08:00
Carter Li c271708f7d GenConfig: don't use Unicode string when drawing options 2026-08-05 14:36:42 +08:00
Carter Li b42f11442c GenConfig: improves visibility on light-background terminal 2026-08-05 14:28:49 +08:00
Carter Li 73918956d7 GenConfig: prefers macros instead of hard coded ANSI string 2026-08-05 14:28:49 +08:00
Carter Li 6559c7f42d GenConfig: don't use Unicode chars on niche platforms 2026-08-05 14:28:11 +08:00
Carter Li 56950e790f Merge pull request #2490 from fastfetch-cli/dev
Release v2.67.0
2026-08-04 20:05:50 -05:00
Carter Li e7642ea3a2 GenConfig: honors -s set by users 2026-08-04 23:34:15 +08:00
李通洲 a88ef86ce3 InitSystem (Windows): fixes logic of assertions 2026-08-04 21:15:34 +08:00
李通洲 fcf4aca3b7 Shell: fixes a potencial out-of-bound read 2026-08-04 21:14:48 +08:00
李通洲 3f8d141313 GenConfig: disables the feature on Win 8.1; improves redraw logic 2026-08-04 21:05:07 +08:00
李通洲 97a9be27b9 GenConfig: fixes arrow keys not working in Haiku 2026-08-04 20:17:05 +08:00
李通洲 dc46ecbcac GenConfig: code cleanup 2026-08-04 19:34:14 +08:00
李通洲 984fadf70f Revert "Global: first step to full C++ project"
This reverts commit 241ddb79b0.
2026-08-04 19:19:37 +08:00
李通洲 1a42cbe1cf Common (Format): format 2026-08-04 19:18:23 +08:00
Carter Li 9c7cfb864f Release: v2.67.0 2026-08-04 16:28:33 +08:00
Carter Li 6d795a3572 Fastfetch: adds interactive --gen-config mode
removes `--gen-config-*` flags (merged into `--gen-config`)
2026-08-04 15:32:44 +08:00
Carter Li 2af56232a4 FFlist: adds FF_LIST_INSERT_AT and FF_LIST_REMOVE_AT 2026-08-04 15:08:50 +08:00
Carter Li 3196f5efaa chore: adds defaultOrder to every module's definition 2026-08-04 09:58:31 +08:00
aldahiiir 1626ced83c OS (Linux): detects Ubuntu Studio installed with core mode
The minimal (core) installation ships the `ubuntustudio-desktop-core`
metapackage instead of `ubuntustudio-desktop`, so the existing check
missed it and the system was reported as Kubuntu.

Fixes #2485
2026-08-03 20:01:47 +08:00
李通洲 241ddb79b0 Global: first step to full C++ project 2026-08-03 20:00:27 +08:00
李通洲 66ce39e3fc Shell (Windows): fixes incompatibility with the newest fish version 2026-08-02 22:02:54 +08:00
李通洲 3fae9e0274 Libc (Windows): simplifies code 2026-07-31 23:12:10 +08:00
李通洲 5eaf98ecd2 Common: forces optionBuf to be 8-byte aligned 2026-07-29 20:15:54 +08:00
Carter Li 00b7c5b56c Netif (Hurd): fixes a compiler warning 2026-07-28 23:42:08 +08:00
李通洲 305ab14e7b DisplayServer (Linux): don't assume the monitor has only one preferred mode
Fixes #2481
2026-07-28 23:41:07 +08:00
Carter Li a58fc4f77d CI: disable Haiku
Ref: https://github.com/haikuports/haikuports/issues/14445
2026-07-28 15:21:28 +08:00
Carter Li b653ef730d General: removes general.preRun due to security concerns 2026-07-28 15:16:30 +08:00
Carter Li dc464d6efe FFstrbuf: prefers ffStrbufEnsureFree 2026-07-28 14:51:54 +08:00
Carter Li 1c3f0eb7c0 FFstrbuf: adds integer overflow checks to EnsureFreeNoCheck and EnsureFixedLengthFree 2026-07-28 14:51:37 +08:00
Carter Li 476cd67345 Networking: adds Content-Length size limit to prevent excessive memory allocation and potential attacks 2026-07-28 13:29:47 +08:00
Carter Li 2c736697d2 Watch: adds -w/--watch as a seconds-based alias for --dynamic-interval
Closes #2478
2026-07-28 10:52:04 +08:00
Carter Li 738ad59f54 Revert "Weather: replaces aggressive exit(1) with proper error handling (#2474)"
This reverts commit c5a8950ad4.
2026-07-28 10:40:33 +08:00
Carter Li 5476e01407 Revert "PublicIP: replaces exit(1) with proper error status"
This reverts commit 18eef29d0a.
2026-07-28 10:38:53 +08:00
Carter Li 4f0b00116e PublicIP: fixes invalid URL parser 2026-07-28 10:37:36 +08:00
Carter Li 6490e2707f Networking: relaxes accepted response format 2026-07-28 10:31:32 +08:00