1 Commits

Author SHA1 Message Date
unkin-agent bc6d2b218d feat(github): allowlist jellyfin-plugin-sso release assets
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
jellyfin-ha bakes the SSO auth plugin at image build time, but the CI
build network cannot reach github directly. Route it through the
artifactapi github proxy by allowlisting the SSO plugin release asset.
2026-08-26 23:32:07 +10:00
6 changed files with 1 additions and 57 deletions
-2
View File
@@ -1,8 +1,6 @@
when: when:
- event: push - event: push
branch: main branch: main
- event: manual
branch: main
steps: steps:
- name: apply - name: apply
@@ -1,2 +0,0 @@
---
description: "Jellyfin plugin zips built in-house (JPRM release archives published on tag)"
-2
View File
@@ -1,2 +0,0 @@
---
description: "Neovim plugin release archives (<plugin>-<version>.zip) installed by arti-pack"
-6
View File
@@ -1,6 +0,0 @@
base_url: https://git.unkin.net
description: Internal Gitea unkin tag source archives
immutable_ttl: 0
mutable_ttl: 7200
patterns:
- "^unkin/[^/]+/archive/refs/tags/[^/]+\\.zip$"
+1 -39
View File
@@ -3,53 +3,17 @@ description: GitHub releases and files
immutable_ttl: 0 immutable_ttl: 0
mutable_ttl: 7200 mutable_ttl: 7200
mutable_patterns: mutable_patterns:
# Branch archives of tagless Neovim plugins; a branch ref moves, so these - ".*/archive/refs/heads/.*.tar.gz$"
# revalidate on mutable_ttl instead of caching immutably.
- "^HampusHauffman/block\\.nvim/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-buffer/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-nvim-lsp/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-nvim-lsp-signature-help/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-nvim-lua/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-path/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-vsnip/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/vim-vsnip/archive/refs/heads/master\\.(zip|tar\\.gz)$"
- "^junegunn/gv\\.vim/archive/refs/heads/master\\.(zip|tar\\.gz)$"
- "^jvirtanen/vim-hcl/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^Mofiqul/dracula\\.nvim/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^numToStr/FTerm\\.nvim/archive/refs/heads/master\\.(zip|tar\\.gz)$"
- "^qvalentin/helm-ls\\.nvim/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^rafamadriz/friendly-snippets/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "stalwartlabs/webadmin/releases/latest/download/webadmin.zip$" - "stalwartlabs/webadmin/releases/latest/download/webadmin.zip$"
# iplocate IP databases (Git-LFS; the /raw/ path redirects to the LFS media host). # iplocate IP databases (Git-LFS; the /raw/ path redirects to the LFS media host).
- "iplocate/ip-address-databases/raw/.*/ip-to-asn/.*" - "iplocate/ip-address-databases/raw/.*/ip-to-asn/.*"
- "iplocate/ip-address-databases/raw/.*/ip-to-country/.*" - "iplocate/ip-address-databases/raw/.*/ip-to-country/.*"
patterns: patterns:
# Branch archives of Neovim plugins that publish no tags. patterns is a
# strict allowlist checked before mutable_patterns, so each repo must be
# listed in both. Anchored per repo: matching is a substring search, so an
# unanchored entry would also admit evil/<owner>/<repo>/....
- "^HampusHauffman/block\\.nvim/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-buffer/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-nvim-lsp/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-nvim-lsp-signature-help/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-nvim-lua/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-path/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/cmp-vsnip/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^hrsh7th/vim-vsnip/archive/refs/heads/master\\.(zip|tar\\.gz)$"
- "^junegunn/gv\\.vim/archive/refs/heads/master\\.(zip|tar\\.gz)$"
- "^jvirtanen/vim-hcl/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^Mofiqul/dracula\\.nvim/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^numToStr/FTerm\\.nvim/archive/refs/heads/master\\.(zip|tar\\.gz)$"
- "^qvalentin/helm-ls\\.nvim/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- "^rafamadriz/friendly-snippets/archive/refs/heads/main\\.(zip|tar\\.gz)$"
- ".*/archive/refs/tags/.*.tar.gz$" - ".*/archive/refs/tags/.*.tar.gz$"
- ".*/archive/refs/tags/.*\\.zip$"
- "9p4/jellyfin-plugin-sso/.*/sso-authentication_.*.zip$" - "9p4/jellyfin-plugin-sso/.*/sso-authentication_.*.zip$"
- "ahmetb/kubectx/.*/kubectx_.*_linux_x86_64.tar.gz$" - "ahmetb/kubectx/.*/kubectx_.*_linux_x86_64.tar.gz$"
- "ahmetb/kubectx/.*/kubens_.*_linux_x86_64.tar.gz$" - "ahmetb/kubectx/.*/kubens_.*_linux_x86_64.tar.gz$"
- "apple/foundationdb/.*/libfdb_c.x86_64.so$" - "apple/foundationdb/.*/libfdb_c.x86_64.so$"
- "argoproj/argo-cd/.*/argocd-linux-amd64$"
- "argoproj/argo-cd/.*/cli_checksums.txt$"
- "astral-sh/ruff/.*/ruff-x86_64-unknown-linux-gnu.tar.gz$" - "astral-sh/ruff/.*/ruff-x86_64-unknown-linux-gnu.tar.gz$"
- "astral-sh/uv/.*/uv-x86_64-unknown-linux-gnu.tar.gz$" - "astral-sh/uv/.*/uv-x86_64-unknown-linux-gnu.tar.gz$"
- "camptocamp/prometheus-puppetdb-exporter/.*/prometheus-puppetdb-exporter-.*.linux-amd64.tar.gz$" - "camptocamp/prometheus-puppetdb-exporter/.*/prometheus-puppetdb-exporter-.*.linux-amd64.tar.gz$"
@@ -70,8 +34,6 @@ patterns:
- "iplocate/ip-address-databases/raw/.*/ip-to-asn/.*" - "iplocate/ip-address-databases/raw/.*/ip-to-asn/.*"
- "iplocate/ip-address-databases/raw/.*/ip-to-country/.*" - "iplocate/ip-address-databases/raw/.*/ip-to-country/.*"
- "jesseduffield/lazydocker/.*/lazydocker_.*_Linux_x86_64.tar.gz$" - "jesseduffield/lazydocker/.*/lazydocker_.*_Linux_x86_64.tar.gz$"
- "JohnnyMorganz/StyLua/.*/stylua-linux-x86_64\\.zip$"
- "JohnnyMorganz/StyLua/.*/stylua-linux-x86_64-musl\\.zip$"
- "kubecolor/kubecolor/.*/kubecolor_.*_linux_amd64.tar.gz$" - "kubecolor/kubecolor/.*/kubecolor_.*_linux_amd64.tar.gz$"
- "kubernetes-sigs/gateway-api/.*/standard-install.yaml$" - "kubernetes-sigs/gateway-api/.*/standard-install.yaml$"
- "kubernetes-sigs/kustomize/.*/kustomize_.*_linux_amd64.tar.gz$" - "kubernetes-sigs/kustomize/.*/kustomize_.*_linux_amd64.tar.gz$"
-6
View File
@@ -1,6 +0,0 @@
base_url: https://repo.jellyfin.org
description: Jellyfin official plugin repository
immutable_ttl: 0
mutable_ttl: 7200
patterns:
- "files/plugin/ldap-authentication/ldap-authentication_.*.zip$"