Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 7 additions & 7 deletions .github/workflows/container-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,13 +31,13 @@ jobs:

steps:
- name: Check out repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only major version?


- name: Set up Python
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 #v6.2.0
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 #v7.0.0
with:
# renovate: datasource=python-version depName=python
python-version: '3.14.4'
python-version: '3.14.7'

- name: Build Docker image
run: docker build -t ${{ env.IMAGE_NAME }} .
Expand All @@ -57,31 +57,31 @@ jobs:
- name: Upload Trivy SARIF to GitHub Security tab
id: upload_trivy
if: always()
uses: github/codeql-action/upload-sarif@c35d1b164463ee62a100735382aaaa525c5d3496 #v2.25.6
uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 #v4.38.0
with:
sarif_file: ${{ env.TRIVY_SCA_SARIF_OUTPUT }}
category: trivy-container-scanning

- name: Upload OSV Scanner SARIF to GitHub Security tab
id: upload_osv
if: always()
uses: github/codeql-action/upload-sarif@c35d1b164463ee62a100735382aaaa525c5d3496 #v2.25.6
uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 #v4.38.0
with:
sarif_file: ${{ env.OSV_SCA_SARIF_OUTPUT }}
category: osv-scanner-container-scanning

- name: Upload OpenGrep SARIF to GitHub Security tab
id: upload_opengrep
if: always()
uses: github/codeql-action/upload-sarif@c35d1b164463ee62a100735382aaaa525c5d3496 #v2.25.6
uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 #v4.38.0
with:
sarif_file: ${{ env.OPENGREP_SAST_SARIF_OUTPUT }}
category: opengrep-sast

- name: Upload Hadolint SARIF to GitHub Security tab
id: upload_hadolint
if: always()
uses: github/codeql-action/upload-sarif@c35d1b164463ee62a100735382aaaa525c5d3496 #v2.25.6
uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 #v4.38.0
with:
sarif_file: ${{ env.HADOLINT_SAST_SARIF_OUTPUT }}
category: hadolint-sast
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/publish_images.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ jobs:
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 #v7.0.1

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c #v4.2.0
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e #v4.3.0

- name: Harbor connectivity probe
run: |
Expand All @@ -36,7 +36,7 @@ jobs:
sudo sysctl -w net.ipv6.conf.default.disable_ipv6=1

- name: Log in to Docker Hub
uses: docker/login-action@371161bbe7024a29a25c5e19bfcbc0804fe9ad2c #v4.5.2
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f #v4.6.0
with:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_PASSWORD }}
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/sast.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,13 +23,13 @@ jobs:

steps:
- name: Check out repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Set up Python
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 #v6.2.0
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 #v7.0.0
with:
# renovate: datasource=python-version depName=python
python-version: '3.14.4'
python-version: '3.14.7'

- name: Setup tools
run: bash ci/setup-tools.sh --install-tool opengrep,semgrep-rules
Expand All @@ -40,7 +40,7 @@ jobs:
- name: Upload Semgrep SARIF to GitHub Security tab
id: upload_semgrep
if: always()
uses: github/codeql-action/upload-sarif@c35d1b164463ee62a100735382aaaa525c5d3496 #v2.25.6
uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 #v4.38.0
with:
sarif_file: ${{ env.OPENGREP_SARIF_OUTPUT }}
category: semgrep-app
Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/sca.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,13 +23,13 @@ jobs:

steps:
- name: Check out repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Set up Python
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 #v6.2.0
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 #v7.0.0
with:
# renovate: datasource=python-version depName=python
python-version: '3.14.4'
python-version: '3.14.7'

- name: Cache Maven packages
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 #v6.1.0
Expand All @@ -50,15 +50,15 @@ jobs:
- name: Upload Trivy SARIF to GitHub Security tab
id: upload_trivy
if: always()
uses: github/codeql-action/upload-sarif@c35d1b164463ee62a100735382aaaa525c5d3496 #v2.25.6
uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 #v4.38.0
with:
sarif_file: ${{ env.TRIVY_SARIF_OUTPUT }}
category: trivy-app

- name: Upload OSV Scanner SARIF to GitHub Security tab
id: upload_osv
if: always()
uses: github/codeql-action/upload-sarif@c35d1b164463ee62a100735382aaaa525c5d3496 #v2.25.6
uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 #v4.38.0
with:
sarif_file: ${{ env.OSV_SARIF_OUTPUT }}
category: osv-scanner-app
Expand Down
14 changes: 7 additions & 7 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,20 +6,20 @@ This repository contains the Spring Boot backend for the Medical Informatics Pla
## Repository Layout
- `src/main/java/hbp/mip`: application entrypoint and backend code.
- `src/main/java/hbp/mip/configurations`: security, OAuth2/JWT, persistence, OpenAPI, and redirect/filter configuration.
- `src/main/java/hbp/mip/algorithm`: algorithm metadata API/service and disabled algorithm filtering.
- `src/main/java/hbp/mip/algorithm`: algorithm metadata API/service and Exaflow specification passthrough.
- `src/main/java/hbp/mip/datamodel`: data model API/service backed by Exaflow metadata endpoints.
- `src/main/java/hbp/mip/experiment`: experiment API, service, repository, JPA entity, specifications, and DTOs.
- `src/main/java/hbp/mip/user`: active user API/service, user repository, JPA entity, and DTO.
- `src/main/java/hbp/mip/utils`: shared logging, JSON/HTTP helpers, resource loading, claim validation, and exception handling.
- `src/main/java/hbp/mip/folder`: experiment folder/set API, service, repository, JPA entities, and DTOs.
- `src/main/java/hbp/mip/utils`: shared logging, JSON/HTTP helpers, claim validation, and exception handling.
- `src/main/resources`: local runtime config, Log4j2 config, and Flyway migrations under `db/migration`.
- `config/`: container config template and static runtime assets such as `disabledAlgorithms.json`.
- `.github/workflows`: release image publishing and EBRAINS mirror automation.
- `docs/context`: durable repository context for humans and AI coding agents.

## Stack
- Language/runtime: Java 21.
- Build/package manager: Maven (`pom.xml`); no Maven wrapper is committed.
- Frameworks/libraries: Spring Boot 4.0.6, Spring Security 7, OAuth2 client/resource server, Spring Data JPA, Hibernate, Flyway, Gson, Log4j2, springdoc OpenAPI.
- Frameworks/libraries: Spring Boot 4.1.1, Spring Security 7, OAuth2 client/resource server, Spring Data JPA, Hibernate, Flyway, Gson, Log4j2, springdoc OpenAPI.
- Database: PostgreSQL, configured through Spring datasource properties.
- Auth: Keycloak/OIDC when `authentication.enabled` is enabled; anonymous development mode exists when disabled.
- External services: Exaflow endpoints for algorithms, data models, metadata, dataset variables, and algorithm execution.
Expand All @@ -32,7 +32,7 @@ Use a local Java 21 JDK and Maven installation.
mvn -B -ntp dependency:go-offline
```

Local development also expects PostgreSQL and reachable Exaflow/Keycloak endpoints based on `src/main/resources/application.yml`. Unknown / TODO: verify the preferred local database bootstrap command; no Docker Compose or Makefile is committed.
Local development also expects PostgreSQL, reachable Exaflow/Keycloak endpoints, and `MIP_VERSION` set in the environment. Defaults for other settings live in `src/main/resources/application.yml`.

## Development Commands
Run locally with the development config in `src/main/resources/application.yml`:
Expand Down Expand Up @@ -74,12 +74,12 @@ mvn clean package
## Architecture Rules
- Put HTTP endpoints in `*API` classes under the owning feature package.
- Put business logic in `*Service` classes; controllers should delegate rather than implement workflows directly.
- Put persistence in Spring Data repositories and JPA `*DAO` entities. Current JPA packages are `hbp.mip.experiment` and `hbp.mip.user`.
- Put persistence in Spring Data repositories and JPA `*DAO` entities. Current JPA packages are `hbp.mip.experiment`, `hbp.mip.user`, and `hbp.mip.folder` (list them in `PersistenceConfiguration` when adding another).
- Put API/request/response shapes in `*DTO` records or DTO classes close to the feature package.
- Put cross-cutting helpers in `hbp.mip.utils` only when they are genuinely shared.
- Put security, persistence, OpenAPI, and web filter wiring in `hbp.mip.configurations`.
- Keep Flyway migrations in `src/main/resources/db/migration` using `V{number}__Description.sql`.
- Keep runtime/container configuration in `src/main/resources/application.yml` and `config/application.tmpl`; do not read environment variables ad hoc from feature code.
- Keep runtime configuration in `src/main/resources/application.yml` using `${ENV:default}` placeholders; containers override via environment variables. Do not read environment variables ad hoc from feature code.

## Coding Conventions
- Use 4-space Java indentation and existing package style under lowercase `hbp.mip`.
Expand Down
32 changes: 8 additions & 24 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
#######################################################
# Build the spring boot maven project
#######################################################
FROM maven:3.9.11-amazoncorretto-21 AS mvn-build-env
FROM maven:3.9.16-amazoncorretto-21 AS mvn-build-env
LABEL maintainer="Thanasis Karampatsis <tkarabatsis@athenarc.gr>"

ENV CODE_PATH="/opt/code"
Expand All @@ -19,7 +19,7 @@
#######################################################
# Setup the running container
#######################################################
FROM amazoncorretto:21-alpine3.21
FROM amazoncorretto:21-alpine3.24

#######################################################
# Setting up timezone
Expand All @@ -30,47 +30,31 @@
#######################################################
# Setting up environment
#######################################################
ENV APP_CONFIG_TEMPLATE="/opt/config/application.tmpl"
ENV APP_CONFIG_LOCATION="/opt/config/application.yml"
ENV SPRING_CONFIG_LOCATION="file:/opt/config/application.yml"

ENV SERVICE="platform-backend"
ENV FEDERATION="default"
ENV LOG_LEVEL="INFO"
ENV FRAMEWORK_LOG_LEVEL="INFO"

WORKDIR /opt

RUN apk add --no-cache curl

#######################################################
# Install dockerize
#######################################################
ENV DOCKERIZE_VERSION=v0.14.0
RUN wget https://github.com/jwilder/dockerize/releases/download/$DOCKERIZE_VERSION/dockerize-alpine-linux-amd64-$DOCKERIZE_VERSION.tar.gz \
&& tar -C /usr/local/bin -xzvf dockerize-alpine-linux-amd64-$DOCKERIZE_VERSION.tar.gz \
&& rm dockerize-alpine-linux-amd64-$DOCKERIZE_VERSION.tar.gz

# libcrypto3/libssl3 are refreshed because the amazoncorretto base image ships
# openssl 3.5.7-r0, which carries CVE-2026-14456, CVE-2026-63073 and
# CVE-2026-75803 (CVSS >= 8.0, blocks the container SCA gate). Alpine 3.24
# fixes them in openssl 3.5.8-r0.
RUN apk add --no-cache --upgrade libcrypto3 libssl3 curl

#######################################################
# Prepare the spring boot application files
#######################################################
COPY config/application.tmpl $APP_CONFIG_TEMPLATE
COPY --from=mvn-build-env /opt/code/target/platform-backend.jar /usr/share/jars/


#######################################################
# Configuration for the backend config files
#######################################################
ENV DISABLED_ALGORITHMS_CONFIG_PATH="/opt/platform/algorithms/disabledAlgorithms.json"
COPY config/disabledAlgorithms.json $DISABLED_ALGORITHMS_CONFIG_PATH
VOLUME /opt/platform/api

RUN addgroup -S appgroup && adduser -S appuser -G appgroup \
&& mkdir -p /opt/config /opt/platform/api \
&& chown -R appuser:appgroup /opt/config /opt/platform/api /usr/share/jars

USER appuser
ENTRYPOINT ["sh", "-ec", "exec dockerize -template ${APP_CONFIG_TEMPLATE}:${APP_CONFIG_LOCATION} java --add-opens java.base/java.io=ALL-UNNAMED -Daeron.term.buffer.length -jar /usr/share/jars/platform-backend.jar"]
ENTRYPOINT ["java", "--add-opens", "java.base/java.io=ALL-UNNAMED", "-Daeron.term.buffer.length", "-jar", "/usr/share/jars/platform-backend.jar"]
EXPOSE 8080
HEALTHCHECK --start-period=60s CMD curl --fail --silent --show-error http://localhost:8080/services/actuator/health | grep -q '"status":"UP"'
18 changes: 9 additions & 9 deletions ci/setup-tools.sh
Original file line number Diff line number Diff line change
Expand Up @@ -11,27 +11,27 @@ trap 'echo "[setup-tools] ERROR: command failed (exit $?) at line $LINENO: $BASH
# *_SHA256 must be overridden as well or verification will fail.

# renovate: datasource=github-release-attachments depName=aquasecurity/trivy
TRIVY_VERSION="${TRIVY_VERSION:-v0.71.1}"
TRIVY_SHA256="${TRIVY_SHA256:-3cbae37cd440cd8676e5ce9207fe460b5641c7579a17e9d00f8894928c41a88d}"
TRIVY_VERSION="${TRIVY_VERSION:-v0.74.0}"
TRIVY_SHA256="${TRIVY_SHA256:-2ae6fe3ee734b7fdf11335663e18c75ea12dccc76062f09f164a3b0f8be4371a}"

# renovate: datasource=github-release-attachments depName=google/osv-scanner
OSV_SCANNER_VERSION="${OSV_SCANNER_VERSION:-v2.4.0}"
OSV_SCANNER_SHA256="${OSV_SCANNER_SHA256:-15314940c10d26af9c6649f150b8a47c1262e8fc7e17b1d1029b0e479e8ed8a0}"
OSV_SCANNER_VERSION="${OSV_SCANNER_VERSION:-v2.5.1}"
OSV_SCANNER_SHA256="${OSV_SCANNER_SHA256:-f9f25499a2c8cc367b3af45df2ea7eeca7fbccceab9c35079968f4b3652194be}"

# renovate: datasource=github-release-attachments depName=opengrep/opengrep
OPENGREP_VERSION="${OPENGREP_VERSION:-v1.25.0}"
OPENGREP_SHA256="${OPENGREP_SHA256:-9ac4aebb47ba3f7b0d8fc641ac8749cb6c2f253f616131a67d9631e00d4bea33}"
OPENGREP_VERSION="${OPENGREP_VERSION:-v1.30.0}"
OPENGREP_SHA256="${OPENGREP_SHA256:-35779bdd72e92129c8df2a77f0c55e8c08356801ea92591ef32108d6b28d564c}"

# renovate: datasource=github-tags depName=semgrep/semgrep-rules
SEMGREP_RULES_REF="${SEMGREP_RULES_REF:-40b8c63f75dc7c22c8a77482d73bfb864b146f7e}"
SEMGREP_RULES_DIR="semgrep-rules"

# renovate: datasource=github-release-attachments depName=hadolint/hadolint
HADOLINT_VERSION="${HADOLINT_VERSION:-v2.14.0}"
HADOLINT_SHA256="${HADOLINT_SHA256:-6bf226944684f56c84dd014e8b979d27425c0148f61b3bd99bcc6f39e9dc5a47}"
HADOLINT_VERSION="${HADOLINT_VERSION:-v2.15.1}"
HADOLINT_SHA256="${HADOLINT_SHA256:-c7187db94eeeeca956519a6af171adc31453941a1e777961f6e680f697c8c507}"

# renovate: datasource=npm depName=@cyclonedx/cyclonedx-npm
CYCLONEDX_NPM_VERSION="${CYCLONEDX_NPM_VERSION:-6.0.0}"
CYCLONEDX_NPM_VERSION="${CYCLONEDX_NPM_VERSION:-6.0.1}"

TMP_DIR="$(mktemp -d)"
trap 'rm -rf "${TMP_DIR}"' EXIT
Expand Down
9 changes: 5 additions & 4 deletions ci/suppress_osv_scanner.toml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
[[IgnoredVulns]]
id = "GHSA-5jmj-h7xm-6q6v"
ignoreUntil = 2026-09-30
reason = "The proposed fix version 2.21.5 not yet released"
# No active suppressions.
# GHSA-5jmj-h7xm-6q6v was suppressed while the fixed Jackson release did not
# exist; it is fixed upstream and pom.xml now pins Jackson 2.22.2 / 3.2.2, so
# the suppression is gone. Add entries here only with an id, reason and an
# ignoreUntil date.
9 changes: 6 additions & 3 deletions ci/suppress_trivy.yaml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
vulnerabilities:
- id: CVE-2026-54515
statement: "The proposed fix version 2.21.5 not yet released"
# No active suppressions.
# CVE-2026-54515 (GHSA-5jmj-h7xm-6q6v) was suppressed while the fixed Jackson
# release did not exist; it is fixed upstream and pom.xml now pins Jackson
# 2.22.2 / 3.2.2, so the suppression is gone. Add entries here only with a CVE
# id, a reason, and a removal condition.
vulnerabilities: []
76 changes: 0 additions & 76 deletions config/application.tmpl

This file was deleted.

4 changes: 0 additions & 4 deletions config/disabledAlgorithms.json

This file was deleted.

Loading
Loading