Skip to content
This repository was archived by the owner on Aug 12, 2026. It is now read-only.
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
81 commits
Select commit Hold shift + click to select a range
a58cc24
Merge pull request #1 from contentstack/feat/ECO-188_added_json_viewer
kego1992 Oct 27, 2021
804c701
Merge pull request #2 from contentstack/feat/ss/ECO-251-fix-housec-sr…
ssurabhi10 Oct 28, 2021
c075e94
Merge pull request #4 from contentstack/feat/ss/ECO-251-fix-housec-sr…
ssurabhi10 Nov 2, 2021
9ff50ea
Merge pull request #3 from contentstack/feat/ECO-188_added_json_viewer
Amitkanswal Nov 10, 2021
ec60e8d
Merge pull request #6 from contentstack/staging
Amitkanswal Nov 11, 2021
a207c39
Create CODEOWNERS
nandeesh-gajula Nov 12, 2021
e2de1f5
feat:updated env variable [ECO-270]
Amitkanswal Nov 12, 2021
b0e5973
feat:updated env variable [ECO-270]
Amitkanswal Nov 12, 2021
c7fcdcd
fix:changed env variable [ECO-270]
Amitkanswal Nov 16, 2021
2774b4c
fix:remove unused config [ECO-270]
Amitkanswal Nov 17, 2021
ca88f7e
fix:updated env-sample [ECO-270]
Amitkanswal Nov 18, 2021
c8da35c
fix:added comment in env [ECO-270]
Amitkanswal Nov 18, 2021
b12b6a6
fix:bugfix for env config [ECO-350]
Amitkanswal Nov 22, 2021
18ae457
fix:updated version and remove logs [ECO-350]
Amitkanswal Nov 22, 2021
bfa61f1
Merge pull request #10 from contentstack/fix/ECO-350_bugfix_for_envCo…
Amitkanswal Nov 22, 2021
47d5730
feat:replace RTE with JSON RTE [ECO-184]
Amitkanswal Nov 24, 2021
52a2757
feat:updated header and sdk code [ECO-184]
Amitkanswal Nov 24, 2021
056276c
fix:updated version [ECO-184]
Amitkanswal Nov 25, 2021
58ee2b3
Merge pull request #11 from contentstack/feat/ECO-184_added_json_rte
Amitkanswal Nov 25, 2021
da06f50
Revert "Merge pull request #11 from contentstack/feat/ECO-184_added_j…
Amitkanswal Nov 25, 2021
266f3b2
Merge pull request #12 from contentstack/staging
Amitkanswal Dec 17, 2021
e5082bf
feat:replace rte with json rte [ECO-184]
Amitkanswal Dec 20, 2021
5811c5f
Merge pull request #13 from contentstack/feat/ECO-184_json_rte_field
Amitkanswal Dec 20, 2021
214fd08
Merge pull request #14 from contentstack/staging
Amitkanswal Dec 21, 2021
e21ab08
fix: updated dependency versions [ECO-535]
Amitkanswal Jan 17, 2022
67b6ee6
Merge pull request #15 from contentstack/fix/ECO-535_updated_dependen…
Amitkanswal Jan 24, 2022
38f1bd5
Merge pull request #18 from contentstack/staging
Amitkanswal Jan 24, 2022
9aaf94a
feat:added live preview [ECO-507]
Amitkanswal Feb 9, 2022
0af0248
fix:updated package [ECO-507]
Amitkanswal Feb 9, 2022
64887e8
fix:updated livepreview lib [ECO-507]
Amitkanswal Feb 9, 2022
0c712a1
Merge pull request #21 from contentstack/feat/ECO-507_std_live_preview
Amitkanswal Feb 9, 2022
69ece26
fix: resolved issue with package lock in stencil [ECO-687]
amit-kanswal-cs Feb 11, 2022
c2950a9
Merge pull request #22 from contentstack/fix/ECO-687_package-lock-ste…
Amitkanswal Feb 11, 2022
b1851a6
docs:updated env sample
amit-kanswal-cs Feb 11, 2022
e398df2
Merge pull request #23 from contentstack/fix/ECO-687_package-lock-ste…
Amitkanswal Feb 14, 2022
8a231c6
doc:updated env.sample file for config [ECO-507]
Amitkanswal Feb 14, 2022
0363f94
Merge pull request #24 from contentstack/fix/ECO-687_package-lock-ste…
Amitkanswal Feb 14, 2022
ba6374d
Merge branch 'main' into staging
Amitkanswal Feb 15, 2022
9cdac21
Merge pull request #25 from contentstack/staging
Amitkanswal Feb 15, 2022
b592663
fix: resolve npm audit issue [ECO-580]
karantalapalli Mar 8, 2022
cf76511
Merge pull request #26 from contentstack/fix/ECO-580_resolve_npm_audi…
kego1992 Mar 9, 2022
12c29a0
Merge pull request #27 from contentstack/staging
karantalapalli Mar 30, 2022
017f030
feat:dynamic page generation [ECO-887]
amit-kanswal-cs Apr 14, 2022
1537967
fix:live edit button [ECO-887]
amit-kanswal-cs Apr 18, 2022
0b9e8dd
fix:removed logs [ECO-887]
amit-kanswal-cs Apr 18, 2022
c8dfb81
fix:live preview fixes
amit-kanswal-cs Apr 19, 2022
17248a4
fix:removed page,blog option from store
amit-kanswal-cs Apr 19, 2022
4394728
Merge pull request #29 from contentstack/feat/ECO-887-dynamic-page
Amitkanswal Apr 19, 2022
2c31809
fix:edit button fix [ECO-930]
amit-kanswal-cs Apr 20, 2022
31f7de3
Merge pull request #30 from contentstack/fix/ECO-930-edit-button
Amitkanswal Apr 20, 2022
d1f4b6d
docs:added security.md file
Amitkanswal Apr 21, 2022
6ff5aa2
Merge pull request #31 from contentstack/doc/added-security-file
Amitkanswal Apr 21, 2022
6350a6c
Merge pull request #32 from contentstack/staging
Amitkanswal Apr 25, 2022
3ebe5de
docs: add region support doc to readme [ECO-892]
karantalapalli Apr 26, 2022
ea21f70
update instrcution for region support
karantalapalli Apr 27, 2022
00f9989
Merge pull request #33 from contentstack/docs/ECO-892_add_region_supp…
karantalapalli Jun 1, 2022
cc2a701
Merge pull request #34 from contentstack/staging
karantalapalli Jun 1, 2022
23e391c
feature: add typescript [ECO-1097]
karantalapalli Jun 6, 2022
a78568e
Create codeql-analysis.yml
contentstack-admin Jun 14, 2022
1595795
Add files via upload
contentstack-admin Jun 14, 2022
03e6309
Merge pull request #35 from contentstack/feature/ECO-1097_add_typescript
karantalapalli Jun 15, 2022
8b3eec6
Merge pull request #36 from contentstack/staging
karantalapalli Jun 15, 2022
eb2c664
fix/ECO-1189-updated all libraries
Jul 15, 2022
6b213e9
added npmrc to resolve peer dependency
Jul 18, 2022
19cfdb5
removed npmrc
Jul 18, 2022
04ebc39
version update
Jul 18, 2022
3f3154e
Merge pull request #39 from contentstack/fix/ECO-1189_upgrade_all_lib…
akashbhosale97 Jul 18, 2022
ecdd42a
Merge pull request #40 from contentstack/staging
akashbhosale97 Jul 20, 2022
b3f25bc
Delete sca-monitor.yml
Aravind-Kumar-cstk Sep 15, 2022
0900f26
codeql-analysis.yml
Aravind-Kumar-cstk Sep 15, 2022
8171f33
sast-scan.yml
Aravind-Kumar-cstk Sep 15, 2022
87246f5
sca-scan.yml
Aravind-Kumar-cstk Sep 15, 2022
fb60612
secrets-scan.yml
Aravind-Kumar-cstk Sep 15, 2022
7a6d759
codeql-analysis.yml
Aravind-Kumar-cstk Sep 21, 2022
bfa0278
sast-scan.yml
Aravind-Kumar-cstk Sep 21, 2022
6a9aa24
sca-scan.yml
Aravind-Kumar-cstk Sep 21, 2022
0d17517
secrets-scan.yml
Aravind-Kumar-cstk Sep 21, 2022
425bf77
jira.yml
Aravind-Kumar-cstk Oct 3, 2022
d313270
jira.yml
Aravind-Kumar-cstk Oct 4, 2022
e89ca2c
jira.yml
Aravind-Kumar-cstk Nov 4, 2022
a1c3370
build(deps): bump json5 from 2.2.1 to 2.2.3
dependabot[bot] Jan 9, 2023
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 0 additions & 6 deletions .env-sample

This file was deleted.

21 changes: 21 additions & 0 deletions .env.sample
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@

# create a file name it as .env for stencil starter app
# copy & paste below content to the newly created env file.

CONTENTSTACK_API_KEY= YOUR_API_KEY
CONTENTSTACK_DELIVERY_TOKEN= YOUR_DELIVERY_TOKEN
CONTENTSTACK_ENVIRONMENT= YOUR_PUBLISHING_ENVIRONMENT

# For live preview
CONTENTSTACK_MANAGEMENT_TOKEN=YOUR_MANAGEMENT_TOKEN
CONTENTSTACK_API_HOST=api.contentstack.io
CONTENTSTACK_APP_HOST=app.contentstack.com

CONTENTSTACK_LIVE_PREVIEW=true
CONTENTSTACK_LIVE_EDIT_TAGS=false
#Enable Live Preview

# For disabling live preview for this project set CONTENTSTACK_LIVE_PREVIEW=false
# For enabling live editing tags for this project set CONTENTSTACK_LIVE_EDIT_TAGS=true
# For EU region add CONTENTSTACK_APP_HOST=eu-app.contentstack.com
# For setting custom host add CONTENTSTACK_API_HOST=for(NA: api.contentstack.io, EU: eu-api.contentstack.com)
68 changes: 68 additions & 0 deletions .github/workflows/codeql-analysis.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,68 @@
# For most projects, this workflow file will not need changing; you simply need
# to commit it to your repository.
#
# You may wish to alter this file to override the set of languages analyzed,
# or to provide custom queries or build logic.
#
# ******** NOTE ********
# We have attempted to detect the languages in your repository. Please check
# the `language` matrix defined below to confirm you have the correct set of
# supported CodeQL languages.
#
name: "CodeQL"

on:
pull_request:
# The branches below must be a subset of the branches above
branches: '*'

jobs:
analyze:
name: Analyze
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write

strategy:
fail-fast: false
matrix:
language: [ 'javascript' ]
# CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python', 'ruby' ]
# Learn more about CodeQL language support at https://aka.ms/codeql-docs/language-support

steps:
- name: Checkout repository
uses: actions/checkout@v3

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v2
with:
languages: ${{ matrix.language }}
# If you wish to specify custom queries, you can do so here or in a config file.
# By default, queries listed here will override any specified in a config file.
# Prefix the list here with "+" to use these queries and those in the config file.

# Details on CodeQL's query packs refer to : https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
# queries: security-extended,security-and-quality


# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
# If this step fails, then you should remove it and run the build manually (see below)
- name: Autobuild
uses: github/codeql-action/autobuild@v2

# ℹ️ Command-line programs to run using the OS shell.
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun

# If the Autobuild fails above, remove it and uncomment the following three lines.
# modify them (or add more) to build your code if your project, please refer to the EXAMPLE below for guidance.

# - run: |
# echo "Run, Build Application using script"
# ./location_of_script_within_repo/buildscript.sh

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v2
28 changes: 28 additions & 0 deletions .github/workflows/jira.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
name: Create JIRA ISSUE
on:
pull_request:
types: [opened]
jobs:
security:
if: ${{ github.actor == 'dependabot[bot]' || github.actor == 'snyk-bot' || contains(github.event.pull_request.head.ref, 'snyk-fix-') || contains(github.event.pull_request.head.ref, 'snyk-upgrade-')}}
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- name: Login into JIRA
uses: atlassian/gajira-login@master
env:
JIRA_BASE_URL: ${{ secrets.JIRA_BASE_URL }}
JIRA_USER_EMAIL: ${{ secrets.JIRA_USER_EMAIL }}
JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}
- name: Create a JIRA Issue
id: create
uses: atlassian/gajira-create@master
with:
project: ${{ secrets.JIRA_PROJECT }}
issuetype: ${{ secrets.JIRA_ISSUE_TYPE }}
summary: |
${{ github.event.pull_request.title }}
description: |
PR: ${{ github.event.pull_request.html_url }}

fields: "${{ secrets.JIRA_FIELDS }}"
11 changes: 11 additions & 0 deletions .github/workflows/sast-scan.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
name: SAST Scan
on:
pull_request:
types: [opened, synchronize, reopened]
jobs:
security:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- name: Horusec Scan
run: docker run -v /var/run/docker.sock:/var/run/docker.sock -v $(pwd):/src horuszup/horusec-cli:latest horusec start -p /src -P $(pwd)
15 changes: 15 additions & 0 deletions .github/workflows/sca-scan.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
name: Source Composition Analysis Scan
on:
pull_request:
types: [opened, synchronize, reopened]
jobs:
security:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@master
- name: Run Snyk to check for vulnerabilities
uses: snyk/actions/node@master
env:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
with:
args: --all-projects
11 changes: 11 additions & 0 deletions .github/workflows/secrets-scan.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
name: Secrets Scan
on:
pull_request:
types: [opened, synchronize, reopened]
jobs:
security:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- name: Gittyleaks
uses: gupy-io/gittyleaks-action@v0.1
2 changes: 0 additions & 2 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -25,5 +25,3 @@ Thumbs.db
UserInterfaceState.xcuserstate
.env
.vercel

.talismanrc
1 change: 1 addition & 0 deletions CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
* @contentstack/security-admin @contentstack/ecosystem-admin
2 changes: 1 addition & 1 deletion LICENSE
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
MIT License

Copyright (c) 2021 Contentstack
Copyright (c) 2022 Contentstack

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
Expand Down
27 changes: 27 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
## Security

Contentstack takes the security of our software products and services seriously, which includes all source code repositories managed through our GitHub organizations.

If you believe you have found a security vulnerability in any Contentstack-owned repository, please report it to us as described below.

## Reporting Security Issues

**Please do not report security vulnerabilities through public GitHub issues.**

Send email to [security@contentstack.com](mailto:security@contentstack.com).

You should receive a response within 24 hours. If for some reason you do not, please follow up via email to ensure we received your original message.

Please include the requested information listed below (as much as you can provide) to help us better understand the nature and scope of the possible issue:

* Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)
* Full paths of source file(s) related to the manifestation of the issue
* The location of the affected source code (tag/branch/commit or direct URL)
* Any special configuration required to reproduce the issue
* Step-by-step instructions to reproduce the issue
* Proof-of-concept or exploit code (if possible)
* Impact of the issue, including how an attacker might exploit the issue

This information will help us triage your report more quickly.

[https://www.contentstack.com/trust/](https://www.contentstack.com/trust/)
Loading