No description
Find a file
Sam Limbu ba425e8a87 SEC-01: pin actions/checkout in the deploy workflow to a commit SHA
deploy.yml runs on the self-hosted VPS runner with passwordless sudo, so a
mutable tag on this action is a code-execution path onto that host if the tag
is ever moved. Pinned to the commit v4 currently resolves to
(11d5960a326750d5838078e36cf38b85af677262), verified against upstream — this is
the same code the deploy already runs today, not a version bump. ci.yml is on
v7.0.1; the deploy path is deliberately left on v4 so that pinning does not
smuggle a major-version change into a workflow whose only test is a live deploy.

Raised by Codex review of PR #5 as the one unpinned `uses:` in either workflow.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-27 22:42:29 +10:00
.github/workflows SEC-01: pin actions/checkout in the deploy workflow to a commit SHA 2026-08-27 22:42:29 +10:00
src ensure member is active before receiving member role (#4) 2026-08-17 11:24:13 +10:00
.dockerignore SEC-01: add pull-request CI and stop the deploy leaving DOT_ENV on the VPS 2026-08-27 09:42:31 +10:00
.env.example added row level security 2026-07-09 16:51:50 +10:00
.gitignore updated gitignore, updated thread title to be leetcode titles 2026-08-10 00:32:15 +10:00
Cargo.lock added verification command 2025-11-23 19:24:05 +11:00
Cargo.toml removed Arc 2025-11-29 18:12:23 +08:00
docker-compose.yml dockerized successfully 2025-11-10 15:12:21 +11:00
Dockerfile SEC-01: add pull-request CI and stop the deploy leaving DOT_ENV on the VPS 2026-08-27 09:42:31 +10:00
LICENSE updated license 2025-11-22 10:04:16 +11:00
README.md updated serverinfo and info files 2025-11-12 13:02:27 +11:00

DSEC Discord Bot

Deakin Software Engineering Club Discord Bot project. To encourage students to learn Rust and how to work in a practical and collaborative project.

Setup

Setup Rust

Installing Rustup will also install cargo

Linux & MacOS:

curl https://sh.rustup.rs -sSf | sh

Windows:

Download and run rustup-init.exe

Setup Discord Bot Profile on Discord Developers

Note: To contribute, you need to create your own Discord Bot profile and test it yourself in another server.

  1. Open Discord Developers and click on "Get Started"

  2. Create a New Application, with any name you like

  3. Navigate to Bot on the left sidebar

    • Note down the Token, the code of your bot will require it.
    • Enable all the Intents Presence, Server Members, Message Content
      • This is required by Discord to ensure popular discord bots do not scrape server message contents without permission.
  4. Generate a Discord Bot URL:

    1. Navigate to OAuth2 on the left sidebar
    2. Scroll down to OAuth2 URL Generator
    3. Under Scopes, select bot
    4. Scroll down to Bot Permissions
    5. Select permissions, or later override it in the invite link.
    • DSEC Bot's Permission integer is 4235288712703990.
    1. Copy the Generated URL, and invite your bot to your Discord server.

    OR

    1. https://discord.com/oauth2/authorize?client_id=DISCORD_BOT_ID&permissions=4235288712703990&integration_type=0&scope=bot

Setup Discord Bot on your machine

Rust with Cargo

  1. Navigate to directory on your machine
  2. git clone https://github.com/liyunze-coding/DSEC-Discord-Bot
  3. Create .env file according to .env.example
  • You can ask the committee (or Ryan) for the environment variables on Discord.
  1. Run cargo run
  2. You may need to reload Discord to see changes to slash commands.

Or Use Docker

  1. Make sure Docker engine is running.
    • On Windows, open Docker Desktop.
  2. Run the commands
docker-compose build
docker-compose up

Rules

General Rules

  • Follow DSEC Server Rules
  • Follow Deakin Code of Conduct
  • Follow Discord Terms of Services

Programming Rules

  • Do not test in Production
  • Do not write malicious code (unless you have obtained permission for white hat hacking)
  • Do not spam pull requests
  • Do not add your own code formatter, affecting the whole files you edit

To-do

  • Membership verification command
  • Unit information command

Information

What is Rust?

Rust is memory safe yet performant, making it the ideal programming language for systems programming.

C and C++ require developers to manage memory allocation, which can lead to memory unsafe programs.

Python, Java, C# and Go use the garbage collector so that developers don't need to manually manage memory, but can slow down the program significantly due to lack of low level control.

Rust takes a unique approach, by using an "ownership" and "borrowing" system to prevent memory bugs at compile time.

Hence, Rust is performant and memory safe (when you write it well).

Why Rust?

This is a good opportunity for students at Deakin to learn Rust.

At Deakin, Software Engineering, Computer Science and IT students mostly touch on high level languages such as Python, C# and low level languages such as C++.

More and more developer tools are being written in Rust, including Rolldown, Rspack, Tauri, SWC and many more (Ryan is a web developer, he's only aware of these tools written in Rust).

Rust has its own unique concepts and challenges such as the ownership model and the borrow checker. Its strict rules help prevent programming errors such as data races and memory leaks. The strict rules also help students learn how to think about writing efficient code coming from high level languages.

Contributors

Ryan