From 3586a567bf8267f363c7bcfb687b719f79efd94d Mon Sep 17 00:00:00 2001 From: ChatGPT Governance Automation Date: Sat, 12 Sep 2026 02:05:44 +0100 Subject: [PATCH] ci: complete Wave 4 security migration --- .github/workflows/codeql.yml | 51 --------------------------------- .github/workflows/scorecard.yml | 40 ++++++++++++++++++++++++++ .github/workflows/trivy.yml | 51 +++++++++++++++++++++++++++++++++ 3 files changed, 91 insertions(+), 51 deletions(-) delete mode 100644 .github/workflows/codeql.yml create mode 100644 .github/workflows/scorecard.yml create mode 100644 .github/workflows/trivy.yml diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml deleted file mode 100644 index eafa6a7..0000000 --- a/.github/workflows/codeql.yml +++ /dev/null @@ -1,51 +0,0 @@ -name: "CodeQL Advanced" - -on: - push: - branches: ["main"] - pull_request: - branches: ["main"] - schedule: - - cron: "37 7 * * 4" - -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - # Preserve completed push-to-main analyses; only supersede stale PR runs. - cancel-in-progress: ${{ github.event_name == 'pull_request' }} - -jobs: - analyze: - name: Analyze (${{ matrix.language }}) - runs-on: ubuntu-24.04 - timeout-minutes: 20 - permissions: - security-events: write - packages: read - actions: read - contents: read - strategy: - fail-fast: false - matrix: - include: - - language: actions - build-mode: none - - language: javascript-typescript - build-mode: none - - language: python - build-mode: none - steps: - - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - - name: Initialize CodeQL - uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 - with: - languages: ${{ matrix.language }} - build-mode: ${{ matrix.build-mode }} - - - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 - with: - category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml new file mode 100644 index 0000000..b1848d6 --- /dev/null +++ b/.github/workflows/scorecard.yml @@ -0,0 +1,40 @@ +name: OpenSSF Scorecard + +on: + push: + branches: [main] + schedule: + - cron: "31 4 * * 6" + workflow_dispatch: + +permissions: read-all + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: false + +jobs: + scorecard: + name: Scorecard + runs-on: ubuntu-24.04 + timeout-minutes: 15 + permissions: + contents: read + security-events: write + steps: + - name: Checkout repository + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Run OpenSSF Scorecard + uses: ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc # v2.4.4 + with: + results_file: results.sarif + results_format: sarif + publish_results: false + + - name: Upload Scorecard SARIF + uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 + with: + sarif_file: results.sarif diff --git a/.github/workflows/trivy.yml b/.github/workflows/trivy.yml new file mode 100644 index 0000000..78ef936 --- /dev/null +++ b/.github/workflows/trivy.yml @@ -0,0 +1,51 @@ +name: Trivy security scan + +on: + push: + branches: [main] + schedule: + - cron: "13 5 * * 0" # weekly, Sunday 05:13 UTC + workflow_dispatch: + +permissions: read-all + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: false + +jobs: + trivy: + name: Trivy filesystem scan + runs-on: ubuntu-24.04 + timeout-minutes: 20 + permissions: + contents: read + security-events: write + steps: + - name: Checkout repository + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Scan dependencies and configuration + shell: bash + run: | + set -euo pipefail + mkdir -p "$RUNNER_TEMP/trivy" + docker run --rm --pull=always \ + --user "$(id -u):$(id -g)" \ + -e TRIVY_CACHE_DIR=/out/cache \ + -v "$GITHUB_WORKSPACE:/workspace:ro" \ + -v "$RUNNER_TEMP/trivy:/out" \ + "aquasec/trivy@sha256:be1190afcb28352bfddc4ddeb71470835d16462af68d310f9f4bca710961a41e" \ + fs \ + --scanners vuln,misconfig \ + --severity HIGH,CRITICAL \ + --format sarif \ + --output /out/trivy-results.sarif \ + /workspace + + - name: Upload Trivy SARIF + uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 + with: + sarif_file: ${{ runner.temp }}/trivy/trivy-results.sarif