Skip to content

ci: add adversarial security audit workflow - #52

Merged
Conrad Rockenhaus (skyphusion) merged 1 commit into
mainfrom
ci/adversarial-audit
Jul 22, 2026
Merged

ci: add adversarial security audit workflow#52
Conrad Rockenhaus (skyphusion) merged 1 commit into
mainfrom
ci/adversarial-audit

Conversation

@skyphusion

Copy link
Copy Markdown
Member

Summary

  • Adds advisory LLM red-team audit on every PR (Kimi K2.7 Code, merge-base diff).
  • workflow_dispatch supports K3 full-repo deep scan (repo mode).
  • CodeQL remains the merge gate; findings post as a PR comment (upsert).

Credentials

Org ADVERSARIAL_AUDIT_CF_API_TOKEN, CF_AIG_TOKEN, FLEET_CHEZMOI_READ_TOKEN, vars CLOUDFLARE_ACCOUNT_ID, AI_GATEWAY_ID.
Org FLEET_CHEZMOI_READ_TOKEN: read-only deploy key on fleet-chezmoi (not RUNNER_GROUP_ADMIN_TOKEN).

Template

fleet-chezmoi system/ci/adversarial-audit-public.yml pinned @ 43be53981a895cd4399babab30cde27823744170

Test plan

  • Merge PR; open a test PR and confirm adversarial audit job runs and posts comment.

Kimi K2.7 Code on every PR diff (advisory). K3 full-repo scan via workflow_dispatch.
Template: fleet-chezmoi system/ci/adversarial-audit-public.yml @ 43be539
@github-actions

Copy link
Copy Markdown

Adversarial security audit

Generated 2026-07-22T16:47:27.678Z · 054cde0...f83a14b

Workflow PR conditional and secret verification only address fork trust; pin verification lacks transitive-history checks but no direct authz/injection/SSRF/data-leak exploit in this diff.

Severity Location Finding
- - No findings

@skyphusion
Conrad Rockenhaus (skyphusion) merged commit 5786e48 into main Jul 22, 2026
10 checks passed
@skyphusion
Conrad Rockenhaus (skyphusion) deleted the ci/adversarial-audit branch July 22, 2026 16:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant