diff --git a/.github/workflows/ratchet-report.yml b/.github/workflows/ratchet-report.yml index b2c35af..c0438e5 100644 --- a/.github/workflows/ratchet-report.yml +++ b/.github/workflows/ratchet-report.yml @@ -62,7 +62,10 @@ jobs: rows=""; moved=0 for f in $BASELINES; do [ -z "$f" ] && continue - before=$(git show "$BASE:$f" 2>/dev/null | count); before=${before:-0} + # `|| true`: a baseline not on the base yet (the PR that adopts Foundry, or + # the first bootstrap seed) makes `git show` exit 128, which pipefail + -e + # would turn into a failed job instead of a "before: 0" row. + before=$( (git show "$BASE:$f" 2>/dev/null || true) | count); before=${before:-0} after=$([ -f "$f" ] && count < "$f" || echo 0) delta=$((after - before)) if [ "$delta" -lt 0 ]; then icon="✅ −$(( -delta ))"; moved=1 diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 337d8ba..51cc8dd 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -5,6 +5,7 @@ # jobs: # security: # uses: CMaintz/foundry/.github/workflows/security.yml@v2 +# permissions: { contents: read, pull-requests: read } # the secret scan lists PR commits # with: { ruleset_paths: '^(mise\.toml|backend/.habit-hooks/|…)' } # # Require the `security-ok` check in branch protection. @@ -38,6 +39,14 @@ permissions: jobs: guards: + # A nested reusable workflow can use at most the permissions of the job that calls + # it. Without this, `guards` inherits the file-level `contents: read` and _guards' + # secret-scan job (which needs `pull-requests: read` to list the PR's commits) is + # rejected, and the whole run ends in `startup_failure`. The consumer's caller job + # must grant the same (see the usage example above). + permissions: + contents: read + pull-requests: read uses: ./.github/workflows/_guards.yml with: ruleset_paths: ${{ inputs.ruleset_paths }} diff --git a/docs/OVERVIEW.md b/docs/OVERVIEW.md index cf8bda9..c85791f 100644 --- a/docs/OVERVIEW.md +++ b/docs/OVERVIEW.md @@ -330,6 +330,7 @@ on: { pull_request: {}, push: { branches: [main] } } jobs: security: uses: CMaintz/foundry/.github/workflows/security.yml@v2 + permissions: { contents: read, pull-requests: read } # the secret scan lists the PR's commits with: ruleset_paths: '^(mise\.toml|backend/\.habit-hooks/|frontend/\.habit-hooks/|\.github/workflows/)' ``` diff --git a/scripts/foundry-init.sh b/scripts/foundry-init.sh index f43cbe7..86470be 100644 --- a/scripts/foundry-init.sh +++ b/scripts/foundry-init.sh @@ -138,6 +138,7 @@ concurrency: { group: security-\${{ github.ref }}, cancel-in-progress: true } jobs: security: uses: $REPO/.github/workflows/security.yml@$REF # facade: secret scan + ruleset-guard + SAST + permissions: { contents: read, pull-requests: read } # the secret scan lists the PR's commits YAML write ".github/workflows/ratchet.yml" <