Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion .github/workflows/ratchet-report.yml
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,10 @@ jobs:
rows=""; moved=0
for f in $BASELINES; do
[ -z "$f" ] && continue
before=$(git show "$BASE:$f" 2>/dev/null | count); before=${before:-0}
# `|| true`: a baseline not on the base yet (the PR that adopts Foundry, or
# the first bootstrap seed) makes `git show` exit 128, which pipefail + -e
# would turn into a failed job instead of a "before: 0" row.
before=$( (git show "$BASE:$f" 2>/dev/null || true) | count); before=${before:-0}
after=$([ -f "$f" ] && count < "$f" || echo 0)
delta=$((after - before))
if [ "$delta" -lt 0 ]; then icon="✅ −$(( -delta ))"; moved=1
Expand Down
9 changes: 9 additions & 0 deletions .github/workflows/security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@
# jobs:
# security:
# uses: CMaintz/foundry/.github/workflows/security.yml@v2
# permissions: { contents: read, pull-requests: read } # the secret scan lists PR commits
# with: { ruleset_paths: '^(mise\.toml|backend/.habit-hooks/|…)' }
#
# Require the `security-ok` check in branch protection.
Expand Down Expand Up @@ -38,6 +39,14 @@ permissions:

jobs:
guards:
# A nested reusable workflow can use at most the permissions of the job that calls
# it. Without this, `guards` inherits the file-level `contents: read` and _guards'
# secret-scan job (which needs `pull-requests: read` to list the PR's commits) is
# rejected, and the whole run ends in `startup_failure`. The consumer's caller job
# must grant the same (see the usage example above).
permissions:
contents: read
pull-requests: read
uses: ./.github/workflows/_guards.yml
with:
ruleset_paths: ${{ inputs.ruleset_paths }}
Expand Down
1 change: 1 addition & 0 deletions docs/OVERVIEW.md
Original file line number Diff line number Diff line change
Expand Up @@ -330,6 +330,7 @@ on: { pull_request: {}, push: { branches: [main] } }
jobs:
security:
uses: CMaintz/foundry/.github/workflows/security.yml@v2
permissions: { contents: read, pull-requests: read } # the secret scan lists the PR's commits
with:
ruleset_paths: '^(mise\.toml|backend/\.habit-hooks/|frontend/\.habit-hooks/|\.github/workflows/)'
```
Expand Down
1 change: 1 addition & 0 deletions scripts/foundry-init.sh
Original file line number Diff line number Diff line change
Expand Up @@ -138,6 +138,7 @@ concurrency: { group: security-\${{ github.ref }}, cancel-in-progress: true }
jobs:
security:
uses: $REPO/.github/workflows/security.yml@$REF # facade: secret scan + ruleset-guard + SAST
permissions: { contents: read, pull-requests: read } # the secret scan lists the PR's commits
YAML

write ".github/workflows/ratchet.yml" <<YAML
Expand Down
Loading