Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions .github/workflows/deploy-pages.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,10 @@ jobs:
steps:
- name: Check out the repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Nothing here pushes with git, so the checkout's token has no reason to
# stay behind in .git/config.
persist-credentials: false

- name: Install uv
uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0
Expand Down Expand Up @@ -63,6 +67,10 @@ jobs:

- name: Check out the repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Nothing here pushes with git, so the checkout's token has no reason to
# stay behind in .git/config.
persist-credentials: false

- name: Install uv
uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0
Expand Down Expand Up @@ -123,6 +131,10 @@ jobs:
steps:
- name: Check out the repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Nothing here pushes with git, so the checkout's token has no reason to
# stay behind in .git/config.
persist-credentials: false

- name: Deploy to Pages
id: deployment
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/monitor-pages.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,9 @@ jobs:
- name: Check out the repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Nothing here pushes with git, so the checkout's token has no reason to
# stay behind in .git/config.
persist-credentials: false
# A scheduled workflow runs from the default branch. Once the default moves to
# integration, checking out the default here would verify integration's schema
# set against a site that publishes from main, failing every six hours between
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/open-promotion.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,9 @@ jobs:
- name: Check out the repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Nothing here pushes with git, so the checkout's token has no reason to
# stay behind in .git/config.
persist-credentials: false
fetch-depth: 0

- name: Open the promotion pull request if integration is ahead
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/pr-base-guard.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,9 @@ jobs:
- name: Check out the repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Nothing here pushes with git, so the checkout's token has no reason to
# stay behind in .git/config.
persist-credentials: false
# Both endpoints of the diff have to be present to compute a merge base.
fetch-depth: 0

Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/pr-intake.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,8 @@
name: PR intake

on:
pull_request_target:
# zizmor flags every pull_request_target. The paragraph above is why this one is safe.
pull_request_target: # zizmor: ignore[dangerous-triggers]
types: [opened, edited, reopened]

permissions: {}
Expand Down
6 changes: 5 additions & 1 deletion .github/workflows/reference-implementation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -42,13 +42,17 @@ jobs:
steps:
- name: Check out the repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Nothing here pushes with git, so the checkout's token has no reason to
# stay behind in .git/config.
persist-credentials: false

# Pinned to an exact version rather than a moving major. The bridge in
# packages/agt-bridge/src/opa-path.ts works around a Bun defect measured on a
# specific version, so the runtime version is part of this tree's contract
# rather than an implementation detail.
- name: Install Bun
uses: oven-sh/setup-bun@735343b667d3e6f658f44d0eca948eb6282f2b76 # v2.0.1
uses: oven-sh/setup-bun@735343b667d3e6f658f44d0eca948eb6282f2b76 # v2.0.2
with:
bun-version: "1.3.11"

Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/scope-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,10 @@ jobs:
steps:
- name: Check out the repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Nothing here pushes with git, so the checkout's token has no reason to
# stay behind in .git/config.
persist-credentials: false

- name: Open a review issue if the date has passed
env:
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/sync-integration.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,9 @@ jobs:
- name: Check out the repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Nothing here pushes with git, so the checkout's token has no reason to
# stay behind in .git/config.
persist-credentials: false
fetch-depth: 0

- name: Open or update the sync pull request
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/sync_version.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,10 @@ jobs:
steps:
- name: Check out the repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# create-pull-request sets up its own token for the push, so nothing needs
# the checkout's token left behind in .git/config.
persist-credentials: false

- name: Install uv
uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0
Expand Down
6 changes: 5 additions & 1 deletion .github/workflows/validate-owasp-metadata.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,11 @@ jobs:

steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Nothing here pushes with git, so the checkout's token has no reason to
# stay behind in .git/config.
persist-credentials: false

- name: Validate metadata file
uses: owasp/nest-schema/.github/actions/validate@a733198b4a942eb12d3ee8629cd9e0d409b1b2b9
90 changes: 90 additions & 0 deletions .github/workflows/zizmor.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,90 @@
# Audits every workflow, composite action, and dependabot.yml with zizmor.
#
# CodeQL's actions analysis covers the common injection paths. zizmor is the defense in
# depth the OWASP GitHub Actions Security Cheat Sheet recommends beside it, and it checks
# what CodeQL does not: hash pins no tag points to, version comments that disagree with
# their pin, App tokens broader than the workflow needs, and credentials a checkout
# leaves behind in .git/config.
#
# Findings go to the Security tab instead of failing this job. Code scanning tracks them
# across runs, and a ruleset can gate merges on them. A tool or upload failure still
# fails the job, so the scan cannot skip itself quietly.
name: zizmor

on:
pull_request:
paths:
- ".github/**"
- "**/action.yml"
- "**/action.yaml"
- "pyproject.toml"
- "uv.lock"
push:
branches: ["main", "integration"]
paths:
- ".github/**"
- "**/action.yml"
- "**/action.yaml"
- "pyproject.toml"
- "uv.lock"
schedule:
# Weekly even when no workflow changed, because the online audits compare pinned
# actions against advisories that are published after the pin.
- cron: "0 6 * * 1"
workflow_dispatch:

# Deny by default. The one job below grants itself only what it needs.
permissions: {}

concurrency:
group: zizmor-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

jobs:
zizmor:
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write # upload the SARIF report to code scanning
steps:
- name: Check out the repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Nothing here pushes with git, so the checkout's token has no reason to
# stay behind in .git/config.
persist-credentials: false

- name: Install uv
uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0
with:
version: "0.9.9"

# zizmor runs from its own dependency group in uv.lock, so its version is pinned
# with hashes and --locked refuses a lockfile that drifted from pyproject.toml.
- name: Audit workflows and actions
env:
# The online audits read the public API: impostor commits, version comments,
# and known-vulnerable actions. The job's read-only token is all they use.
GH_TOKEN: ${{ github.token }}
run: |
set -euo pipefail
uv run --locked --only-group zizmor \
zizmor --no-progress --no-exit-codes --format sarif . > zizmor.sarif

- name: Upload the report to code scanning
# A pull request from a fork runs with a read-only token and cannot upload.
# Its findings print as annotations in the next step instead.
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
with:
sarif_file: zizmor.sarif
category: zizmor

- name: Annotate a pull request from a fork
if: github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name != github.repository
env:
GH_TOKEN: ${{ github.token }}
run: |
set -euo pipefail
uv run --locked --only-group zizmor \
zizmor --no-progress --no-exit-codes --format github .
4 changes: 4 additions & 0 deletions pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,10 @@ dependencies = [ "mike>=1.2.0", "mkdocs-material>=9.6.14", "pymdown-extensions>=

[dependency-groups]
dev = [ "pytest>=8.0", "jsonschema>=4.25.0",]
# Workflow security analysis, run by .github/workflows/zizmor.yml. A named group rather
# than dev, so the docs build and the test gate never install it. The lockfile pins the
# version with hashes, and Dependabot moves it under the usual cooldown.
zizmor = [ "zizmor>=1.30.1",]

[tool.pytest.ini_options]
# The deploy workflow runs a bare `uv run pytest -v` as the gate the site build
Expand Down
22 changes: 22 additions & 0 deletions uv.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading