|
| 1 | +name: Public repository boundary |
| 2 | + |
| 3 | +on: |
| 4 | + pull_request_target: |
| 5 | + types: [opened, synchronize, reopened, ready_for_review, edited] |
| 6 | + push: |
| 7 | + branches: ['**'] |
| 8 | + tags: ['**'] |
| 9 | + workflow_dispatch: |
| 10 | + |
| 11 | +permissions: |
| 12 | + contents: read |
| 13 | + |
| 14 | +concurrency: |
| 15 | + group: public-boundary-${{ github.event.pull_request.number || github.ref }} |
| 16 | + cancel-in-progress: true |
| 17 | + |
| 18 | +jobs: |
| 19 | + trusted-pr-boundary: |
| 20 | + if: github.event_name == 'pull_request_target' |
| 21 | + name: Trusted public-boundary policy |
| 22 | + runs-on: ubuntu-latest |
| 23 | + timeout-minutes: 10 |
| 24 | + permissions: |
| 25 | + contents: read |
| 26 | + pull-requests: read |
| 27 | + statuses: write |
| 28 | + steps: |
| 29 | + - name: Mark candidate boundary status pending |
| 30 | + id: pending_status |
| 31 | + env: |
| 32 | + GH_TOKEN: ${{ github.token }} |
| 33 | + HEAD_SHA: ${{ github.event.pull_request.head.sha }} |
| 34 | + run: | |
| 35 | + [[ "$HEAD_SHA" =~ ^[0-9a-f]{40}$ ]] |
| 36 | + gh api --method POST "repos/$GITHUB_REPOSITORY/statuses/$HEAD_SHA" \ |
| 37 | + -f state=pending \ |
| 38 | + -f context='Public repository boundary' \ |
| 39 | + -f description='Trusted default-branch policy is scanning this commit' \ |
| 40 | + -f target_url="$GITHUB_SERVER_URL/$GITHUB_REPOSITORY/actions/runs/$GITHUB_RUN_ID" |
| 41 | +
|
| 42 | + # The policy always comes from the protected default branch. The target |
| 43 | + # base is checked out separately and is used only as the opaque-file |
| 44 | + # baseline. Candidate code is data and is never executed. |
| 45 | + - name: Check out trusted default-branch policy |
| 46 | + id: policy_checkout |
| 47 | + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 |
| 48 | + with: |
| 49 | + repository: ${{ github.repository }} |
| 50 | + ref: ${{ github.event.repository.default_branch }} |
| 51 | + path: policy |
| 52 | + persist-credentials: false |
| 53 | + |
| 54 | + - name: Check out target base baseline |
| 55 | + id: baseline_checkout |
| 56 | + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 |
| 57 | + with: |
| 58 | + repository: ${{ github.repository }} |
| 59 | + ref: ${{ github.event.pull_request.base.sha }} |
| 60 | + path: baseline |
| 61 | + persist-credentials: false |
| 62 | + |
| 63 | + - name: Check out untrusted candidate as data |
| 64 | + id: candidate_checkout |
| 65 | + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 |
| 66 | + with: |
| 67 | + repository: ${{ github.event.pull_request.head.repo.full_name }} |
| 68 | + ref: ${{ github.event.pull_request.head.sha }} |
| 69 | + fetch-depth: 0 |
| 70 | + path: candidate |
| 71 | + persist-credentials: false |
| 72 | + |
| 73 | + - name: Ensure target base exists in candidate history |
| 74 | + id: candidate_base |
| 75 | + env: |
| 76 | + BASE_SHA: ${{ github.event.pull_request.base.sha }} |
| 77 | + UPSTREAM_REPOSITORY: ${{ github.repository }} |
| 78 | + run: | |
| 79 | + [[ "$BASE_SHA" =~ ^[0-9a-f]{40}$ ]] |
| 80 | + [[ "$UPSTREAM_REPOSITORY" =~ ^[A-Za-z0-9_.-]+/[A-Za-z0-9_.-]+$ ]] |
| 81 | + if ! git -C candidate cat-file -e "$BASE_SHA^{commit}" 2>/dev/null; then |
| 82 | + GIT_TERMINAL_PROMPT=0 git \ |
| 83 | + -c credential.helper= \ |
| 84 | + -c protocol.version=2 \ |
| 85 | + -c protocol.file.allow=never \ |
| 86 | + -c protocol.ext.allow=never \ |
| 87 | + -C candidate fetch --no-tags --depth=1 \ |
| 88 | + "https://github.com/$UPSTREAM_REPOSITORY.git" \ |
| 89 | + "$BASE_SHA:refs/boundary/base" |
| 90 | + fi |
| 91 | + resolved=$(git -C candidate rev-parse --verify "$BASE_SHA^{commit}") |
| 92 | + [ "$resolved" = "$BASE_SHA" ] |
| 93 | +
|
| 94 | + - name: Test trusted boundary policy |
| 95 | + id: policy_tests |
| 96 | + run: >- |
| 97 | + python3 -m unittest discover |
| 98 | + -s policy/scripts/ci |
| 99 | + -p 'test_*.py' |
| 100 | +
|
| 101 | + - name: Require guard files to match trusted policy |
| 102 | + id: guard_integrity |
| 103 | + run: >- |
| 104 | + python3 policy/scripts/ci/check_boundary_guard_integrity.py |
| 105 | + --trusted-root policy |
| 106 | + --candidate-root candidate |
| 107 | +
|
| 108 | + - name: Scan complete candidate tree with trusted policy |
| 109 | + id: candidate_scan |
| 110 | + env: |
| 111 | + BASE_SHA: ${{ github.event.pull_request.base.sha }} |
| 112 | + HEAD_SHA: ${{ github.event.pull_request.head.sha }} |
| 113 | + HEAD_REF: ${{ github.event.pull_request.head.ref }} |
| 114 | + run: | |
| 115 | + python3 policy/scripts/ci/check_public_repository_boundary.py \ |
| 116 | + --root candidate \ |
| 117 | + --policy policy/scripts/ci/private-content-markers.txt \ |
| 118 | + --baseline-root baseline \ |
| 119 | + --history-base-ref "$BASE_SHA" \ |
| 120 | + --history-head-ref "$HEAD_SHA" \ |
| 121 | + --ref-name "refs/heads/$HEAD_REF" |
| 122 | +
|
| 123 | + - name: Publish candidate boundary status |
| 124 | + if: always() |
| 125 | + env: |
| 126 | + GH_TOKEN: ${{ github.token }} |
| 127 | + HEAD_SHA: ${{ github.event.pull_request.head.sha }} |
| 128 | + BASE_SHA: ${{ github.event.pull_request.base.sha }} |
| 129 | + PR_NUMBER: ${{ github.event.pull_request.number }} |
| 130 | + STATUS_STATE: ${{ steps.pending_status.outcome == 'success' && steps.policy_checkout.outcome == 'success' && steps.baseline_checkout.outcome == 'success' && steps.candidate_checkout.outcome == 'success' && steps.candidate_base.outcome == 'success' && steps.policy_tests.outcome == 'success' && steps.guard_integrity.outcome == 'success' && steps.candidate_scan.outcome == 'success' && 'success' || 'failure' }} |
| 131 | + run: | |
| 132 | + [[ "$HEAD_SHA" =~ ^[0-9a-f]{40}$ ]] |
| 133 | + [[ "$BASE_SHA" =~ ^[0-9a-f]{40}$ ]] |
| 134 | + [[ "$PR_NUMBER" =~ ^[0-9]+$ ]] |
| 135 | + current_head=$(gh api "repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER" --jq .head.sha) |
| 136 | + current_base=$(gh api "repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER" --jq .base.sha) |
| 137 | + if [ "$current_head" != "$HEAD_SHA" ] || [ "$current_base" != "$BASE_SHA" ]; then |
| 138 | + echo 'Skipping final status from a stale pull-request event.' |
| 139 | + exit 0 |
| 140 | + fi |
| 141 | + if [ "$STATUS_STATE" = success ]; then |
| 142 | + description='Trusted public repository boundary passed' |
| 143 | + else |
| 144 | + description='Trusted public repository boundary failed' |
| 145 | + fi |
| 146 | + gh api --method POST "repos/$GITHUB_REPOSITORY/statuses/$HEAD_SHA" \ |
| 147 | + -f state="$STATUS_STATE" \ |
| 148 | + -f context='Public repository boundary' \ |
| 149 | + -f description="$description" \ |
| 150 | + -f target_url="$GITHUB_SERVER_URL/$GITHUB_REPOSITORY/actions/runs/$GITHUB_RUN_ID" |
| 151 | +
|
| 152 | + pushed-tree-boundary: |
| 153 | + if: github.event_name == 'workflow_dispatch' || (github.event_name == 'push' && !github.event.deleted) |
| 154 | + name: Public repository boundary (advisory push scan) |
| 155 | + runs-on: ubuntu-latest |
| 156 | + timeout-minutes: 10 |
| 157 | + steps: |
| 158 | + - name: Check out trusted default-branch policy |
| 159 | + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 |
| 160 | + with: |
| 161 | + repository: ${{ github.repository }} |
| 162 | + ref: ${{ github.event.repository.default_branch }} |
| 163 | + path: policy |
| 164 | + persist-credentials: false |
| 165 | + |
| 166 | + - name: Check out pushed tree as data |
| 167 | + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 |
| 168 | + with: |
| 169 | + repository: ${{ github.repository }} |
| 170 | + ref: ${{ github.sha }} |
| 171 | + fetch-depth: 0 |
| 172 | + path: candidate |
| 173 | + persist-credentials: false |
| 174 | + |
| 175 | + - name: Test trusted boundary policy |
| 176 | + run: >- |
| 177 | + python3 -m unittest discover |
| 178 | + -s policy/scripts/ci |
| 179 | + -p 'test_*.py' |
| 180 | +
|
| 181 | + - name: Require guard files to match trusted policy |
| 182 | + run: >- |
| 183 | + python3 policy/scripts/ci/check_boundary_guard_integrity.py |
| 184 | + --trusted-root policy |
| 185 | + --candidate-root candidate |
| 186 | +
|
| 187 | + - name: Resolve the exact pushed history |
| 188 | + id: pushed_history |
| 189 | + env: |
| 190 | + AFTER_SHA: ${{ github.sha }} |
| 191 | + BEFORE_SHA: ${{ github.event.before }} |
| 192 | + PUSHED_REF: ${{ github.ref }} |
| 193 | + UPSTREAM_REPOSITORY: ${{ github.repository }} |
| 194 | + run: | |
| 195 | + [[ "$AFTER_SHA" =~ ^[0-9a-f]{40}$ ]] |
| 196 | + [[ "$PUSHED_REF" =~ ^refs/(heads|tags)/[A-Za-z0-9._/-]+$ ]] |
| 197 | + [[ "$UPSTREAM_REPOSITORY" =~ ^[A-Za-z0-9_.-]+/[A-Za-z0-9_.-]+$ ]] |
| 198 | +
|
| 199 | + fetch_exact() { |
| 200 | + local oid=$1 |
| 201 | + local destination=$2 |
| 202 | + if ! git -C candidate cat-file -e "$oid" 2>/dev/null; then |
| 203 | + GIT_TERMINAL_PROMPT=0 git \ |
| 204 | + -c credential.helper= \ |
| 205 | + -c protocol.version=2 \ |
| 206 | + -c protocol.file.allow=never \ |
| 207 | + -c protocol.ext.allow=never \ |
| 208 | + -C candidate fetch --no-tags --depth=1 \ |
| 209 | + "https://github.com/$UPSTREAM_REPOSITORY.git" \ |
| 210 | + "$oid:$destination" |
| 211 | + fi |
| 212 | + } |
| 213 | +
|
| 214 | + if [[ "$PUSHED_REF" == refs/tags/* ]]; then |
| 215 | + GIT_TERMINAL_PROMPT=0 git \ |
| 216 | + -c credential.helper= \ |
| 217 | + -c protocol.version=2 \ |
| 218 | + -c protocol.file.allow=never \ |
| 219 | + -c protocol.ext.allow=never \ |
| 220 | + -C candidate fetch --no-tags --depth=1 \ |
| 221 | + "https://github.com/$UPSTREAM_REPOSITORY.git" \ |
| 222 | + "+$PUSHED_REF:refs/boundary/pushed-tag" |
| 223 | + pushed_object=$(git -C candidate rev-parse --verify refs/boundary/pushed-tag) |
| 224 | + else |
| 225 | + fetch_exact "$AFTER_SHA" refs/boundary/pushed |
| 226 | + pushed_object=$AFTER_SHA |
| 227 | + fi |
| 228 | + object_type=$(git -C candidate cat-file -t "$pushed_object") |
| 229 | + [ "$object_type" = commit ] || { |
| 230 | + echo 'Annotated tags and non-commit refs require dedicated security review.' >&2 |
| 231 | + exit 1 |
| 232 | + } |
| 233 | + candidate_commit=$(git -C candidate rev-parse --verify "$pushed_object^{commit}") |
| 234 | + [ "$candidate_commit" = "$AFTER_SHA" ] |
| 235 | +
|
| 236 | + if [[ "$BEFORE_SHA" =~ ^0{40}$ ]] || [ -z "$BEFORE_SHA" ]; then |
| 237 | + baseline_commit=$(git -C policy rev-parse --verify HEAD) |
| 238 | + else |
| 239 | + [[ "$BEFORE_SHA" =~ ^[0-9a-f]{40}$ ]] |
| 240 | + baseline_commit=$BEFORE_SHA |
| 241 | + fi |
| 242 | + fetch_exact "$baseline_commit" refs/boundary/baseline |
| 243 | + resolved_baseline=$(git -C candidate rev-parse --verify "$baseline_commit^{commit}") |
| 244 | + [ "$resolved_baseline" = "$baseline_commit" ] |
| 245 | +
|
| 246 | + echo "history_base=$baseline_commit" >> "$GITHUB_OUTPUT" |
| 247 | + echo "history_head=$candidate_commit" >> "$GITHUB_OUTPUT" |
| 248 | +
|
| 249 | + - name: Scan pushed tree against trusted default branch |
| 250 | + env: |
| 251 | + HISTORY_BASE: ${{ steps.pushed_history.outputs.history_base }} |
| 252 | + HISTORY_HEAD: ${{ steps.pushed_history.outputs.history_head }} |
| 253 | + PUSHED_REF: ${{ github.ref }} |
| 254 | + run: | |
| 255 | + python3 policy/scripts/ci/check_public_repository_boundary.py \ |
| 256 | + --root candidate \ |
| 257 | + --policy policy/scripts/ci/private-content-markers.txt \ |
| 258 | + --baseline-ref "$HISTORY_BASE" \ |
| 259 | + --history-base-ref "$HISTORY_BASE" \ |
| 260 | + --history-head-ref "$HISTORY_HEAD" \ |
| 261 | + --ref-name "$PUSHED_REF" |
0 commit comments