diff --git a/.github/gitleaks.toml b/.github/gitleaks.toml new file mode 100644 index 0000000..feaa84d --- /dev/null +++ b/.github/gitleaks.toml @@ -0,0 +1,12 @@ +# gitleaks (keel-linux/.github, security-scan.yml): the default rules, less +# the value below: KEEL_APT_KEY in the Makefile is the OpenPGP fingerprint of +# the archive staging signing subkey, public by design (it names the key the +# keyring must hold), not a secret. +[extend] +useDefault = true + +[[allowlists]] +description = "public OpenPGP fingerprint of the Keel archive staging key" +regexes = [ + '''8CFD1A4841448B2227341CEB202CACBD0E97090A''', +] diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml new file mode 100644 index 0000000..6623d98 --- /dev/null +++ b/.github/workflows/security.yml @@ -0,0 +1,19 @@ +# Security scanning (keel-linux/.github, profile/WORKFLOWS.md "Security +# scanning"): gitleaks, bandit, semgrep and shellcheck on GitHub-hosted +# runners, no secrets. Findings that are not a risk are listed, each with its +# justification, in .github/security-baseline; gitleaks fixtures, if any, in +# .github/gitleaks.toml. +name: security +on: + pull_request: + push: + branches: [main] + workflow_dispatch: +permissions: + contents: read +jobs: + security: + uses: keel-linux/.github/.github/workflows/security-scan.yml@main + permissions: + contents: read + security-events: write