From 70d32ede066bed295ca54858e1e267c3a89ed894 Mon Sep 17 00:00:00 2001 From: NiftyAndy Date: Tue, 28 Jul 2026 03:33:48 -0400 Subject: [PATCH] refactor(security): use reusable workflow wrapper --- .github/workflows/security.yml | 224 +-------------------------------- 1 file changed, 4 insertions(+), 220 deletions(-) diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 7d5ae8fa..5f262266 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -10,224 +10,8 @@ on: permissions: contents: read -env: - REPO_FOUNDRY_PROFILE: ${{ vars.REPO_FOUNDRY_PROFILE }} - REPO_FOUNDRY_LANGUAGES: ${{ vars.REPO_FOUNDRY_LANGUAGES }} - REPO_FOUNDRY_FEATURES: ${{ vars.REPO_FOUNDRY_FEATURES }} - REPO_FOUNDRY_PACKAGE_MANAGER: ${{ vars.REPO_FOUNDRY_PACKAGE_MANAGER }} - REPO_FOUNDRY_CACHE_PACKAGES: ${{ vars.REPO_FOUNDRY_CACHE_PACKAGES || 'auto' }} - REPO_FOUNDRY_BASE_SHA: ${{ github.event_name == 'pull_request' && github.event.pull_request.base.sha || github.event.before || '' }} - -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.head.repo.full_name || github.repository }}-${{ github.event.pull_request.head.ref || github.ref_name }} - cancel-in-progress: true - jobs: - profile: - name: Profile - runs-on: ubuntu-slim - timeout-minutes: 10 - outputs: - javascript: ${{ steps.profile.outputs.javascript }} - rust: ${{ steps.profile.outputs.rust }} - python: ${{ steps.profile.outputs.python }} - python_requirements: ${{ steps.profile.outputs.python_requirements }} - steps: - - name: Checkout - uses: actions/checkout@v7 - with: - fetch-depth: 2 - filter: blob:none - sparse-checkout: | - .github - .mise.toml - mise.lock - .npmrc - .pnpmfile.cjs - .yarnrc* - **/package.json - **/bun.lock - **/bun.lockb - **/pnpm-lock.yaml - **/yarn.lock - **/package-lock.json - **/Cargo.toml - **/Cargo.lock - **/.cargo/** - **/pyproject.toml - **/requirements*.txt - **/setup.py - **/setup.cfg - **/Pipfile - **/Pipfile.lock - **/poetry.lock - **/uv.lock - sparse-checkout-cone-mode: false - - name: Detect - id: profile - run: bash .github/scripts/security.sh profile >> "$GITHUB_OUTPUT" - - dependency-audit-javascript: - name: Dependency Audit (JavaScript) - runs-on: ubuntu-slim - timeout-minutes: 20 - steps: - - name: Checkout - uses: actions/checkout@v7 - with: - # JavaScript audits only need manifests, lockfiles, and audit config. - filter: blob:none - sparse-checkout: | - .github - .mise.toml - mise.lock - .npmrc - .pnpmfile.cjs - .yarnrc* - **/package.json - **/bun.lock - **/bun.lockb - **/pnpm-lock.yaml - **/yarn.lock - **/package-lock.json - sparse-checkout-cone-mode: false - - name: Detect - id: applicability - run: bash .github/scripts/security.sh should_run javascript >> "$GITHUB_OUTPUT" - - name: Setup - if: steps.applicability.outputs.applicable == 'true' - uses: ./.github/actions/setup - with: - mise-scope: javascript - cache-save: ${{ github.event_name != 'pull_request' }} - - name: Audit dependencies - if: steps.applicability.outputs.applicable == 'true' - run: bash .github/scripts/security.sh audit javascript - - dependency-audit-rust: - name: Dependency Audit (Rust) - # ubuntu-latest ships with Cargo/Rust; use it for the audit-only job and - # fall back to the repository toolchain when the image lacks Rust. - runs-on: ${{ vars.REPO_FOUNDRY_RUST_AUDIT_RUNNER || 'ubuntu-latest' }} - timeout-minutes: 20 - steps: - - name: Checkout - uses: actions/checkout@v7 - with: - # Rust audits only need manifests, Cargo configuration, and audit config. - filter: blob:none - sparse-checkout: | - .github - .mise.toml - mise.lock - **/Cargo.toml - **/Cargo.lock - **/.cargo/** - sparse-checkout-cone-mode: false - - name: Detect - id: applicability - run: bash .github/scripts/security.sh should_run rust >> "$GITHUB_OUTPUT" - - name: Check Rust - id: system-rust - if: steps.applicability.outputs.applicable == 'true' - shell: bash - run: | - if command -v cargo >/dev/null 2>&1 && command -v rustc >/dev/null 2>&1; then - cargo --version - rustc --version - echo 'available=true' >> "$GITHUB_OUTPUT" - else - echo 'available=false' >> "$GITHUB_OUTPUT" - fi - - name: Setup - if: >- - steps.applicability.outputs.applicable == 'true' && - steps.system-rust.outputs.available != 'true' - uses: ./.github/actions/setup - with: - mise-scope: rust - cache-save: ${{ github.event_name != 'pull_request' }} - - name: Install cargo-audit - if: steps.applicability.outputs.applicable == 'true' - uses: taiki-e/install-action@v2 - with: - tool: cargo-audit - - name: Audit dependencies - if: steps.applicability.outputs.applicable == 'true' - run: bash .github/scripts/security.sh audit rust - - dependency-audit-python: - name: Dependency Audit (Python) / ${{ matrix.requirement }} - needs: profile - if: >- - ${{ needs.profile.result == 'success' && - needs.profile.outputs.python == 'true' && - needs.profile.outputs.python_requirements != '["none"]' }} - strategy: - fail-fast: false - max-parallel: 8 - matrix: - requirement: ${{ fromJSON(needs.profile.outputs.python_requirements) }} - runs-on: ubuntu-slim - timeout-minutes: 20 - env: - REPO_FOUNDRY_PYTHON_REQUIREMENT: ${{ matrix.requirement }} - steps: - - name: Checkout - uses: actions/checkout@v7 - with: - # Python audits only need manifests, lockfiles, and audit config. - filter: blob:none - sparse-checkout: | - .github - .mise.toml - mise.lock - **/pyproject.toml - **/requirements*.txt - **/setup.py - **/setup.cfg - **/Pipfile - **/Pipfile.lock - **/poetry.lock - **/uv.lock - sparse-checkout-cone-mode: false - - name: Setup - uses: ./.github/actions/setup - with: - mise-scope: python - cache-save: ${{ github.event_name != 'pull_request' }} - - name: Audit dependencies - run: bash .github/scripts/security.sh audit python - - dependency-audit-python-gate: - name: Dependency Audit (Python) - needs: [profile, dependency-audit-python] - if: always() - runs-on: ubuntu-slim - timeout-minutes: 5 - steps: - - name: Gate - env: - PROFILE_RESULT: ${{ needs.profile.result }} - AUDIT_RESULT: ${{ needs.dependency-audit-python.result }} - run: | - if [ "$PROFILE_RESULT" != success ]; then - echo "Python audit profile failed: $PROFILE_RESULT" >&2 - exit 1 - fi - case "$AUDIT_RESULT" in - success|skipped) exit 0 ;; - *) echo "Python dependency audit failed: $AUDIT_RESULT" >&2; exit 1 ;; - esac - - dependency-review: - name: Dependency Review - if: ${{ github.event_name == 'pull_request' && !github.event.repository.private }} - runs-on: ubuntu-slim - timeout-minutes: 10 - steps: - - name: Review - uses: actions/dependency-review-action@v5 - with: - fail-on-severity: high - license-check: true + security: + name: Security + uses: 0xPlayerOne/code-foundry/.github/workflows/reusable-security.yml@v0.10.0 + secrets: inherit