Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
224 changes: 4 additions & 220 deletions .github/workflows/security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,224 +10,8 @@ on:
permissions:
contents: read

env:
REPO_FOUNDRY_PROFILE: ${{ vars.REPO_FOUNDRY_PROFILE }}
REPO_FOUNDRY_LANGUAGES: ${{ vars.REPO_FOUNDRY_LANGUAGES }}
REPO_FOUNDRY_FEATURES: ${{ vars.REPO_FOUNDRY_FEATURES }}
REPO_FOUNDRY_PACKAGE_MANAGER: ${{ vars.REPO_FOUNDRY_PACKAGE_MANAGER }}
REPO_FOUNDRY_CACHE_PACKAGES: ${{ vars.REPO_FOUNDRY_CACHE_PACKAGES || 'auto' }}
REPO_FOUNDRY_BASE_SHA: ${{ github.event_name == 'pull_request' && github.event.pull_request.base.sha || github.event.before || '' }}

concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.head.repo.full_name || github.repository }}-${{ github.event.pull_request.head.ref || github.ref_name }}
cancel-in-progress: true

jobs:
profile:
name: Profile
runs-on: ubuntu-slim
timeout-minutes: 10
outputs:
javascript: ${{ steps.profile.outputs.javascript }}
rust: ${{ steps.profile.outputs.rust }}
python: ${{ steps.profile.outputs.python }}
python_requirements: ${{ steps.profile.outputs.python_requirements }}
steps:
- name: Checkout
uses: actions/checkout@v7
with:
fetch-depth: 2
filter: blob:none
sparse-checkout: |
.github
.mise.toml
mise.lock
.npmrc
.pnpmfile.cjs
.yarnrc*
**/package.json
**/bun.lock
**/bun.lockb
**/pnpm-lock.yaml
**/yarn.lock
**/package-lock.json
**/Cargo.toml
**/Cargo.lock
**/.cargo/**
**/pyproject.toml
**/requirements*.txt
**/setup.py
**/setup.cfg
**/Pipfile
**/Pipfile.lock
**/poetry.lock
**/uv.lock
sparse-checkout-cone-mode: false
- name: Detect
id: profile
run: bash .github/scripts/security.sh profile >> "$GITHUB_OUTPUT"

dependency-audit-javascript:
name: Dependency Audit (JavaScript)
runs-on: ubuntu-slim
timeout-minutes: 20
steps:
- name: Checkout
uses: actions/checkout@v7
with:
# JavaScript audits only need manifests, lockfiles, and audit config.
filter: blob:none
sparse-checkout: |
.github
.mise.toml
mise.lock
.npmrc
.pnpmfile.cjs
.yarnrc*
**/package.json
**/bun.lock
**/bun.lockb
**/pnpm-lock.yaml
**/yarn.lock
**/package-lock.json
sparse-checkout-cone-mode: false
- name: Detect
id: applicability
run: bash .github/scripts/security.sh should_run javascript >> "$GITHUB_OUTPUT"
- name: Setup
if: steps.applicability.outputs.applicable == 'true'
uses: ./.github/actions/setup
with:
mise-scope: javascript
cache-save: ${{ github.event_name != 'pull_request' }}
- name: Audit dependencies
if: steps.applicability.outputs.applicable == 'true'
run: bash .github/scripts/security.sh audit javascript

dependency-audit-rust:
name: Dependency Audit (Rust)
# ubuntu-latest ships with Cargo/Rust; use it for the audit-only job and
# fall back to the repository toolchain when the image lacks Rust.
runs-on: ${{ vars.REPO_FOUNDRY_RUST_AUDIT_RUNNER || 'ubuntu-latest' }}
timeout-minutes: 20
steps:
- name: Checkout
uses: actions/checkout@v7
with:
# Rust audits only need manifests, Cargo configuration, and audit config.
filter: blob:none
sparse-checkout: |
.github
.mise.toml
mise.lock
**/Cargo.toml
**/Cargo.lock
**/.cargo/**
sparse-checkout-cone-mode: false
- name: Detect
id: applicability
run: bash .github/scripts/security.sh should_run rust >> "$GITHUB_OUTPUT"
- name: Check Rust
id: system-rust
if: steps.applicability.outputs.applicable == 'true'
shell: bash
run: |
if command -v cargo >/dev/null 2>&1 && command -v rustc >/dev/null 2>&1; then
cargo --version
rustc --version
echo 'available=true' >> "$GITHUB_OUTPUT"
else
echo 'available=false' >> "$GITHUB_OUTPUT"
fi
- name: Setup
if: >-
steps.applicability.outputs.applicable == 'true' &&
steps.system-rust.outputs.available != 'true'
uses: ./.github/actions/setup
with:
mise-scope: rust
cache-save: ${{ github.event_name != 'pull_request' }}
- name: Install cargo-audit
if: steps.applicability.outputs.applicable == 'true'
uses: taiki-e/install-action@v2
with:
tool: cargo-audit
- name: Audit dependencies
if: steps.applicability.outputs.applicable == 'true'
run: bash .github/scripts/security.sh audit rust

dependency-audit-python:
name: Dependency Audit (Python) / ${{ matrix.requirement }}
needs: profile
if: >-
${{ needs.profile.result == 'success' &&
needs.profile.outputs.python == 'true' &&
needs.profile.outputs.python_requirements != '["none"]' }}
strategy:
fail-fast: false
max-parallel: 8
matrix:
requirement: ${{ fromJSON(needs.profile.outputs.python_requirements) }}
runs-on: ubuntu-slim
timeout-minutes: 20
env:
REPO_FOUNDRY_PYTHON_REQUIREMENT: ${{ matrix.requirement }}
steps:
- name: Checkout
uses: actions/checkout@v7
with:
# Python audits only need manifests, lockfiles, and audit config.
filter: blob:none
sparse-checkout: |
.github
.mise.toml
mise.lock
**/pyproject.toml
**/requirements*.txt
**/setup.py
**/setup.cfg
**/Pipfile
**/Pipfile.lock
**/poetry.lock
**/uv.lock
sparse-checkout-cone-mode: false
- name: Setup
uses: ./.github/actions/setup
with:
mise-scope: python
cache-save: ${{ github.event_name != 'pull_request' }}
- name: Audit dependencies
run: bash .github/scripts/security.sh audit python

dependency-audit-python-gate:
name: Dependency Audit (Python)
needs: [profile, dependency-audit-python]
if: always()
runs-on: ubuntu-slim
timeout-minutes: 5
steps:
- name: Gate
env:
PROFILE_RESULT: ${{ needs.profile.result }}
AUDIT_RESULT: ${{ needs.dependency-audit-python.result }}
run: |
if [ "$PROFILE_RESULT" != success ]; then
echo "Python audit profile failed: $PROFILE_RESULT" >&2
exit 1
fi
case "$AUDIT_RESULT" in
success|skipped) exit 0 ;;
*) echo "Python dependency audit failed: $AUDIT_RESULT" >&2; exit 1 ;;
esac

dependency-review:
name: Dependency Review
if: ${{ github.event_name == 'pull_request' && !github.event.repository.private }}
runs-on: ubuntu-slim
timeout-minutes: 10
steps:
- name: Review
uses: actions/dependency-review-action@v5
with:
fail-on-severity: high
license-check: true
security:
name: Security
uses: 0xPlayerOne/code-foundry/.github/workflows/reusable-security.yml@v0.10.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[WARNING]: Missing runtime-ref input causes version mismatch

The wrapper pins the reusable workflow to v0.10.0 but does not pass runtime-ref: v0.10.0 as an input. The reusable workflow defaults to runtime-ref: v0.9.0 (reusable-security.yml line 15), so the actual runtime scripts executed will be from v0.9.0, not v0.10.0. Pass runtime-ref: v0.10.0 to ensure the runtime version matches the wrapper's stated intent.


Reply with @kilocode-bot fix it to have Kilo Code address this issue.

secrets: inherit