Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 0 additions & 5 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,3 @@
# To get started with Dependabot version updates, you'll need to specify which
# package ecosystems to update and where the package manifests are located.
# Please see the documentation for all configuration options:
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file

version: 2
updates:
- package-ecosystem: "github-actions"
Expand Down
13 changes: 3 additions & 10 deletions .github/workflows/auto-merge.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,19 +7,12 @@ on:

jobs:
auto-merge:
# The reusable workflow cannot grant itself more than the caller has, and
# the org default for GITHUB_TOKEN is read-only — so declare it here.
# The org default token is read-only.
permissions:
contents: write
pull-requests: write
# Only the conclusion is checked, not workflow_run.event: a same-repo
# branch (which is how Dependabot pushes) triggers CI as 'push', not
# 'pull_request', so gating on the event silently skipped every run. The
# reusable workflow looks up the PR and enforces the author allow-list,
# which is the actual safety gate; a run with no open PR just no-ops.
# Every other actor's CI completion used to match this too, spinning up
# the reusable workflow (and its PR lookup) just to no-op - narrowing the
# trigger itself to the only actor that can ever be eligible below.
# Not gated on workflow_run.event: Dependabot branches run CI as 'push'.
# The reusable workflow's author check is the real gate.
if: >-
github.event.workflow_run.conclusion == 'success' &&
github.event.workflow_run.actor.login == 'dependabot[bot]'
Expand Down
12 changes: 3 additions & 9 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,11 +12,8 @@ concurrency:
cancel-in-progress: true

jobs:
# Per-job path filtering, not a workflow-level paths-ignore: the jobs
# below care about disjoint file sets (shell scripts vs .tmpl templates
# vs markdown), and a blanket ignore would wrongly skip markdownlint on
# a shell-only change or vice versa. Each filter also matches this
# workflow file itself, so editing the pipeline always re-runs everything.
# Per-job path filters: the jobs cover disjoint files. Each filter
# includes this file, so pipeline edits rerun everything.
changes:
name: detect changes
runs-on: ubuntu-latest
Expand Down Expand Up @@ -234,13 +231,10 @@ jobs:
with:
globs: "**/*.md"

# Audit of this repo's own workflows; accepted findings are in
# .github/zizmor.yml.
zizmor:
uses: drumandbytes/reusable-actions/.github/workflows/zizmor.yml@v1

# Single stable name for the org's required-status-check ruleset to point
# at, regardless of how the real jobs above are split or renamed.
# The one name the ruleset requires, however the jobs above change.
required-checks-passed:
name: Required checks passed
runs-on: ubuntu-latest
Expand Down
11 changes: 1 addition & 10 deletions .github/workflows/security.yml
Original file line number Diff line number Diff line change
@@ -1,14 +1,6 @@
name: Security

# Split out of the CI workflow deliberately. Auto-merge gates on the CI
# workflow's conclusion, so keeping the scan in CI meant a vulnerability in
# one package blocked merging a Dependabot PR that fixed a different one —
# the gate held its own fixes hostage. Findings still fail this workflow.
#
# No push:branches:[main] leg: pull_request already scanned this before
# merge, so a post-merge rerun scanned nothing new. No npm/pip manifest here
# to path-filter on (only dependency is github-actions), so every PR still
# gets scanned; the weekly run catches advisories against what's on main.
# Separate from CI so a finding can't block auto-merge of an unrelated Dependabot fix.
on:
pull_request:
schedule:
Expand All @@ -19,7 +11,6 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

# Read-only token; no job here writes to the repo or reads other scopes.
permissions:
contents: read

Expand Down
9 changes: 2 additions & 7 deletions .github/zizmor.yml
Original file line number Diff line number Diff line change
@@ -1,18 +1,13 @@
# zizmor configuration, read by the zizmor job in ci.yml. Anything accepted
# here is accepted on purpose -- each entry says why.

rules:
unpinned-uses:
config:
policies:
# GitHub's own and the org's actions stay on tags (Dependabot moves
# them); third-party actions are SHA-pinned.
# GitHub's and our own actions on tags; third-party SHA-pinned.
"actions/*": ref-pin
"drumandbytes/*": ref-pin
"*": hash-pin

dangerous-triggers:
ignore:
# workflow_run so Dependabot PRs get a token that can merge; never
# checks out PR code.
# Needed for Dependabot merges; never checks out PR code.
- auto-merge.yml
Loading