Skip to content

Add security analysis workflow and configuration files - #81

Merged
ColinDaglish merged 6 commits into
mainfrom
add-security-analysis-workflow
Sep 24, 2026
Merged

ColinDaglish merged 6 commits into
mainfrom
add-security-analysis-workflow

Conversation

@ColinDaglish

Copy link
Copy Markdown
Contributor

Introduce a security analysis workflow that triggers on pushes and pull requests to the main branch. This setup includes necessary permissions and configurations for effective security checks.

@ColinDaglish
ColinDaglish requested a review from a team as a code owner September 24, 2026 09:16
@github-advanced-security

Copy link
Copy Markdown
Contributor

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Comment thread .github/workflows/move-major-tag.yml Fixed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Existing manual workflow parameters are removed, breaking non-default and dry-run operations.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Adds automated security scanning and tightens GitHub Actions token permissions.

Changes:

  • Adds Checkov and zizmor configurations with a reusable security-analysis workflow.
  • Moves permissions from workflow scope to individual jobs.
  • Refactors workflow inputs into environment variables.
File Description
configs/​zizmor.yaml Adds zizmor configuration.
configs/​checkov.yml Adds Checkov configuration.
.github/​workflows/​security-analysis.yml Adds security scanning for main.
.github/​workflows/​update-tf-modules.yml Hardens permissions and refactors inputs.
.github/​workflows/​test-suite.yml Scopes test permissions.
.github/​workflows/​test-reusable-workflow-contract.yml Scopes reusable-workflow permissions.
.github/​workflows/​release-please.yml Scopes release permissions.
.github/​workflows/​project-automation.yml Scopes project-routing permissions.
.github/​workflows/​move-major-tag.yml Scopes tag permissions and changes dispatch behavior.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/move-major-tag.yml Outdated
Comment thread .github/workflows/update-tf-modules.yml Outdated
@ColinDaglish
ColinDaglish merged commit 0015cb5 into main Sep 24, 2026
9 checks passed
@ColinDaglish
ColinDaglish deleted the add-security-analysis-workflow branch September 24, 2026 09:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants