diff --git a/.github/workflows/move-major-tag.yml b/.github/workflows/move-major-tag.yml index d25f44a..7f8bc82 100644 --- a/.github/workflows/move-major-tag.yml +++ b/.github/workflows/move-major-tag.yml @@ -1,5 +1,6 @@ name: Move Major Tag +# checkov:skip=CKV_GHA_7:Manual tag input is required to repair or remap a specific stable release. on: release: types: @@ -11,12 +12,13 @@ on: required: false type: string -permissions: - contents: write +permissions: {} # Deny token access by default; the tag-moving job grants only tag update access. jobs: move-major-tag: runs-on: ubuntu-latest + permissions: + contents: write # Required to move the major release tag. steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 diff --git a/.github/workflows/project-automation.yml b/.github/workflows/project-automation.yml index dc16684..fbb1131 100644 --- a/.github/workflows/project-automation.yml +++ b/.github/workflows/project-automation.yml @@ -6,8 +6,7 @@ on: pull_request: types: [opened, reopened] -permissions: - contents: read # Required by the reusable project-routing workflows. +permissions: {} # Deny token access by default; project-routing jobs grant read access. concurrency: group: ${{ github.workflow }}-${{ github.event_name }}-${{ github.event.issue.number || github.event.pull_request.number }} @@ -17,6 +16,8 @@ jobs: add-issue-to-projects: if: github.event_name == 'issues' uses: datasciencecampus/github-actions/.github/workflows/add-issue-to-projects.yml@caf4ab7c789a34efb07d61113830bcb67d634a38 # v1.7.0 + permissions: + contents: read # Required by the reusable issue-routing workflow. secrets: PROJECT_ROUTER_BOT_PRIVATE_KEY: ${{ secrets.PROJECT_ROUTER_BOT_PRIVATE_KEY }} with: @@ -27,6 +28,8 @@ jobs: add-pr-to-projects: if: github.event_name == 'pull_request' uses: datasciencecampus/github-actions/.github/workflows/add-pr-to-projects.yml@caf4ab7c789a34efb07d61113830bcb67d634a38 # v1.7.0 + permissions: + contents: read # Required by the reusable pull-request routing workflow. secrets: PROJECT_ROUTER_BOT_PRIVATE_KEY: ${{ secrets.PROJECT_ROUTER_BOT_PRIVATE_KEY }} with: diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index c992771..96cf9d8 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -6,13 +6,14 @@ on: - main workflow_dispatch: -permissions: - contents: write - pull-requests: write +permissions: {} # Deny token access by default; the release job grants only what it needs. jobs: release-please: runs-on: ubuntu-latest + permissions: + contents: write # Required to create release commits and move the major tag. + pull-requests: write # Required to create and update release pull requests. steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 diff --git a/.github/workflows/security-analysis.yml b/.github/workflows/security-analysis.yml new file mode 100644 index 0000000..de2dd6c --- /dev/null +++ b/.github/workflows/security-analysis.yml @@ -0,0 +1,24 @@ +name: Security Analysis + +on: + push: + branches: [main] + pull_request: + branches: [main] + +run-name: "${{ github.workflow }} - ${{ github.actor }} - ${{ github.event_name == 'pull_request' && format('PR #{0}', github.event.pull_request.number) || github.ref_name }}" + +permissions: {} # Deny token access by default; jobs grant only what they need. + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +jobs: + security-analysis: + name: security-analysis + permissions: + actions: read # Required for SARIF upload metadata lookups in private or internal repositories. + contents: read # Required to read repository contents during analysis. + security-events: write # Required to upload security analysis results. + uses: datasciencecampus/github-actions/.github/workflows/security-analysis.yml@caf4ab7c789a34efb07d61113830bcb67d634a38 # v1.7.0 \ No newline at end of file diff --git a/.github/workflows/test-reusable-workflow-contract.yml b/.github/workflows/test-reusable-workflow-contract.yml index a3a5940..03b9352 100644 --- a/.github/workflows/test-reusable-workflow-contract.yml +++ b/.github/workflows/test-reusable-workflow-contract.yml @@ -1,7 +1,6 @@ name: Test reusable workflow contract -permissions: - contents: read +permissions: {} # Deny token access by default; the reusable workflow job grants read access. on: workflow_dispatch: @@ -17,6 +16,8 @@ on: jobs: invoke-reusable-workflow: uses: ./.github/workflows/update-tf-modules.yml + permissions: + contents: read # Required for the reusable workflow contract test to read repository contents. with: manifest_path: .github/update-modules-manifest.yml create_pr: false diff --git a/.github/workflows/test-suite.yml b/.github/workflows/test-suite.yml index c628bdd..ba9ab91 100644 --- a/.github/workflows/test-suite.yml +++ b/.github/workflows/test-suite.yml @@ -4,12 +4,13 @@ on: pull_request: branches: [ "main" ] -permissions: - contents: read +permissions: {} # Deny token access by default; the test job grants checkout access. jobs: run-tests: runs-on: ubuntu-latest + permissions: + contents: read # Required to check out the repository before running tests. steps: - name: Checkout code diff --git a/.github/workflows/update-tf-modules.yml b/.github/workflows/update-tf-modules.yml index 072334a..f31d34c 100644 --- a/.github/workflows/update-tf-modules.yml +++ b/.github/workflows/update-tf-modules.yml @@ -1,5 +1,6 @@ name: Update Terraform module versions +# checkov:skip=CKV_GHA_7:Manual inputs are required to select the manifest, Terraform root, target branch, updater ref, and PR behavior. on: workflow_call: inputs: @@ -70,6 +71,9 @@ on: required: false default: v0 type: string + +permissions: {} # Deny token access by default; the update job grants only the write access it needs. + concurrency: group: update-tf-modules-${{ github.repository }}-${{ inputs.base_branch || github.ref_name }} cancel-in-progress: false @@ -78,8 +82,8 @@ jobs: update-modules: runs-on: ubuntu-latest permissions: - contents: write - pull-requests: write + contents: write # Required to commit updated Terraform module versions. + pull-requests: write # Required to create and update the automated pull request. outputs: changed: ${{ steps.detect_changes.outputs.changed }} pr_number: ${{ steps.create_pull_request.outputs.pull-request-number }} diff --git a/configs/checkov.yml b/configs/checkov.yml new file mode 100644 index 0000000..2a8e24b --- /dev/null +++ b/configs/checkov.yml @@ -0,0 +1,11 @@ +compact: true +directory: + - . +download-external-modules: false +evaluate-variables: true +framework: github_actions +output: cli +quiet: true +soft-fail: false +skip-check: +summary-position: bottom \ No newline at end of file diff --git a/configs/zizmor.yaml b/configs/zizmor.yaml new file mode 100644 index 0000000..3b7c80b --- /dev/null +++ b/configs/zizmor.yaml @@ -0,0 +1 @@ +rules: {} \ No newline at end of file