Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 4 additions & 2 deletions .github/workflows/move-major-tag.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
name: Move Major Tag

# checkov:skip=CKV_GHA_7:Manual tag input is required to repair or remap a specific stable release.
on:
release:
types:
Expand All @@ -11,12 +12,13 @@ on:
required: false
type: string

permissions:
contents: write
permissions: {} # Deny token access by default; the tag-moving job grants only tag update access.

jobs:
move-major-tag:
runs-on: ubuntu-latest
permissions:
contents: write # Required to move the major release tag.
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down
7 changes: 5 additions & 2 deletions .github/workflows/project-automation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,7 @@ on:
pull_request:
types: [opened, reopened]

permissions:
contents: read # Required by the reusable project-routing workflows.
permissions: {} # Deny token access by default; project-routing jobs grant read access.

concurrency:
group: ${{ github.workflow }}-${{ github.event_name }}-${{ github.event.issue.number || github.event.pull_request.number }}
Expand All @@ -17,6 +16,8 @@ jobs:
add-issue-to-projects:
if: github.event_name == 'issues'
uses: datasciencecampus/github-actions/.github/workflows/add-issue-to-projects.yml@caf4ab7c789a34efb07d61113830bcb67d634a38 # v1.7.0
permissions:
contents: read # Required by the reusable issue-routing workflow.
secrets:
PROJECT_ROUTER_BOT_PRIVATE_KEY: ${{ secrets.PROJECT_ROUTER_BOT_PRIVATE_KEY }}
with:
Expand All @@ -27,6 +28,8 @@ jobs:
add-pr-to-projects:
if: github.event_name == 'pull_request'
uses: datasciencecampus/github-actions/.github/workflows/add-pr-to-projects.yml@caf4ab7c789a34efb07d61113830bcb67d634a38 # v1.7.0
permissions:
contents: read # Required by the reusable pull-request routing workflow.
secrets:
PROJECT_ROUTER_BOT_PRIVATE_KEY: ${{ secrets.PROJECT_ROUTER_BOT_PRIVATE_KEY }}
with:
Expand Down
7 changes: 4 additions & 3 deletions .github/workflows/release-please.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,13 +6,14 @@ on:
- main
workflow_dispatch:

permissions:
contents: write
pull-requests: write
permissions: {} # Deny token access by default; the release job grants only what it needs.

jobs:
release-please:
runs-on: ubuntu-latest
permissions:
contents: write # Required to create release commits and move the major tag.
pull-requests: write # Required to create and update release pull requests.
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down
24 changes: 24 additions & 0 deletions .github/workflows/security-analysis.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
name: Security Analysis

on:
push:
branches: [main]
pull_request:
branches: [main]

run-name: "${{ github.workflow }} - ${{ github.actor }} - ${{ github.event_name == 'pull_request' && format('PR #{0}', github.event.pull_request.number) || github.ref_name }}"

permissions: {} # Deny token access by default; jobs grant only what they need.

concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

jobs:
security-analysis:
name: security-analysis
permissions:
actions: read # Required for SARIF upload metadata lookups in private or internal repositories.
contents: read # Required to read repository contents during analysis.
security-events: write # Required to upload security analysis results.
uses: datasciencecampus/github-actions/.github/workflows/security-analysis.yml@caf4ab7c789a34efb07d61113830bcb67d634a38 # v1.7.0
5 changes: 3 additions & 2 deletions .github/workflows/test-reusable-workflow-contract.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,6 @@
name: Test reusable workflow contract

permissions:
contents: read
permissions: {} # Deny token access by default; the reusable workflow job grants read access.

on:
workflow_dispatch:
Expand All @@ -17,6 +16,8 @@ on:
jobs:
invoke-reusable-workflow:
uses: ./.github/workflows/update-tf-modules.yml
permissions:
contents: read # Required for the reusable workflow contract test to read repository contents.
with:
manifest_path: .github/update-modules-manifest.yml
create_pr: false
Expand Down
5 changes: 3 additions & 2 deletions .github/workflows/test-suite.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,13 @@ on:
pull_request:
branches: [ "main" ]

permissions:
contents: read
permissions: {} # Deny token access by default; the test job grants checkout access.

jobs:
run-tests:
runs-on: ubuntu-latest
permissions:
contents: read # Required to check out the repository before running tests.

steps:
- name: Checkout code
Expand Down
8 changes: 6 additions & 2 deletions .github/workflows/update-tf-modules.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
name: Update Terraform module versions

# checkov:skip=CKV_GHA_7:Manual inputs are required to select the manifest, Terraform root, target branch, updater ref, and PR behavior.
on:
workflow_call:
inputs:
Expand Down Expand Up @@ -70,6 +71,9 @@ on:
required: false
default: v0
type: string

permissions: {} # Deny token access by default; the update job grants only the write access it needs.

concurrency:
group: update-tf-modules-${{ github.repository }}-${{ inputs.base_branch || github.ref_name }}
cancel-in-progress: false
Expand All @@ -78,8 +82,8 @@ jobs:
update-modules:
runs-on: ubuntu-latest
permissions:
contents: write
pull-requests: write
contents: write # Required to commit updated Terraform module versions.
pull-requests: write # Required to create and update the automated pull request.
outputs:
changed: ${{ steps.detect_changes.outputs.changed }}
pr_number: ${{ steps.create_pull_request.outputs.pull-request-number }}
Expand Down
11 changes: 11 additions & 0 deletions configs/checkov.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
compact: true
directory:
- .
download-external-modules: false
evaluate-variables: true
framework: github_actions
output: cli
quiet: true
soft-fail: false
skip-check:
summary-position: bottom
1 change: 1 addition & 0 deletions configs/zizmor.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
rules: {}
Loading