ci: add the org Semgrep workflow, CODEOWNERS and Dependabot config - #1
Open
davidberenstein1957 wants to merge 12 commits into
Open
davidberenstein1957 wants to merge 12 commits into
davidberenstein1957 wants to merge 12 commits into
Conversation
Runs p/default and p/trailofbits at ERROR severity with --baseline-commit set to the pull request base, so existing findings do not fail it. The image and checkout are pinned by digest and SHA.
Python's recursive glob skips hidden folders, so .github/ was never checked. git ls-files includes them, and yq ships on ubuntu-latest.
Every ecosystem waits 7 days before proposing a new release. The Semgrep job uses the container image: form, and a docker entry for /.github/workflows lets Dependabot bump its tag and digest. Also removes the root dependabot.yaml, which Dependabot never reads; .github/dependabot.yml is the config.
This was referenced Sep 28, 2026
davidberenstein1957
force-pushed
the
ci/default-check-and-dependabot
branch
from
September 29, 2026 10:35
eb1eb4f to
5a8411c
Compare
Drop open-pull-requests-limit: 50 so each entry falls back to the default of 5. The weekly schedule and grouping stay the same, and security updates are not subject to the limit.
Adds a check to the required semgrep workflow that fails a pull request
when a run: step embeds ${{ secrets.* }} directly in the shell, the
pattern PrunaAI/prunatree#641 fixed across several workflows (leaks via
shell history/process listings/logs, opens script injection). Semgrep's
p/trailofbits and p/default packs don't catch this pattern, so this adds
a small PyYAML-based script instead.
The workflow now also fails on secrets interpolated directly into run steps, not only Semgrep findings, so semgrep.yml no longer names what it checks.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
This PR adds
.github/workflows/required-checks.yml, the workflow an org ruleset will require on every repository's default branch, and a Dependabot config for this repository.required-checks.ymlRuns
p/defaultandp/trailofbitsat ERROR severity with--baseline-commitset to the pull request base, so it only fails on findings the pull request adds. The image is pinned by digest and the job needs noSEMGREP_APP_TOKEN. It also fails a pull request when arun:step interpolates${{ secrets.* }}directly in the shell — the pattern PrunaAI/prunatree#641 fixed across several workflows (leaks via shell history/process listings/logs, opens script injection) — via a small PyYAML script at.github/scripts/check_run_secrets.py. It triggers onpull_requestonly, because ruleset workflows ignore other events.The file is named
required-checks.yml, notsemgrep.yml, because it checks both Semgrep findings and run-step secret interpolation.Every action in the workflow is pinned to a full commit SHA, with the version in a trailing comment. Dependabot's
github-actionsupdates keep the SHA and the comment current.Dependabot
.github/dependabot.ymluses directory globs where several folders share an ecosystem, so new folders are covered without a config change. It runs weekly, groups minor and patch updates into one PR per ecosystem, and keeps GitHub's default limit of 5 open pull requests (security updates don't count toward it). Dependabot PRs get no Actions secrets.//.github/workflows(tracks the Semgrep image tag and digest)Notes
dependabot.yamlis outside.github/, so GitHub ignored it. It has been deleted;.github/dependabot.ymlis the config GitHub actually reads.Hardening
.github/CODEOWNERSassignsrequired-checks.yml,check_run_secrets.pyand the CODEOWNERS file itself to@PrunaAI/safety, because every repository's merges depend on that workflow. It is enforced once this repository's ruleset requires code owner review.Before merging
Remove the required
defaultcheck from this repository's ruleset, then merge this PR before the others. After that, create the org ruleset with the rule "Require workflows to pass before merging" pointing atPrunaAI/.github,.github/workflows/required-checks.yml, refmain. The org and repo rule changes are tracked in PrunaAI/prunatree#639.Testing
dependabot.ymlvalidated withcheck-jsonschema --builtin-schema vendor.dependabot.required-checks.ymlchecked withactionlint.