Skip to content

ci: add the org Semgrep workflow, CODEOWNERS and Dependabot config - #1

Open
davidberenstein1957 wants to merge 12 commits into
mainfrom
ci/default-check-and-dependabot
Open

davidberenstein1957 wants to merge 12 commits into
mainfrom
ci/default-check-and-dependabot

Conversation

@davidberenstein1957

@davidberenstein1957 davidberenstein1957 commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

What and why

This PR adds .github/workflows/required-checks.yml, the workflow an org ruleset will require on every repository's default branch, and a Dependabot config for this repository.

required-checks.yml

Runs p/default and p/trailofbits at ERROR severity with --baseline-commit set to the pull request base, so it only fails on findings the pull request adds. The image is pinned by digest and the job needs no SEMGREP_APP_TOKEN. It also fails a pull request when a run: step interpolates ${{ secrets.* }} directly in the shell — the pattern PrunaAI/prunatree#641 fixed across several workflows (leaks via shell history/process listings/logs, opens script injection) — via a small PyYAML script at .github/scripts/check_run_secrets.py. It triggers on pull_request only, because ruleset workflows ignore other events.

The file is named required-checks.yml, not semgrep.yml, because it checks both Semgrep findings and run-step secret interpolation.

Every action in the workflow is pinned to a full commit SHA, with the version in a trailing comment. Dependabot's github-actions updates keep the SHA and the comment current.

Dependabot

.github/dependabot.yml uses directory globs where several folders share an ecosystem, so new folders are covered without a config change. It runs weekly, groups minor and patch updates into one PR per ecosystem, and keeps GitHub's default limit of 5 open pull requests (security updates don't count toward it). Dependabot PRs get no Actions secrets.

  • github-actions: /
  • docker: /.github/workflows (tracks the Semgrep image tag and digest)

Notes

  • The root-level dependabot.yaml is outside .github/, so GitHub ignored it. It has been deleted; .github/dependabot.yml is the config GitHub actually reads.

Hardening

  • .github/CODEOWNERS assigns required-checks.yml, check_run_secrets.py and the CODEOWNERS file itself to @PrunaAI/safety, because every repository's merges depend on that workflow. It is enforced once this repository's ruleset requires code owner review.

Before merging

Remove the required default check from this repository's ruleset, then merge this PR before the others. After that, create the org ruleset with the rule "Require workflows to pass before merging" pointing at PrunaAI/.github, .github/workflows/required-checks.yml, ref main. The org and repo rule changes are tracked in PrunaAI/prunatree#639.

Testing

  • dependabot.yml validated with check-jsonschema --builtin-schema vendor.dependabot.
  • required-checks.yml checked with actionlint.

Python's recursive glob skips hidden folders, so .github/ was never
checked. git ls-files includes them, and yq ships on ubuntu-latest.
Every ecosystem waits 7 days before proposing a new release. The Semgrep
job uses the container image: form, and a docker entry for
/.github/workflows lets Dependabot bump its tag and digest.

Also removes the root dependabot.yaml, which Dependabot never reads;
.github/dependabot.yml is the config.
@davidberenstein1957 davidberenstein1957 changed the title ci: add default status check and Dependabot config ci: add the org Semgrep workflow, CODEOWNERS and Dependabot config Sep 28, 2026
@davidberenstein1957
davidberenstein1957 force-pushed the ci/default-check-and-dependabot branch from eb1eb4f to 5a8411c Compare September 29, 2026 10:35
Drop open-pull-requests-limit: 50 so each entry falls back to the
default of 5. The weekly schedule and grouping stay the same, and
security updates are not subject to the limit.

@ManarShehazi ManarShehazi left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

Adds a check to the required semgrep workflow that fails a pull request
when a run: step embeds ${{ secrets.* }} directly in the shell, the
pattern PrunaAI/prunatree#641 fixed across several workflows (leaks via
shell history/process listings/logs, opens script injection). Semgrep's
p/trailofbits and p/default packs don't catch this pattern, so this adds
a small PyYAML-based script instead.
The workflow now also fails on secrets interpolated directly into run
steps, not only Semgrep findings, so semgrep.yml no longer names what
it checks.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants