Skip to content

ci: adopt shared security scans - #42

Merged
sds merged 1 commit into
mainfrom
codex/secure-actions-migration
Sep 17, 2026
Merged

sds merged 1 commit into
mainfrom
codex/secure-actions-migration

Conversation

@sds

@sds sds commented Sep 17, 2026

Copy link
Copy Markdown
Member

Summary

  • run the shared Dependency Scan and Scan GitHub Actions workflows on pull requests
  • start every ordinary GitHub Actions job with the pinned secure-runner action
  • scope OIDC and existing workflow permissions per job
  • baseline existing validated workflow patterns so new security findings remain enforced

Validation

  • actionlint .github/workflows/*.yml
  • zizmor --persona regular --config .github/zizmor.yml .
  • YAML parse and git diff --check

@sds
sds merged commit 9e82c33 into main Sep 17, 2026
8 checks passed
@sds
sds deleted the codex/secure-actions-migration branch September 17, 2026 17:12
sds added a commit that referenced this pull request Sep 18, 2026
## Summary
- repin every existing Secure Runner first step to the latest validated
gh-actions commit
- preserve the shared Dependency Scan and Scan GitHub Actions workflows
merged in #42
- preserve existing job permissions and workflow behavior

## Validation
- parsed every workflow with yq
- verified every ordinary job starts with Secure Runner at the exact
latest pin
- verified every ordinary job retains effective id-token: write
- git diff --check
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant