Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 17 additions & 3 deletions .github/workflows/benchmark-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,20 +26,23 @@ on:
schedule:
- cron: "0 * * * *"

permissions:
actions: write
contents: write
permissions: {}

jobs:
discover:
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
outputs:
has_runs: ${{ steps.discover.outputs.has_runs }}
matrix: ${{ steps.discover.outputs.matrix }}
env:
AWS_REGION: ${{ secrets.AWS_REGION != '' && secrets.AWS_REGION || 'us-east-1' }}
SCFUZZBENCH_BUCKET: ${{ secrets.SCFUZZBENCH_BUCKET }}
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8
- name: Ensure AWS credentials are configured
run: |
if [ -z "${{ secrets.AWS_ACCESS_KEY_ID }}" ] || [ -z "${{ secrets.AWS_SECRET_ACCESS_KEY }}" ]; then
Expand Down Expand Up @@ -174,13 +177,18 @@ jobs:
needs: discover
if: ${{ needs.discover.outputs.has_runs == 'true' }}
runs-on: ubuntu-latest
permissions:
contents: write
id-token: write
strategy:
fail-fast: false
matrix: ${{ fromJson(needs.discover.outputs.matrix) }}
env:
AWS_REGION: ${{ secrets.AWS_REGION != '' && secrets.AWS_REGION || 'us-east-1' }}
SCFUZZBENCH_BUCKET: ${{ secrets.SCFUZZBENCH_BUCKET }}
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8
- name: Checkout (tarball)
timeout-minutes: 5
env:
Expand Down Expand Up @@ -547,7 +555,13 @@ jobs:
needs: [discover, release]
if: ${{ needs.discover.outputs.has_runs == 'true' && needs.release.result == 'success' }}
runs-on: ubuntu-latest
permissions:
actions: write
contents: read
id-token: write
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8
- name: Trigger docs refresh
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
Expand Down
16 changes: 13 additions & 3 deletions .github/workflows/benchmark-request.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,7 @@ on:
issues:
types: [opened, edited, labeled]

permissions:
contents: read
issues: write
permissions: {}

concurrency:
group: benchmark-request-${{ github.event.issue.number }}
Expand All @@ -15,6 +13,10 @@ concurrency:
jobs:
prepare:
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
issues: write
outputs:
is_request: ${{ steps.prepare.outputs.is_request }}
should_run: ${{ steps.prepare.outputs.should_run }}
Expand All @@ -35,6 +37,8 @@ jobs:
properties_path: ${{ steps.prepare.outputs.properties_path }}
fuzzer_env_json: ${{ steps.prepare.outputs.fuzzer_env_json }}
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8
- name: Parse and validate benchmark request
id: prepare
uses: actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7
Expand Down Expand Up @@ -454,6 +458,9 @@ jobs:
benchmark-run:
needs: prepare
if: ${{ needs.prepare.outputs.should_run == 'true' }}
permissions:
contents: read
id-token: write
uses: ./.github/workflows/benchmark-run.yml
secrets: inherit
with:
Expand All @@ -480,7 +487,10 @@ jobs:
runs-on: ubuntu-latest
permissions:
issues: write
id-token: write
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8
- name: Comment result (and close on success)
uses: actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7
with:
Expand Down
8 changes: 6 additions & 2 deletions .github/workflows/benchmark-run.yml
Original file line number Diff line number Diff line change
Expand Up @@ -180,19 +180,23 @@ on:
description: "Benchmark UUID (derived from manifest)."
value: ${{ jobs.benchmark-run.outputs.benchmark_uuid }}

permissions:
contents: read
permissions: {}

jobs:
benchmark-run:
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
outputs:
run_id: ${{ steps.tf_outputs.outputs.run_id }}
benchmark_uuid: ${{ steps.tf_outputs.outputs.benchmark_uuid }}
env:
AWS_REGION: ${{ secrets.AWS_REGION != '' && secrets.AWS_REGION || 'us-east-1' }}
SCFUZZBENCH_BUCKET: ${{ secrets.SCFUZZBENCH_BUCKET }}
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8
- name: Checkout (tarball)
timeout-minutes: 5
env:
Expand Down
23 changes: 21 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,13 +7,17 @@ on:
- main
workflow_dispatch:

permissions:
contents: read
permissions: {}

jobs:
actionlint:
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8
- name: Checkout (tarball)
timeout-minutes: 5
env:
Expand Down Expand Up @@ -43,7 +47,12 @@ jobs:

terraform:
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8
- name: Checkout (tarball)
timeout-minutes: 5
env:
Expand Down Expand Up @@ -75,7 +84,12 @@ jobs:

python:
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8
- name: Checkout (tarball)
timeout-minutes: 5
env:
Expand All @@ -101,7 +115,12 @@ jobs:

docs:
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8
- name: Checkout (tarball)
timeout-minutes: 5
env:
Expand Down
13 changes: 13 additions & 0 deletions .github/workflows/dependency-scan.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
name: Dependency Scan

"on":
pull_request:

permissions: {}

jobs:
dependency-scan:
uses: tempoxyz/gh-actions/.github/workflows/dependency-scan.yml@25cce154e7fb10f99361a166468a6c56b9c31aa3
permissions:
contents: read
id-token: write
15 changes: 11 additions & 4 deletions .github/workflows/docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,10 +8,7 @@ on:
schedule:
- cron: "0 * * * *"

permissions:
contents: read
pages: write
id-token: write
permissions: {}

concurrency:
group: "pages"
Expand All @@ -20,11 +17,16 @@ concurrency:
jobs:
build:
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
env:
AWS_REGION: ${{ secrets.AWS_REGION != '' && secrets.AWS_REGION || 'us-east-1' }}
SCFUZZBENCH_BUCKET: ${{ secrets.SCFUZZBENCH_BUCKET }}
ZERION_API_KEY: ${{ secrets.ZERION_API_KEY }}
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8
- name: Checkout (tarball)
timeout-minutes: 5
env:
Expand Down Expand Up @@ -96,9 +98,14 @@ jobs:
deploy:
needs: build
runs-on: ubuntu-latest
permissions:
id-token: write
pages: write
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8
- id: deployment
uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4
15 changes: 15 additions & 0 deletions .github/workflows/scan-github-actions.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
name: Scan GitHub Actions

"on":
pull_request:

permissions: {}

jobs:
scan:
name: Scan GitHub Actions
uses: tempoxyz/gh-actions/.github/workflows/scan-github-actions.yml@6a4184039b7a7537d35ace0badc96764d5a1d4d0
permissions:
actions: read
contents: read
id-token: write
8 changes: 6 additions & 2 deletions .github/workflows/terraform-cd.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,16 +21,20 @@ on:
required: false
default: ""

permissions:
contents: read
permissions: {}

jobs:
terraform:
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
environment: ${{ (inputs.action == 'apply' || inputs.action == 'destroy') && 'production' || 'plan' }}
env:
AWS_REGION: ${{ secrets.AWS_REGION != '' && secrets.AWS_REGION || 'us-east-1' }}
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@05c669ce878b8719779a28fe7375ba85822403f8
- name: Checkout (tarball)
timeout-minutes: 5
env:
Expand Down
24 changes: 24 additions & 0 deletions .github/zizmor.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
rules:
template-injection:
ignore:
# Existing benchmark workflows interpolate validated inputs and trusted
# matrix or step outputs into scripts. Keep those files baselined while
# continuing to scan new workflows for template injection.
- benchmark-release.yml
- benchmark-request.yml
- benchmark-run.yml
secrets-outside-env:
ignore:
# These existing automation workflows intentionally consume repository
# secrets without a GitHub deployment environment.
- benchmark-release.yml
- benchmark-run.yml
- docs.yml
secrets-inherit:
ignore:
# The local benchmark runner needs the repository's AWS and Terraform
# secrets and is pinned to the caller's own revision.
- benchmark-request.yml
ref-version-mismatch:
# Tempo's internal actions use immutable pins without matching semver tags.
disable: true
Loading