Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 0 additions & 4 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,8 +15,6 @@ updates:
prefix: "fix"
include: "scope"

# Base image bumps (golang:1.27-trixie builder, distroless/static-debian13
# runtime).
- package-ecosystem: "docker"
cooldown:
default-days: 7
Expand All @@ -31,8 +29,6 @@ updates:
prefix: "fix"
include: "scope"

# Grouped into a single PR so related action bumps land together rather than
# as a stream of separate PRs. Auto-merge handles them once CI passes.
- package-ecosystem: "github-actions"
cooldown:
default-days: 7
Expand Down
19 changes: 5 additions & 14 deletions .github/workflows/auto-merge.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,16 +7,12 @@ on:

jobs:
auto-merge:
# The reusable workflow cannot grant itself more than the caller has, and
# the org default for GITHUB_TOKEN is read-only — so declare it here.
# The org default token is read-only.
permissions:
contents: write
pull-requests: write
# Only the conclusion is checked, not workflow_run.event: a same-repo
# branch (which is how Dependabot pushes) triggers CI as 'push', not
# 'pull_request', so gating on the event silently skipped every run. The
# reusable workflow looks up the PR and enforces the author allow-list,
# which is the actual safety gate; a run with no open PR just no-ops.
# Not gated on workflow_run.event: Dependabot branches run CI as 'push'.
# The reusable workflow's author check is the real gate.
if: >-
github.event.workflow_run.conclusion == 'success' &&
(github.event.workflow_run.actor.login == 'dependabot[bot]' ||
Expand All @@ -25,14 +21,9 @@ jobs:
with:
# release-please's own PR; patch bumps auto-merge, minor/major don't.
patch-only-authors: '["dnb-robot[bot]"]'
# GITHUB_TOKEN-authored merges don't trigger further workflow runs, which
# would leave a release-please release stuck (manifest/changelog bumped,
# no tag/release/images ever built) — see drumandbytes/reusable-actions#16.
# This merges with the dnb-robot app token instead, so the merge properly
# cascades into another Release Please run that actually finishes the release.
# A GITHUB_TOKEN merge triggers no workflows, so the release would never
# be cut (reusable-actions#16).
use-app-token-for-merge: true
# Only the two secrets the called workflow uses, rather than `inherit`
# handing it every repo and org secret.
secrets:
DNB_ROBOT_CLIENT_ID: ${{ secrets.DNB_ROBOT_CLIENT_ID }}
AUTOMATION_APP_PRIVATE_KEY: ${{ secrets.AUTOMATION_APP_PRIVATE_KEY }}
10 changes: 3 additions & 7 deletions .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,11 +8,8 @@ on:
- '**.md'
- 'LICENSE'
- '.gitignore'
# CI-config-only changes (Dependabot config, the auto-merge/validate
# workflows themselves) don't touch the image - no need for a full
# multi-arch build+push on every one of them. build.yml is explicitly
# re-included: a change to the workflow that actually builds and
# pushes the image should still be exercised for real, not skipped.
# CI-config-only changes skip the build; this file is re-included so edits
# to it still run.
- '.github/**'
- '!.github/workflows/build.yml'
workflow_dispatch:
Expand Down Expand Up @@ -61,8 +58,7 @@ jobs:
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}

# Signed SLSA build provenance for the pushed image, stored next to it
# in GHCR as an OCI referrer. Verify with:
# SLSA provenance, stored next to the image in GHCR. Verify with:
# gh attestation verify oci://ghcr.io/drumandbytes/github-actions-runner-exporter:latest --owner drumandbytes
- uses: actions/attest-build-provenance@v4.2.2
with:
Expand Down
5 changes: 1 addition & 4 deletions .github/workflows/release-please.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,6 @@
name: Release Please

# Merging the release PR tags vX.Y.Z, which build.yml already builds and
# pushes as a semver-tagged image. Immutable tags — no floating vN.
# The release tag triggers build.yml. Immutable tags, no floating vN.
on:
push:
branches: [main]
Expand All @@ -13,8 +12,6 @@ permissions:
jobs:
release-please:
uses: drumandbytes/reusable-actions/.github/workflows/release-please.yml@v1
# Only the two secrets the called workflow uses, rather than `inherit`
# handing it every repo and org secret.
secrets:
DNB_ROBOT_CLIENT_ID: ${{ secrets.DNB_ROBOT_CLIENT_ID }}
AUTOMATION_APP_PRIVATE_KEY: ${{ secrets.AUTOMATION_APP_PRIVATE_KEY }}
6 changes: 1 addition & 5 deletions .github/workflows/security.yml
Original file line number Diff line number Diff line change
@@ -1,10 +1,6 @@
name: Security

# Kept out of the Validate workflow on purpose. Auto-merge gates on Validate's
# conclusion, so a scan there meant a vulnerability anywhere blocked every
# Dependabot merge, including ones that had nothing to do with it. Findings
# still fail this workflow; the weekly run catches advisories published
# against what's already on main.
# Separate from CI so a finding can't block auto-merge of an unrelated Dependabot fix.
on:
pull_request:
branches: [main]
Expand Down
22 changes: 5 additions & 17 deletions .github/workflows/validate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,28 +5,21 @@ on:
branches: [main]
workflow_dispatch:

# No paths-ignore here on purpose: this workflow hosts required-checks-passed,
# which the org's branch ruleset requires by name on every PR. A path filter
# on the workflow trigger means GitHub never even starts the run for an
# excluded diff (e.g. a docs-only PR) -- not "skipped", just never reported --
# so the ruleset's required check sits at "Expected" forever and the PR can't
# merge. Filter what runs inside jobs (paths-filter, changed-files, etc.) if
# needed, never the trigger.
# No paths-ignore: a filtered-out run never reports required-checks-passed,
# which the ruleset requires, so the PR could never merge.

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

# Read-only token; no job here writes to the repo or reads other scopes.
permissions:
contents: read

jobs:
lint:
uses: drumandbytes/reusable-actions/.github/workflows/go-ci.yml@v1
with:
# Explicit rather than read from go.mod: its `go 1.27.0` directive
# would install exactly 1.27.0, while "1.27" gets the latest 1.27.x.
# "1.27", not go.mod: `go 1.27.0` there would pin that exact patch.
go-version: "1.27"
dockerfile-path: Dockerfile

Expand All @@ -44,9 +37,7 @@ jobs:
load: true
tags: github-actions-runner-exporter:smoke-test

# Fake credentials - never actually connects to the real GitHub API.
# This only proves the container starts cleanly, listens, and answers
# /healthz without crashing - not that it can reach a real org.
# Fake credentials: only proves the container starts and answers /healthz.
- name: Container starts and serves /healthz
run: |
docker run -d --name smoke-test \
Expand All @@ -63,13 +54,10 @@ jobs:
-sS -f -o /dev/null http://localhost:9222/healthz
docker rm -f smoke-test

# Audit of this repo's own workflows; accepted findings are in
# .github/zizmor.yml.
zizmor:
uses: drumandbytes/reusable-actions/.github/workflows/zizmor.yml@v1

# Single stable name for the org's required-status-check ruleset to point
# at, regardless of how the real jobs above are split or renamed.
# The one name the ruleset requires, however the jobs above change.
required-checks-passed:
name: Required checks passed
runs-on: ubuntu-latest
Expand Down
9 changes: 2 additions & 7 deletions .github/zizmor.yml
Original file line number Diff line number Diff line change
@@ -1,18 +1,13 @@
# zizmor configuration, read by the zizmor job in validate.yml. Anything accepted
# here is accepted on purpose -- each entry says why.

rules:
unpinned-uses:
config:
policies:
# GitHub's own and the org's actions stay on tags (Dependabot moves
# them); third-party actions are SHA-pinned.
# GitHub's and our own actions on tags; third-party SHA-pinned.
"actions/*": ref-pin
"drumandbytes/*": ref-pin
"*": hash-pin

dangerous-triggers:
ignore:
# workflow_run so Dependabot PRs get a token that can merge; never
# checks out PR code.
# Needed for Dependabot merges; never checks out PR code.
- auto-merge.yml
Loading