Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@ version: 2
updates:

- package-ecosystem: "gomod"
cooldown:
default-days: 7
directory: "/"
schedule:
interval: "weekly"
Expand All @@ -16,6 +18,8 @@ updates:
# Base image bumps (golang:1.27-trixie builder, distroless/static-debian13
# runtime).
- package-ecosystem: "docker"
cooldown:
default-days: 7
directory: "/"
schedule:
interval: "weekly"
Expand All @@ -30,6 +34,8 @@ updates:
# Grouped into a single PR so related action bumps land together rather than
# as a stream of separate PRs. Auto-merge handles them once CI passes.
- package-ecosystem: "github-actions"
cooldown:
default-days: 7
directory: "/"
schedule:
interval: "weekly"
Expand Down
6 changes: 5 additions & 1 deletion .github/workflows/auto-merge.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,4 +31,8 @@ jobs:
# This merges with the dnb-robot app token instead, so the merge properly
# cascades into another Release Please run that actually finishes the release.
use-app-token-for-merge: true
secrets: inherit
# Only the two secrets the called workflow uses, rather than `inherit`
# handing it every repo and org secret.
secrets:
DNB_ROBOT_CLIENT_ID: ${{ secrets.DNB_ROBOT_CLIENT_ID }}
AUTOMATION_APP_PRIVATE_KEY: ${{ secrets.AUTOMATION_APP_PRIVATE_KEY }}
6 changes: 5 additions & 1 deletion .github/workflows/release-please.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,4 +13,8 @@ permissions:
jobs:
release-please:
uses: drumandbytes/reusable-actions/.github/workflows/release-please.yml@v1
secrets: inherit
# Only the two secrets the called workflow uses, rather than `inherit`
# handing it every repo and org secret.
secrets:
DNB_ROBOT_CLIENT_ID: ${{ secrets.DNB_ROBOT_CLIENT_ID }}
AUTOMATION_APP_PRIVATE_KEY: ${{ secrets.AUTOMATION_APP_PRIVATE_KEY }}
26 changes: 26 additions & 0 deletions .github/workflows/security.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
name: Security

# Kept out of the Validate workflow on purpose. Auto-merge gates on Validate's
# conclusion, so a scan there meant a vulnerability anywhere blocked every
# Dependabot merge, including ones that had nothing to do with it. Findings
# still fail this workflow; the weekly run catches advisories published
# against what's already on main.
on:
pull_request:
branches: [main]
schedule:
- cron: '0 6 * * 1'
workflow_dispatch:

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
trivy:
uses: drumandbytes/reusable-actions/.github/workflows/security-scan.yml@v1
with:
scan-type: image
12 changes: 3 additions & 9 deletions .github/workflows/validate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,8 @@ jobs:
lint:
uses: drumandbytes/reusable-actions/.github/workflows/go-ci.yml@v1
with:
# Explicit rather than read from go.mod: its `go 1.27.0` directive
# would install exactly 1.27.0, while "1.27" gets the latest 1.27.x.
go-version: "1.27"
dockerfile-path: Dockerfile

Expand Down Expand Up @@ -56,20 +58,12 @@ jobs:
-sS -f -o /dev/null http://localhost:9222/healthz
docker rm -f smoke-test

trivy:
uses: drumandbytes/reusable-actions/.github/workflows/security-scan.yml@v1
with:
scan-type: image
dockerfile: Dockerfile
severity: 'CRITICAL,HIGH'
ignore-unfixed: true

# Single stable name for the org's required-status-check ruleset to point
# at, regardless of how the real jobs above are split or renamed.
required-checks-passed:
name: Required checks passed
runs-on: ubuntu-latest
needs: [lint, smoke-test, trivy]
needs: [lint, smoke-test]
if: always()
steps:
- if: contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled')
Expand Down
6 changes: 4 additions & 2 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -62,8 +62,10 @@ docker build -t github-actions-runner-exporter .
```

CI (`.github/workflows/validate.yml`) gates on the `drumandbytes/reusable-actions`
`go-ci.yml` lint job, a Docker smoke test (`/healthz` against fake credentials
— never a real GitHub org), and Trivy image scan. `build.yml` pushes
`go-ci.yml` lint job and a Docker smoke test (`/healthz` against fake credentials
— never a real GitHub org). The Trivy image scan is its own workflow
(`security.yml`: PRs plus a weekly run on main), kept out of `validate.yml` so
a CVE can't block every Dependabot merge. `build.yml` pushes
multi-arch images to GHCR with SLSA provenance attestation on push to
`main`/tags.

Expand Down
5 changes: 3 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -79,6 +79,7 @@ docker build -t github-actions-runner-exporter .
```

CI (`.github/workflows/validate.yml`) gates on the `drumandbytes/reusable-actions`
`go-ci.yml` lint job, a Docker smoke test (`/healthz` against fake credentials —
never a real GitHub org), and Trivy image scan. `build.yml` pushes multi-arch
`go-ci.yml` lint job and a Docker smoke test (`/healthz` against fake credentials —
never a real GitHub org). The Trivy image scan runs separately (`security.yml`,
on PRs and weekly on main). `build.yml` pushes multi-arch
images to GHCR with SLSA provenance attestation on push to `main`/tags.
Loading