Skip to content

ci(security): add informational security checks - #2930

Merged
alangou merged 1 commit into
mainfrom
2837-p0-repository-and-pr-gates-tighten-ownership-and-workflow-permissions-add-dependency-review-codeql-zizmoractionlint-secret-scanning-push-protection-and-expiring-exceptions
Aug 27, 2026
Merged

ci(security): add informational security checks#2930
alangou merged 1 commit into
mainfrom
2837-p0-repository-and-pr-gates-tighten-ownership-and-workflow-permissions-add-dependency-review-codeql-zizmoractionlint-secret-scanning-push-protection-and-expiring-exceptions

Conversation

@alangou

@alangou alangou commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

Summary

Add observation-mode security checks for GitHub Actions, dependency changes, and the Rust/SDK codebase. Findings remain informational while scanner, configuration, and build failures stay visible.

Related Issue

Refs #2837

This PR implements the initial scanner-observation tranche and does not close the broader repository-hardening issue.

Changes

  • add pinned Actionlint and Zizmor tooling with High-severity workflow reports and retained artifacts
  • add Dependency Review in warn-only mode with a neutral Dependency Graph availability preflight
  • add non-blocking CodeQL analysis for Rust and the Go, Python, and TypeScript SDKs
  • document the GitHub-hosted security checks and their non-required status

Testing

  • mise run pre-commit passes
  • Unit tests added/updated — N/A; mise run ci passes the existing suite
  • E2E tests added/updated — N/A; no runtime or deployment behavior changed
  • mise run security:actionlint
  • mise run security:zizmor

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

@copy-pr-bot

copy-pr-bot Bot commented Aug 25, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@github-actions

Copy link
Copy Markdown

@alangou

alangou commented Aug 25, 2026

Copy link
Copy Markdown
Contributor Author

/ok to test 1a6053e

@alangou
alangou force-pushed the 2837-p0-repository-and-pr-gates-tighten-ownership-and-workflow-permissions-add-dependency-review-codeql-zizmoractionlint-secret-scanning-push-protection-and-expiring-exceptions branch from 1a6053e to 228bf5a Compare August 26, 2026 10:29
@alangou

alangou commented Aug 26, 2026

Copy link
Copy Markdown
Contributor Author

/ok to test 228bf5a

@alangou
alangou force-pushed the 2837-p0-repository-and-pr-gates-tighten-ownership-and-workflow-permissions-add-dependency-review-codeql-zizmoractionlint-secret-scanning-push-protection-and-expiring-exceptions branch from 228bf5a to 8e2b40d Compare August 26, 2026 12:46
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@copy-pr-bot

copy-pr-bot Bot commented Aug 26, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@alangou
alangou marked this pull request as ready for review August 26, 2026 14:16
Comment thread .github/dependabot.yml Outdated
Comment thread .github/workflows/security-report-upload.yml Outdated
Comment thread .github/workflows/codeql.yml Outdated
@alangou
alangou force-pushed the 2837-p0-repository-and-pr-gates-tighten-ownership-and-workflow-permissions-add-dependency-review-codeql-zizmoractionlint-secret-scanning-push-protection-and-expiring-exceptions branch 6 times, most recently from 5d024ec to e1c3a45 Compare August 27, 2026 11:45
SDAChess
SDAChess previously approved these changes Aug 27, 2026
Signed-off-by: Adrien Langou <alangou@nvidia.com>
@alangou
alangou force-pushed the 2837-p0-repository-and-pr-gates-tighten-ownership-and-workflow-permissions-add-dependency-review-codeql-zizmoractionlint-secret-scanning-push-protection-and-expiring-exceptions branch from e1c3a45 to 5cac923 Compare August 27, 2026 12:25
@alangou
alangou added this pull request to the merge queue Aug 27, 2026
Merged via the queue into main with commit 5f90c85 Aug 27, 2026
49 checks passed
@alangou
alangou deleted the 2837-p0-repository-and-pr-gates-tighten-ownership-and-workflow-permissions-add-dependency-review-codeql-zizmoractionlint-secret-scanning-push-protection-and-expiring-exceptions branch August 27, 2026 13:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

5 participants