This public repository provides reusable security checks and an organization Renovate preset. Each calling repository keeps its own triggers, build matrix, release workflow, and package-specific checks.
Each caller should pin a reusable workflow to a full commit SHA. The examples
below use reviewed workflow revision
a92994b7ee9271d6124414bd7e3709265d7ecea5; update that reference only after
reviewing a newer revision.
| Workflow | What it checks | Inputs |
|---|---|---|
codeql.yml |
CodeQL static analysis and SARIF upload. Uses the selected language set, query suite, and build mode. | languages (required, comma-separated); queries (default security-extended); build-mode (default autobuild) |
scorecard.yml |
OpenSSF Scorecard and publishes its SARIF results. | None |
dependency-review.yml |
New or changed dependencies on pull requests. Does not write PR comments. | fail-on-severity (critical by default; use high to match stricter current callers); deny-licenses; allow-licenses (comma-separated SPDX values, both default empty) |
audit.yml |
npm or pnpm advisory audit in each supplied directory. Production-only mode omits development dependencies. | package-manager (npm or pnpm, required); working-directories (required JSON array); audit-level (default high); production-only (default false); use-pnpm-bulk-api (default false, for pnpm's Bulk Advisory API path) |
The five-repository inventory informed these interfaces: CodeQL covers the
four repositories that currently run it; Scorecard and dependency review cover
those same four; package audit supports the npm root plus apps/docs shape and
the pnpm production audits used by the workspaces. Set use-pnpm-bulk-api: true
for AgentsKit to preserve its lockfile-resolved production graph check against
npm's supported Bulk Advisory API; other pnpm callers can keep using native
pnpm audit. Existing callers can retain their severity and license policies
through inputs. The central workflows do not replace repository-specific CI,
release, publishing, or build steps.
CodeQL, matching the javascript-typescript repositories:
name: CodeQL
on:
push:
pull_request:
schedule:
- cron: '23 5 * * 1'
permissions:
contents: read
jobs:
analyze:
uses: AgentsKit-io/.github/.github/workflows/codeql.yml@a92994b7ee9271d6124414bd7e3709265d7ecea5
with:
languages: javascript-typescript
queries: security-extended
build-mode: autobuild
permissions:
actions: read
contents: read
security-events: writeScorecard:
name: Scorecard
on:
branch_protection_rule:
schedule:
- cron: '17 4 * * 1'
push:
branches: [main]
permissions:
contents: read
jobs:
scorecard:
uses: AgentsKit-io/.github/.github/workflows/scorecard.yml@a92994b7ee9271d6124414bd7e3709265d7ecea5
permissions:
contents: read
id-token: write
security-events: writeDependency review, preserving the GPL/AGPL deny list used by AgentsKit:
name: Dependency Review
on:
pull_request:
permissions:
contents: read
jobs:
review:
uses: AgentsKit-io/.github/.github/workflows/dependency-review.yml@a92994b7ee9271d6124414bd7e3709265d7ecea5
with:
fail-on-severity: high
deny-licenses: GPL-2.0,GPL-3.0,AGPL-1.0,AGPL-3.0
permissions:
contents: read
pull-requests: readnpm audit for Code Review's production dependencies in both package roots:
name: Dependency Audit
on:
pull_request:
push:
branches: [main]
permissions:
contents: read
jobs:
audit:
uses: AgentsKit-io/.github/.github/workflows/audit.yml@a92994b7ee9271d6124414bd7e3709265d7ecea5
with:
package-manager: npm
working-directories: '[".","apps/docs"]'
audit-level: high
production-only: true
permissions:
contents: readFor a pnpm workspace, use package-manager: pnpm, pass its lockfile root (or
each audited workspace directory) in working-directories, and set
audit-level: critical to preserve the current Chat and Playbook threshold.
For the AgentsKit audit, also set use-pnpm-bulk-api: true,
audit-level: high, and production-only: true.
Do not use secrets: inherit; these security workflows need no caller secrets.
External actions are pinned to full commit SHAs. The adjacent version comments record the upstream release represented by each SHA. When updating an action, select the newest version already exercised in the five-repository inventory, verify the release SHA against the upstream repository, update the comment, and run the self-test. Callers pin this repository's reusable workflows to a reviewed full commit SHA; Renovate can propose those pin updates for review. The self-test runs on pushes and pull requests, invokes each reusable workflow on this repository where applicable, and runs actionlint v1.7.12. The central repository has no package manifests, so the audit call uses an empty directory list and is intentionally skipped. Dependency review needs GitHub's dependency graph, which is disabled here; that reusable workflow is validated by actionlint and should be exercised by a caller repository with the graph enabled. Scorecard runs on PRs and on pushes to the default branch because the upstream action only accepts the default branch for push events.
Repositories opt in by adding a renovate.json file:
{
"extends": ["github>AgentsKit-io/.github"]
}The preset schedules updates weekly, groups npm development patch/minor updates and GitHub Actions, and groups production runtime patch/minor updates for human review. It enables platform automerge only for development patch/minor and GitHub Actions digest/patch/minor updates, so GitHub's required checks must pass first. Major updates stay separate and never automerge. GitHub Actions are pinned to commit digests with release comments. A three-day minimum release age applies to npm updates. npm workspaces and pnpm workspaces remain discovered from their package manifests and lockfiles; no manager or workspace paths are hard-coded. The preset widens runtime dependency ranges for library packages instead of pinning published runtime dependencies.
When migrating a repository from Dependabot, add renovate.json and remove
the version-update entries in .github/dependabot.yml in the same PR.
Keep Dependabot security alerts enabled; they are separate from Dependabot
version update configuration.