Skip to content

Add reusable security workflows - #1

Merged
EmersonBraun merged 6 commits into
mainfrom
codex/reusable-security-workflows
Oct 3, 2026
Merged

EmersonBraun merged 6 commits into
mainfrom
codex/reusable-security-workflows

Conversation

@EmersonBraun

@EmersonBraun EmersonBraun commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

What: Adds reusable CodeQL, Scorecard, dependency review, and npm/pnpm audit workflows with minimal job permissions and pinned action SHAs. The pnpm audit supports the npm Bulk Advisory API path used by AgentsKit. A push/PR self-test calls the applicable workflows and runs pinned actionlint; README documents inputs, callers, and pin updates.

Why: Centralizes security checks used across AgentsKit, Code Review, Chat, and Playbook while keeping repository-specific CI and releases local.

How: Exposes explicit CodeQL, severity/license, package-manager, directory, audit-level, production-only, and pnpm bulk-API inputs. Caller examples pin reviewed workflow revision a92994b7ee9271d6124414bd7e3709265d7ecea5.

Validation: go run github.com/rhysd/actionlint/cmd/actionlint@v1.7.12 .github/workflows/*.yml, node --check .github/scripts/pnpm-bulk-audit.mjs, and git diff --check passed locally. Final PR self-test run 37084266004 on f77632c passed actionlint, Scorecard, and CodeQL. Audit was intentionally skipped because this repository has no package manifests; dependency review is not applicable because its dependency graph is disabled.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@EmersonBraun
EmersonBraun merged commit 3b21744 into main Oct 3, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants