Skip to content

ci: apply focused OmniRoute CI hardening for #3194 - #3282

Merged
Xore merged 1 commit into
mainfrom
issue-3194-omniroute-ci
Sep 25, 2026
Merged

Xore merged 1 commit into
mainfrom
issue-3194-omniroute-ci

Conversation

@Xore

@Xore Xore commented Sep 23, 2026

Copy link
Copy Markdown
Owner

Summary

This is the focused CI/ops slice of issue #3194. It applies only the verified, bounded findings from the recorded research; it does not claim that the 55-file OmniRoute campaign is complete.

Scope: CI/ops only. No product code, deployment configuration, production changes, secrets, runner registration, or deploy.yml changes are included.

Adopt

OmniRoute source @ pinned commit APIARY target Finding applied Issue trace
.github/dependabot.yml .github/dependabot.yml Add Cargo coverage for the tracked dashboard backend Cargo.toml/Cargo.lock, using APIARY's weekly minor/patch grouping. This is an APIARY-specific coverage repair inspired by the upstream ecosystem discipline; OmniRoute's reviewed file has no Cargo stanza. Issue comment #5706295757; file-24/result.json
.github/dependabot.yml .github/dependabot.yml Add the dashboard frontend and backend Dockerfile directories exactly once, preserving existing Docker grouping and compatibility exceptions. Issue comment #5706295757; file-24/result.json
.github/workflows/codeql.yml .github/workflows/security.yml Pin checkout and CodeQL actions to reviewed full commit SHAs and set persist-credentials: false on checkout. Issue comment #5706295757; file-45/result.json
.github/workflows/codeql.yml docs/CI-CD.md Document the default-vs-advanced CodeQL setup guardrail and exact failure text. APIARY has no docs/ops/ directory, so this uses the existing CI/CD runbook. Issue comment #5706295757; file-45/result.json
.github/workflows/api-route-typecheck.yml .github/workflows/quality.yml Pin the two frontend checkout and setup-node references and disable persisted checkout credentials in both frontend runner variants. Issue comment #5706295757; file-50/result.json

Skip

Candidate Reason
Duplicate API-route TypeScript workflow APIARY already runs project-wide tsc --noEmit in both frontend Quality variants; api-route-typecheck.yml would duplicate coverage and does not match APIARY's Vite/TanStack layout.
OmniRoute npm-only/electron groups and package freezes APIARY already has broader ecosystem policy and different dependencies; copying source-specific freezes or /electron would not fit.
Workflow/actionlint/zizmor gate Real follow-up gap, but it requires a larger pinned tooling workflow and is outside this short CI slice.
Coverage ratchet, Playwright/JUnit artifacts, container boot smoke, Dockerfile lint, SBOM/provenance, Semgrep, Scorecard, property tests, mutation pilot, Node 22 behavior tests, runner lifecycle/resource docs, branch-protection/merge-train docs Valid research follow-ups, but not bounded adoptions for this CI slice; no speculative expansion.
Broader workflow-wide action pinning This patch pins only the reviewed security and frontend references; unrelated workflows retain their established policy.
Product/application changes and deploy.yml Explicitly out of scope; no application, deployment, secrets, or production changes made.

Verification

Commands and real output from this branch:

$ git diff --check
git diff --check: PASS

$ python3 -c "import yaml,sys;[yaml.safe_load(open(f)) for f in sys.argv[1:]]" .github/dependabot.yml .github/workflows/security.yml .github/workflows/quality.yml
YAML parse: PASS (.github/dependabot.yml .github/workflows/security.yml .github/workflows/quality.yml)
Structural assertions: PASS
Action SHA format: PASS

$ bash -n <all 217 repository shell scripts>
Repository shell gate: PASS (217 shell scripts)
$ shellcheck --severity=error <all 217 repository shell scripts>
Repository shell gate: PASS (217 shell scripts)

$ actionlint .github/workflows/security.yml .github/workflows/quality.yml
actionlint: NOT RUN (binary not installed)

Also verified independently with GitHub:

$ gh api repos/actions/checkout/commits/v7.0.1 --jq .sha
3d3c42e5aac5ba805825da76410c181273ba90b1
$ gh api repos/actions/setup-node/commits/v7 --jq .sha
820762786026740c76f36085b0efc47a31fe5020
$ gh api repos/github/codeql-action/commits/v4.37.9 --jq .sha
cdf488f595d80d6e07e03d4674febd5ab45fa938

No 402 or 429 occurred during this implementation. The pre-existing untracked run.log was not modified or included. This PR is opened for review and is not merged.

@Xore Xore added documentation Improvements or additions to documentation dependencies Pull requests that update a dependency file ops Deployment, runners, observability, host access security Security hardening or a security defect ci-queue-stall CI queue stall alarm (scripts/ci-queue-watch.py) labels Sep 23, 2026
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
actions/actions/checkout 3d3c42e5aac5ba805825da76410c181273ba90b1 🟢 6.6
Details
CheckScoreReason
Maintained🟢 79 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7
Code-Review🟢 10all changesets reviewed
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 3dependency not pinned by hash detected -- score normalized to 3
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Packaging⚠️ -1packaging workflow not detected
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 9security policy file detected
SAST🟢 10SAST tool is run on all commits
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
actions/github/codeql-action/analyze cdf488f595d80d6e07e03d4674febd5ab45fa938 UnknownUnknown
actions/github/codeql-action/init cdf488f595d80d6e07e03d4674febd5ab45fa938 UnknownUnknown

Scanned Files

  • .github/workflows/security.yml

@Xore
Xore merged commit 5490694 into main Sep 25, 2026
128 of 130 checks passed
@Xore
Xore deleted the issue-3194-omniroute-ci branch September 25, 2026 06:13
Xore added a commit that referenced this pull request Sep 27, 2026
…rkflows (#3313) (#3388)

#3282 set persist-credentials: false and SHA-pinned actions for security.yml
and two frontend jobs in quality.yml. The rest of the tree was left as is:
30 of 33 checkouts left the GITHUB_TOKEN in .git/config on the runner, most
of them on the shared self-hosted honeypot-ci executor that deploy.yml also
holds the deploy SSH material on, and 80-odd third-party `uses:` were still
tag-pinned. Finishes all three proposals across all 19 workflows.

persist-credentials: false on every checkout. Audited for `git push` first:
none exists outside Dependabot tooling, so no checkout needs the token left
on disk. 35 checkouts, 0 without it.

Full-SHA pins with a `# vX.Y.Z` comment on every third-party `uses:` (52
references). SHAs resolved with `git ls-remote --tags`, not copied from a
release page. Dependabot's github-actions ecosystem already covers `/` with
no ignore rules, so it keeps bumping these. Two pins that were already SHAs
gained a version comment, and quality.yml's two setup-node pins said `# v7`
where the tag is v7.0.0.

permissions: {} at workflow level on the 13 workflows that granted a write
scope there, with the grant moved to the job that spends it. actions: write
existed only so the ci-target job could call the reusable ci-router.yml and
dispatch the ci-heartbeat canary, so it stays on ci-target and no longer
reaches the other 24 jobs in quality.yml; packages: write is now on
containers.yml's build job alone, and security-events: write on security.yml's
analyze job alone. Verified job by job that every job's effective envelope is
equal or narrower than before: no job gained a scope, and the dropped ones
each had a single consumer that keeps its grant. deploy.yml, diagnostics.yml,
vps-start-blackhole.yml and ci-router.yml grant no write scope at the workflow
level and are left alone.

Enforced rather than asserted: #3314's zizmor step listed unpinned-uses,
excessive-permissions and artipacked as advisory "until #3313 lands". They
are dropped from ADVISORY, so a regression in any of them is now a blocking
finding. The two rules left advisory are documented inline with why: the five
`uses: ./.github/workflows/ci-router.yml` calls (zizmor wants the
owner/repo/path@ref form; the local-path form is GitHub's own first-party
syntax and is what lets the shared router change without a second SHA to
bump), and main-health-watch.yml's workflow_run (it runs the default branch's
copy of the script and reads no event payload -- every value it reports comes
from a main-scoped API read, and changing the trigger would blind the #3324
alarm that exists to catch runs nobody started).

zizmor on the tree: unpinned-uses 51 -> 0, excessive-permissions 7 -> 0,
artipacked 27 -> 0, with the gate now passing. actionlint 1.7.7 clean, all 19
workflows parse, and tests/docs (444) plus scripts/tests (193 of 195; the two
compose-drift-watch_sweep privileged-fallback failures are pre-existing on
the base commit) pass.

Co-authored-by: Dev Operator <dev@localhost>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-queue-stall CI queue stall alarm (scripts/ci-queue-watch.py) dependencies Pull requests that update a dependency file documentation Improvements or additions to documentation ops Deployment, runners, observability, host access security Security hardening or a security defect

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant