Remove parked security-review CI drafts

CI was swapped for the global git hooks + nightly VM sweep (solo dev), so
the parked ci/*.yml and CI-BACKSTOP-NOTES.md were dead weight — a defective
workflow in-tree is a foot-gun. Recover from history if the team grows.
This commit is contained in:
Adam Moussa 2026-06-16 14:59:42 -04:00
parent d066690b4a
commit 18412c7482

View file

@ -1,61 +0,0 @@
# Sea Haven security-review CI backstop (Phase 3).
# Drop into a target repo as .github/workflows/security-review.yml, OR (preferred, per
# engineering-handbook/cicd.md) promote into Sea-Haven-Industries/.github as a reusable workflow.
#
# This is the UNBYPASSABLE deterministic backstop: local hooks can be skipped with --no-verify,
# this cannot. It runs the SAME review.sh as local. The agentic detector/verifier pass (Path B)
# is gated behind SECURITY_REVIEW_AGENTIC=1 and requires the headless orchestrator runner +
# ANTHROPIC creds (see DEPLOY-R720.md) — until that exists, CI runs the scanners-only gate.
name: security-review
on:
pull_request:
workflow_dispatch:
permissions:
contents: read
jobs:
security-review:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install scanners
run: |
python3 -m pip install --quiet pipx && python3 -m pipx ensurepath
pipx install semgrep >/dev/null
pipx install checkov >/dev/null
pipx install pip-audit >/dev/null
pip install --quiet cfn-lint
# gitleaks binary
curl -sSL https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_linux_x64.tar.gz \
| tar -xz -C /usr/local/bin gitleaks
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
- name: Fetch review.sh
run: |
# Pin to the orchestrator repo / a release artifact. Placeholder: vendor a copy or curl a tag.
git clone --depth 1 https://github.com/amoussa1229/orchestrator /tmp/orch
chmod +x /tmp/orch/security-review/review.sh
- name: Run gate (scanners; agentic if enabled)
env:
SECURITY_REVIEW_AGENTIC: ${{ vars.SECURITY_REVIEW_AGENTIC }} # set to 1 once headless runner exists
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
run: |
SCOPE="${SECURITY_REVIEW_SCOPE:-src scripts template.yaml}"
if [ "${SECURITY_REVIEW_AGENTIC:-0}" = "1" ]; then
python3 /tmp/orch/security-review/run_headless.py --scope "$SCOPE" --out /tmp/agent.json .
/tmp/orch/security-review/review.sh --scope "$SCOPE" --agent-findings /tmp/agent.json \
--suppressions .security-review/suppressions.json --json-out /tmp/review.json .
else
/tmp/orch/security-review/review.sh --scope "$SCOPE" --scanners-only \
--suppressions .security-review/suppressions.json --json-out /tmp/review.json .
fi
- name: Upload findings
if: always()
uses: actions/upload-artifact@v4
with:
name: security-review-findings
path: /tmp/review.json