Remove parked security-review CI drafts
CI was swapped for the global git hooks + nightly VM sweep (solo dev), so the parked ci/*.yml and CI-BACKSTOP-NOTES.md were dead weight — a defective workflow in-tree is a foot-gun. Recover from history if the team grows.
This commit is contained in:
parent
d066690b4a
commit
18412c7482
1 changed files with 0 additions and 61 deletions
|
|
@ -1,61 +0,0 @@
|
|||
# Sea Haven security-review CI backstop (Phase 3).
|
||||
# Drop into a target repo as .github/workflows/security-review.yml, OR (preferred, per
|
||||
# engineering-handbook/cicd.md) promote into Sea-Haven-Industries/.github as a reusable workflow.
|
||||
#
|
||||
# This is the UNBYPASSABLE deterministic backstop: local hooks can be skipped with --no-verify,
|
||||
# this cannot. It runs the SAME review.sh as local. The agentic detector/verifier pass (Path B)
|
||||
# is gated behind SECURITY_REVIEW_AGENTIC=1 and requires the headless orchestrator runner +
|
||||
# ANTHROPIC creds (see DEPLOY-R720.md) — until that exists, CI runs the scanners-only gate.
|
||||
name: security-review
|
||||
on:
|
||||
pull_request:
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
security-review:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Install scanners
|
||||
run: |
|
||||
python3 -m pip install --quiet pipx && python3 -m pipx ensurepath
|
||||
pipx install semgrep >/dev/null
|
||||
pipx install checkov >/dev/null
|
||||
pipx install pip-audit >/dev/null
|
||||
pip install --quiet cfn-lint
|
||||
# gitleaks binary
|
||||
curl -sSL https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_linux_x64.tar.gz \
|
||||
| tar -xz -C /usr/local/bin gitleaks
|
||||
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
|
||||
|
||||
- name: Fetch review.sh
|
||||
run: |
|
||||
# Pin to the orchestrator repo / a release artifact. Placeholder: vendor a copy or curl a tag.
|
||||
git clone --depth 1 https://github.com/amoussa1229/orchestrator /tmp/orch
|
||||
chmod +x /tmp/orch/security-review/review.sh
|
||||
|
||||
- name: Run gate (scanners; agentic if enabled)
|
||||
env:
|
||||
SECURITY_REVIEW_AGENTIC: ${{ vars.SECURITY_REVIEW_AGENTIC }} # set to 1 once headless runner exists
|
||||
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||
run: |
|
||||
SCOPE="${SECURITY_REVIEW_SCOPE:-src scripts template.yaml}"
|
||||
if [ "${SECURITY_REVIEW_AGENTIC:-0}" = "1" ]; then
|
||||
python3 /tmp/orch/security-review/run_headless.py --scope "$SCOPE" --out /tmp/agent.json .
|
||||
/tmp/orch/security-review/review.sh --scope "$SCOPE" --agent-findings /tmp/agent.json \
|
||||
--suppressions .security-review/suppressions.json --json-out /tmp/review.json .
|
||||
else
|
||||
/tmp/orch/security-review/review.sh --scope "$SCOPE" --scanners-only \
|
||||
--suppressions .security-review/suppressions.json --json-out /tmp/review.json .
|
||||
fi
|
||||
|
||||
- name: Upload findings
|
||||
if: always()
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: security-review-findings
|
||||
path: /tmp/review.json
|
||||
Reference in a new issue