From 18412c748207f0e6158f9cd39d220045b9bdef3a Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 16 Jun 2026 14:59:42 -0400 Subject: [PATCH] Remove parked security-review CI drafts MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit CI was swapped for the global git hooks + nightly VM sweep (solo dev), so the parked ci/*.yml and CI-BACKSTOP-NOTES.md were dead weight — a defective workflow in-tree is a foot-gun. Recover from history if the team grows. --- security-review/ci/security-review.yml | 61 -------------------------- 1 file changed, 61 deletions(-) delete mode 100644 security-review/ci/security-review.yml diff --git a/security-review/ci/security-review.yml b/security-review/ci/security-review.yml deleted file mode 100644 index d52d930..0000000 --- a/security-review/ci/security-review.yml +++ /dev/null @@ -1,61 +0,0 @@ -# Sea Haven security-review CI backstop (Phase 3). -# Drop into a target repo as .github/workflows/security-review.yml, OR (preferred, per -# engineering-handbook/cicd.md) promote into Sea-Haven-Industries/.github as a reusable workflow. -# -# This is the UNBYPASSABLE deterministic backstop: local hooks can be skipped with --no-verify, -# this cannot. It runs the SAME review.sh as local. The agentic detector/verifier pass (Path B) -# is gated behind SECURITY_REVIEW_AGENTIC=1 and requires the headless orchestrator runner + -# ANTHROPIC creds (see DEPLOY-R720.md) — until that exists, CI runs the scanners-only gate. -name: security-review -on: - pull_request: - workflow_dispatch: - -permissions: - contents: read - -jobs: - security-review: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v4 - - - name: Install scanners - run: | - python3 -m pip install --quiet pipx && python3 -m pipx ensurepath - pipx install semgrep >/dev/null - pipx install checkov >/dev/null - pipx install pip-audit >/dev/null - pip install --quiet cfn-lint - # gitleaks binary - curl -sSL https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_linux_x64.tar.gz \ - | tar -xz -C /usr/local/bin gitleaks - echo "$HOME/.local/bin" >> "$GITHUB_PATH" - - - name: Fetch review.sh - run: | - # Pin to the orchestrator repo / a release artifact. Placeholder: vendor a copy or curl a tag. - git clone --depth 1 https://github.com/amoussa1229/orchestrator /tmp/orch - chmod +x /tmp/orch/security-review/review.sh - - - name: Run gate (scanners; agentic if enabled) - env: - SECURITY_REVIEW_AGENTIC: ${{ vars.SECURITY_REVIEW_AGENTIC }} # set to 1 once headless runner exists - ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }} - run: | - SCOPE="${SECURITY_REVIEW_SCOPE:-src scripts template.yaml}" - if [ "${SECURITY_REVIEW_AGENTIC:-0}" = "1" ]; then - python3 /tmp/orch/security-review/run_headless.py --scope "$SCOPE" --out /tmp/agent.json . - /tmp/orch/security-review/review.sh --scope "$SCOPE" --agent-findings /tmp/agent.json \ - --suppressions .security-review/suppressions.json --json-out /tmp/review.json . - else - /tmp/orch/security-review/review.sh --scope "$SCOPE" --scanners-only \ - --suppressions .security-review/suppressions.json --json-out /tmp/review.json . - fi - - - name: Upload findings - if: always() - uses: actions/upload-artifact@v4 - with: - name: security-review-findings - path: /tmp/review.json