# Sea Haven security-review CI backstop (Phase 3). # Drop into a target repo as .github/workflows/security-review.yml, OR (preferred, per # engineering-handbook/cicd.md) promote into Sea-Haven-Industries/.github as a reusable workflow. # # This is the UNBYPASSABLE deterministic backstop: local hooks can be skipped with --no-verify, # this cannot. It runs the SAME review.sh as local. The agentic detector/verifier pass (Path B) # is gated behind SECURITY_REVIEW_AGENTIC=1 and requires the headless orchestrator runner + # ANTHROPIC creds (see DEPLOY-R720.md) — until that exists, CI runs the scanners-only gate. name: security-review on: pull_request: workflow_dispatch: permissions: contents: read jobs: security-review: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Install scanners run: | python3 -m pip install --quiet pipx && python3 -m pipx ensurepath pipx install semgrep >/dev/null pipx install checkov >/dev/null pipx install pip-audit >/dev/null pip install --quiet cfn-lint # gitleaks binary curl -sSL https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_linux_x64.tar.gz \ | tar -xz -C /usr/local/bin gitleaks echo "$HOME/.local/bin" >> "$GITHUB_PATH" - name: Fetch review.sh run: | # Pin to the orchestrator repo / a release artifact. Placeholder: vendor a copy or curl a tag. git clone --depth 1 https://github.com/amoussa1229/orchestrator /tmp/orch chmod +x /tmp/orch/security-review/review.sh - name: Run gate (scanners; agentic if enabled) env: SECURITY_REVIEW_AGENTIC: ${{ vars.SECURITY_REVIEW_AGENTIC }} # set to 1 once headless runner exists ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }} run: | SCOPE="${SECURITY_REVIEW_SCOPE:-src scripts template.yaml}" if [ "${SECURITY_REVIEW_AGENTIC:-0}" = "1" ]; then python3 /tmp/orch/security-review/run_headless.py --scope "$SCOPE" --out /tmp/agent.json . /tmp/orch/security-review/review.sh --scope "$SCOPE" --agent-findings /tmp/agent.json \ --suppressions .security-review/suppressions.json --json-out /tmp/review.json . else /tmp/orch/security-review/review.sh --scope "$SCOPE" --scanners-only \ --suppressions .security-review/suppressions.json --json-out /tmp/review.json . fi - name: Upload findings if: always() uses: actions/upload-artifact@v4 with: name: security-review-findings path: /tmp/review.json