This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/security-review/ci/security-review.yml
Adam Moussa f90f759e12 Tune checkov severity, wire npm audit, add CI backstop + R720 runbook
checkov: high-signal exposure/access checks -> high, best-practice noise -> low
(was 51 undifferentiated mediums). npm audit wired for Node dep CVEs. Report
collapses the low/info tail to a count. Adds ci/security-review.yml (PR backstop)
and DEPLOY-R720.md (Phase 3 host runbook).
2026-06-15 15:57:34 -04:00

61 lines
2.6 KiB
YAML

# Sea Haven security-review CI backstop (Phase 3).
# Drop into a target repo as .github/workflows/security-review.yml, OR (preferred, per
# engineering-handbook/cicd.md) promote into Sea-Haven-Industries/.github as a reusable workflow.
#
# This is the UNBYPASSABLE deterministic backstop: local hooks can be skipped with --no-verify,
# this cannot. It runs the SAME review.sh as local. The agentic detector/verifier pass (Path B)
# is gated behind SECURITY_REVIEW_AGENTIC=1 and requires the headless orchestrator runner +
# ANTHROPIC creds (see DEPLOY-R720.md) — until that exists, CI runs the scanners-only gate.
name: security-review
on:
pull_request:
workflow_dispatch:
permissions:
contents: read
jobs:
security-review:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install scanners
run: |
python3 -m pip install --quiet pipx && python3 -m pipx ensurepath
pipx install semgrep >/dev/null
pipx install checkov >/dev/null
pipx install pip-audit >/dev/null
pip install --quiet cfn-lint
# gitleaks binary
curl -sSL https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_linux_x64.tar.gz \
| tar -xz -C /usr/local/bin gitleaks
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
- name: Fetch review.sh
run: |
# Pin to the orchestrator repo / a release artifact. Placeholder: vendor a copy or curl a tag.
git clone --depth 1 https://github.com/amoussa1229/orchestrator /tmp/orch
chmod +x /tmp/orch/security-review/review.sh
- name: Run gate (scanners; agentic if enabled)
env:
SECURITY_REVIEW_AGENTIC: ${{ vars.SECURITY_REVIEW_AGENTIC }} # set to 1 once headless runner exists
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
run: |
SCOPE="${SECURITY_REVIEW_SCOPE:-src scripts template.yaml}"
if [ "${SECURITY_REVIEW_AGENTIC:-0}" = "1" ]; then
python3 /tmp/orch/security-review/run_headless.py --scope "$SCOPE" --out /tmp/agent.json .
/tmp/orch/security-review/review.sh --scope "$SCOPE" --agent-findings /tmp/agent.json \
--suppressions .security-review/suppressions.json --json-out /tmp/review.json .
else
/tmp/orch/security-review/review.sh --scope "$SCOPE" --scanners-only \
--suppressions .security-review/suppressions.json --json-out /tmp/review.json .
fi
- name: Upload findings
if: always()
uses: actions/upload-artifact@v4
with:
name: security-review-findings
path: /tmp/review.json