security-review/.github/workflows/ci.yaml
Adam Moussa 4c88c01f7b
chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo
Fresh-init copy of the security-review/ subsystem extracted from
Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold:
CI reusable-workflow callers (ruff + collect), dependency-review, labeler,
dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to
Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and
nightly_sweep.sh/checker_coordinator.sh remain the source of truth.

Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry
intentional secret-shaped test data that trips the deterministic gate (the
documented detector-fixture false positive); no new logic is introduced.
2026-06-29 11:41:41 -04:00

16 lines
503 B
YAML

name: CI
on:
pull_request:
branches: [main]
permissions:
contents: read
jobs:
ci:
# Thin wrapper over the org reusable CI: ruff lint/format + conventions and a
# root `pytest --collect-only` import check. This is code hygiene for THIS repo's
# own source (run_headless.py et al.), not a security gate over other repos. The
# aggregator job (keyed `ci`) emits the org-required `ci / ci` check.
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml@main