Skip to content

ci: offer the Origin89 security workflow template - #2

Merged
lemarier merged 1 commit into
mainfrom
lemarier/dependabot
Sep 27, 2026
Merged

lemarier merged 1 commit into
mainfrom
lemarier/dependabot

Conversation

@lemarier

Copy link
Copy Markdown
Contributor

Change

Adds workflow-templates/origin89-security.yml and its .properties.json, copied unchanged from origin89hq/engineering#28, so Actions → New workflow offers the Origin89 security checks in every organization repository. The workflow runs dependency review on pull requests, a zizmor audit of the workflows, and cargo-deny for Cargo workspaces. GitHub replaces $default-branch when a repository adopts it. Adopters still delete the cargo-deny job without a Cargo.lock, delete dependency review in private repositories without GitHub Advanced Security, and add deny.toml and .github/dependabot.yml from the engineering templates, which the picker does not install.

This repository has no workflows or dependencies, so it gets no dependabot.yml.

Validation

  • actionlint on the template and on a copy with $default-branch replaced by main: clean.
  • uvx zizmor@1.30.1 --offline --min-severity medium on the rendered copy: no findings.
  • python3 -m json.tool on the properties file: valid.
  • Not checked: how the template appears in the workflow picker, which only shows after merge.

Copilot AI lite review requested due to automatic review settings September 27, 2026 12:02

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai

coderabbitai Bot commented Sep 27, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: QUIET

Plan: Advanced

Run ID: e0d47dc4-9122-4b64-9971-e7ba9568a442

📥 Commits

Reviewing files that changed from the base of the PR and between 948c19f and 7dc7d9f.

📒 Files selected for processing (2)
  • workflow-templates/origin89-security.properties.json
  • workflow-templates/origin89-security.yml

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T12:06:01.575420Z 7dc7d9f PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@lemarier
lemarier merged commit 14923fd into main Sep 27, 2026
1 check was pending
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants