Skip to content

ci: add Dependabot and security checks - #241

Open
lemarier wants to merge 3 commits into
mainfrom
lemarier/dependabot
Open

lemarier wants to merge 3 commits into
mainfrom
lemarier/dependabot

Conversation

@lemarier

@lemarier lemarier commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Change

Adds Dependabot version updates and the shared origin89-security workflow from origin89hq/engineering#28. Updates run weekly with minor and patch releases grouped per ecosystem, majors as separate PRs, and a seven-day cooldown; nothing auto-merges. The workflow runs dependency review on pull requests and a zizmor audit of the workflows on pull requests, pushes to main, and weekly. There is no Cargo workspace, so the cargo-deny job is omitted.

Dependabot covers GitHub Actions in the workflows and the setup and setup-duckdb composite actions, and the pnpm workspace through the npm ecosystem at the root.

The seven-day cooldown is the minimum zizmor 1.30.1 accepts, so no cooldown ignore is needed; security updates are not delayed.

zizmor also flagged two existing files, recorded as reviewed exceptions rather than changed. publish.yml uses workflow_run, but its only trigger source is Deploy the spider, which runs by workflow_dispatch on main alone; the publish job checks out the default branch rather than the triggering run's head and downloads no artifacts, so it never runs untrusted code with its OIDC token. setup-duckdb appends a fixed $RUNNER_TEMP directory holding the checksum-verified CLI to GITHUB_PATH, with no input from the event.

Validation

  • uvx zizmor@1.30.1 --offline --min-severity medium .github/: no findings; before this change it reported the two findings above.
  • actionlint: clean.
  • check-jsonschema with the Dependabot and GitHub workflow schemas: both new files pass.
  • The new workflow has not run yet; this PR is its first run.

Copilot AI lite review requested due to automatic review settings September 27, 2026 12:01

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T12:05:32.045565Z 17880b5 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: QUIET

Plan: Advanced

Run ID: ecc1e591-ff21-4000-984a-3d38262786a1

📥 Commits

Reviewing files that changed from the base of the PR and between da98e90 and a5f4d9c.

📒 Files selected for processing (5)
  • .github/actions/setup-duckdb/action.yml
  • .github/actions/setup/action.yml
  • .github/dependabot.yml
  • .github/workflows/origin89-security.yml
  • .github/workflows/publish.yml

Limit details: You’ve used all 10 included reviews currently available.


📝 Walkthrough

Walkthrough

The changes add weekly Dependabot updates for GitHub Actions and npm, plus a workflow that reviews dependencies on pull requests and runs zizmor checks. They also update the pnpm setup action reference and add zizmor suppression annotations to an action and a workflow declaration.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Merge Risk: ⚪ Minimal · up to a5f4d

No concrete issue remains that should block merging. The new security checks will receive their first run after the workflow is enabled.

Security Architecture Review

Security architecture risk: 🔵 Low · up to a5f4d

The new checks have read-only repository access, and the production publishing trigger and permissions are unchanged. No security regression was established, but the new workflow has not yet run and production environment restrictions could not be confirmed.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The new checks can assess pull-request content but receive only read-only repository permission. The separately privileged production publisher remains on its existing workflow and Worker authorization path.

Security Findings and Attack Paths

  • inferred — No PR-induced path from pull-request content to production publishing was established: the publish job gates successful workflow runs, checks out the default branch, and the Worker independently restricts publish identity. This does not prove the unavailable production environment settings.

Trust Boundaries and Controls

  • observed — The publisher requests a fresh GitHub OIDC token for the Worker audience; the Worker verifies its signature and claims and restricts the publishing route to the designated workflow and production environment.

Hardening Proposals

  • proposed — Confirm the production environment's deployment-branch restrictions and the provenance of the replacement pnpm action revision before relying on those controls in production.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly and concisely summarizes the main changes: adding Dependabot configuration and security checks.
Description check ✅ Passed The description includes the required Change and Validation sections. It explains the configuration, scope, reviewed exceptions, validation commands, results, and the fact that the new workflow has no…

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants