Skip to content

feat: add Dependabot and security check templates - #28

Merged
lemarier merged 2 commits into
mainfrom
lemarier/dependabot
Sep 27, 2026
Merged

lemarier merged 2 commits into
mainfrom
lemarier/dependabot

Conversation

@lemarier

Copy link
Copy Markdown
Contributor

Change

No repository had Dependabot version updates, dependency review, or a workflow audit, and the dependency standard only said a repo "may configure an update bot". This adds the shared baseline and runs it here.

  • templates/dependabot.yml: weekly updates grouped per ecosystem for minor and patch, majors as separate PRs, and a three-day cooldown so proposals clear pnpm's minimumReleaseAge. Security updates are not delayed.
  • templates/workflows/origin89-security.yml: dependency review of what a PR adds (vulnerabilities at moderate or above, plus a license allowlist), zizmor 1.30.1 on the workflows, and cargo-deny. A new RustSec advisory reports on PRs without blocking them, and fails the weekly and default-branch runs.
  • templates/rust/deny.toml: the shared cargo-deny policy.
  • docs/dependencies.md and docs/adopting.md describe the policy (people merge every update) and the repository settings.
  • The OCR review caller template now records why its pull_request_target trigger is accepted, so zizmor passes in adopting repos.
  • Engineering itself gets a github-actions Dependabot config and a zizmor job.

The repository settings (Dependabot alerts and security updates, secret scanning with push protection, private vulnerability reporting, CodeQL default setup, and organization defaults for new repos) were applied separately through the API. Each adopting repo gets its own PR.

Validation

  • just check: 32 tests pass.
  • actionlint on .github/workflows/*.yml and on the rendered security template: clean.
  • zizmor 1.30.1 --min-severity medium on .github/workflows and templates/workflows: clean except the template's ENGINEERING_COMMIT_SHA placeholder, which consumers replace.
  • cargo deny check with the template on both firmware workspaces runs and reports real findings (git sources, a few licenses, unmaintained crates). Those are handled in the firmware PR, which shows the template needs per-repo exceptions rather than working unchanged.
  • Dependabot's own parsing of the config is only proven once it runs on main.

Copilot AI lite review requested due to automatic review settings September 27, 2026 11:58

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T12:03:23.156338Z ed551f0 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Sep 27, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: QUIET

Plan: Advanced

Run ID: 10b5f0d5-2e5e-4207-91d4-1391b2cdd3c5

📥 Commits

Reviewing files that changed from the base of the PR and between 99052e8 and ed551f0.

📒 Files selected for processing (9)
  • .github/dependabot.yml
  • .github/workflows/security.yml
  • docs/adopting.md
  • docs/dependencies.md
  • templates/dependabot.yml
  • templates/rust/deny.toml
  • templates/workflows/ocr-review.yml
  • templates/workflows/origin89-security.properties.json
  • templates/workflows/origin89-security.yml

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ed551f0c70

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

persist-credentials: false
- uses: EmbarkStudios/cargo-deny-action@3c6349835b2b7b196a839186cb8b78e02f7b5f25 # v2.1.1
with:
command: check ${{ matrix.checks }}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Pass check selectors through command-arguments

Every Cargo repository adopting this template supplies check advisories or check bans licenses sources as the single command value. The pinned action's input contract treats command as one cargo-deny subcommand and provides command-arguments for selectors, so both matrix jobs invoke an invalid subcommand instead of performing an audit. Keep command: check and pass ${{ matrix.checks }} through command-arguments.

AGENTS.md reference: AGENTS.md:L15-L16

Useful? React with 👍 / 👎.

Comment on lines +65 to +67
- uses: EmbarkStudios/cargo-deny-action@3c6349835b2b7b196a839186cb8b78e02f7b5f25 # v2.1.1
with:
command: check ${{ matrix.checks }}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Audit every configured Cargo workspace

In repositories with Cargo workspaces below the repository root—the layout explicitly supported by the new adoption guidance—this action still runs only from the checkout root and supplies neither a workspace-specific working directory nor a manifest path. Cargo-deny cannot discover child manifests, so a repository with only nested workspaces fails immediately, while one with an unrelated root workspace silently leaves the nested workspaces unaudited; add workspace manifests/configs to the matrix or require a separate job for each workspace.

AGENTS.md reference: AGENTS.md:L15-L16

Useful? React with 👍 / 👎.

@lemarier

Copy link
Copy Markdown
Contributor Author

Decision (lemarier, Roger Ask 01M3HFKBAX1NRNFDP0P1Q1QVW9): "Keep 7 days". The Dependabot cooldown stays at 7 days in every repository, as merged here; no .github/zizmor.yml override is added.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants