feat: add Dependabot and security check templates - #28
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Organization UI Review profile: QUIET Plan: Advanced Run ID: 📒 Files selected for processing (9)
Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ed551f0c70
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| persist-credentials: false | ||
| - uses: EmbarkStudios/cargo-deny-action@3c6349835b2b7b196a839186cb8b78e02f7b5f25 # v2.1.1 | ||
| with: | ||
| command: check ${{ matrix.checks }} |
There was a problem hiding this comment.
Pass check selectors through command-arguments
Every Cargo repository adopting this template supplies check advisories or check bans licenses sources as the single command value. The pinned action's input contract treats command as one cargo-deny subcommand and provides command-arguments for selectors, so both matrix jobs invoke an invalid subcommand instead of performing an audit. Keep command: check and pass ${{ matrix.checks }} through command-arguments.
AGENTS.md reference: AGENTS.md:L15-L16
Useful? React with 👍 / 👎.
| - uses: EmbarkStudios/cargo-deny-action@3c6349835b2b7b196a839186cb8b78e02f7b5f25 # v2.1.1 | ||
| with: | ||
| command: check ${{ matrix.checks }} |
There was a problem hiding this comment.
Audit every configured Cargo workspace
In repositories with Cargo workspaces below the repository root—the layout explicitly supported by the new adoption guidance—this action still runs only from the checkout root and supplies neither a workspace-specific working directory nor a manifest path. Cargo-deny cannot discover child manifests, so a repository with only nested workspaces fails immediately, while one with an unrelated root workspace silently leaves the nested workspaces unaudited; add workspace manifests/configs to the matrix or require a separate job for each workspace.
AGENTS.md reference: AGENTS.md:L15-L16
Useful? React with 👍 / 👎.
|
Decision (lemarier, Roger Ask |
Change
No repository had Dependabot version updates, dependency review, or a workflow audit, and the dependency standard only said a repo "may configure an update bot". This adds the shared baseline and runs it here.
templates/dependabot.yml: weekly updates grouped per ecosystem for minor and patch, majors as separate PRs, and a three-day cooldown so proposals clear pnpm'sminimumReleaseAge. Security updates are not delayed.templates/workflows/origin89-security.yml: dependency review of what a PR adds (vulnerabilities at moderate or above, plus a license allowlist), zizmor 1.30.1 on the workflows, and cargo-deny. A new RustSec advisory reports on PRs without blocking them, and fails the weekly and default-branch runs.templates/rust/deny.toml: the shared cargo-deny policy.docs/dependencies.mdanddocs/adopting.mddescribe the policy (people merge every update) and the repository settings.pull_request_targettrigger is accepted, so zizmor passes in adopting repos.The repository settings (Dependabot alerts and security updates, secret scanning with push protection, private vulnerability reporting, CodeQL default setup, and organization defaults for new repos) were applied separately through the API. Each adopting repo gets its own PR.
Validation
just check: 32 tests pass.actionlinton.github/workflows/*.ymland on the rendered security template: clean.zizmor 1.30.1 --min-severity mediumon.github/workflowsandtemplates/workflows: clean except the template'sENGINEERING_COMMIT_SHAplaceholder, which consumers replace.cargo deny checkwith the template on both firmware workspaces runs and reports real findings (git sources, a few licenses, unmaintained crates). Those are handled in the firmware PR, which shows the template needs per-repo exceptions rather than working unchanged.main.