chore(public): add CI coverage security and OSS process visibility

This commit is contained in:
igor04091968
2026-06-21 08:54:53 +03:00
parent f5e9c81c5b
commit 4970d31a81
21 changed files with 798 additions and 52 deletions
+131
View File
@@ -0,0 +1,131 @@
name: Security
# GitHub Actions is public mirror validation only.
# Primary registry release security evidence must be produced on Russian build-runner.
on:
push:
pull_request:
workflow_dispatch:
permissions:
contents: read
pull-requests: read
jobs:
cargo-audit:
name: Cargo audit
runs-on: ubuntu-latest
defaults:
run:
shell: bash
working-directory: adk-rust
steps:
- name: Checkout
uses: actions/checkout@v4
with:
lfs: false
- name: Install stable Rust
uses: dtolnay/rust-toolchain@stable
- name: Install cargo-audit
uses: taiki-e/install-action@cargo-audit
- name: cargo audit
run: cargo audit
cargo-deny:
name: Cargo deny
runs-on: ubuntu-latest
defaults:
run:
shell: bash
steps:
- name: Checkout
uses: actions/checkout@v4
with:
lfs: false
- name: Install stable Rust
uses: dtolnay/rust-toolchain@stable
- name: Install cargo-deny
uses: taiki-e/install-action@cargo-deny
- name: cargo deny
run: cargo deny --manifest-path adk-rust/Cargo.toml --config deny.toml check
secret-pattern-check:
name: Secret pattern check
runs-on: ubuntu-latest
defaults:
run:
shell: bash
steps:
- name: Checkout
uses: actions/checkout@v4
with:
lfs: false
- name: Scan for obvious secret patterns
run: |
python3 - <<'PY'
import os
import re
import sys
from pathlib import Path
root = Path(".")
text_suffixes = {
".cfg", ".conf", ".env", ".ini", ".json", ".lock", ".md", ".py",
".rs", ".sh", ".toml", ".ts", ".txt", ".yaml", ".yml"
}
skip_dirs = {
".git", "target", "node_modules", "release-evidence", "dist", "bin"
}
patterns = [
("private_key_header", re.compile(r"-----BEGIN (?:RSA |OPENSSH |EC |DSA )?PRIVATE KEY-----")),
("aws_access_key", re.compile(r"\bAKIA[0-9A-Z]{16}\b")),
("secret_assignment", re.compile(
r"(?i)\b(password|passwd|pwd|token|secret|api[_-]?key|bearer|cookie)\b"
r"\s*[:=]\s*[\"']?[A-Za-z0-9_./+=-]{16,}"
)),
]
findings = []
for path in root.rglob("*"):
if not path.is_file():
continue
if any(part in skip_dirs for part in path.parts):
continue
if path.suffix.lower() not in text_suffixes:
continue
try:
lines = path.read_text(encoding="utf-8", errors="ignore").splitlines()
except OSError:
continue
for line_no, line in enumerate(lines, start=1):
for name, pattern in patterns:
if pattern.search(line):
findings.append(f"{path}:{line_no}:{name}")
break
if findings:
print("secret_pattern_check=fail")
for finding in findings:
print(finding)
sys.exit(2)
print("secret_pattern_check=ok")
PY
dependency-review:
name: Dependency review
runs-on: ubuntu-latest
if: github.event_name == 'pull_request'
steps:
- name: Checkout
uses: actions/checkout@v4
with:
lfs: false
- name: Dependency Review
uses: actions/dependency-review-action@v4