chore(public): add CI coverage security and OSS process visibility
This commit is contained in:
@@ -0,0 +1,131 @@
|
||||
name: Security
|
||||
|
||||
# GitHub Actions is public mirror validation only.
|
||||
# Primary registry release security evidence must be produced on Russian build-runner.
|
||||
|
||||
on:
|
||||
push:
|
||||
pull_request:
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
pull-requests: read
|
||||
|
||||
jobs:
|
||||
cargo-audit:
|
||||
name: Cargo audit
|
||||
runs-on: ubuntu-latest
|
||||
defaults:
|
||||
run:
|
||||
shell: bash
|
||||
working-directory: adk-rust
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
lfs: false
|
||||
|
||||
- name: Install stable Rust
|
||||
uses: dtolnay/rust-toolchain@stable
|
||||
|
||||
- name: Install cargo-audit
|
||||
uses: taiki-e/install-action@cargo-audit
|
||||
|
||||
- name: cargo audit
|
||||
run: cargo audit
|
||||
|
||||
cargo-deny:
|
||||
name: Cargo deny
|
||||
runs-on: ubuntu-latest
|
||||
defaults:
|
||||
run:
|
||||
shell: bash
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
lfs: false
|
||||
|
||||
- name: Install stable Rust
|
||||
uses: dtolnay/rust-toolchain@stable
|
||||
|
||||
- name: Install cargo-deny
|
||||
uses: taiki-e/install-action@cargo-deny
|
||||
|
||||
- name: cargo deny
|
||||
run: cargo deny --manifest-path adk-rust/Cargo.toml --config deny.toml check
|
||||
|
||||
secret-pattern-check:
|
||||
name: Secret pattern check
|
||||
runs-on: ubuntu-latest
|
||||
defaults:
|
||||
run:
|
||||
shell: bash
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
lfs: false
|
||||
|
||||
- name: Scan for obvious secret patterns
|
||||
run: |
|
||||
python3 - <<'PY'
|
||||
import os
|
||||
import re
|
||||
import sys
|
||||
from pathlib import Path
|
||||
|
||||
root = Path(".")
|
||||
text_suffixes = {
|
||||
".cfg", ".conf", ".env", ".ini", ".json", ".lock", ".md", ".py",
|
||||
".rs", ".sh", ".toml", ".ts", ".txt", ".yaml", ".yml"
|
||||
}
|
||||
skip_dirs = {
|
||||
".git", "target", "node_modules", "release-evidence", "dist", "bin"
|
||||
}
|
||||
patterns = [
|
||||
("private_key_header", re.compile(r"-----BEGIN (?:RSA |OPENSSH |EC |DSA )?PRIVATE KEY-----")),
|
||||
("aws_access_key", re.compile(r"\bAKIA[0-9A-Z]{16}\b")),
|
||||
("secret_assignment", re.compile(
|
||||
r"(?i)\b(password|passwd|pwd|token|secret|api[_-]?key|bearer|cookie)\b"
|
||||
r"\s*[:=]\s*[\"']?[A-Za-z0-9_./+=-]{16,}"
|
||||
)),
|
||||
]
|
||||
findings = []
|
||||
for path in root.rglob("*"):
|
||||
if not path.is_file():
|
||||
continue
|
||||
if any(part in skip_dirs for part in path.parts):
|
||||
continue
|
||||
if path.suffix.lower() not in text_suffixes:
|
||||
continue
|
||||
try:
|
||||
lines = path.read_text(encoding="utf-8", errors="ignore").splitlines()
|
||||
except OSError:
|
||||
continue
|
||||
for line_no, line in enumerate(lines, start=1):
|
||||
for name, pattern in patterns:
|
||||
if pattern.search(line):
|
||||
findings.append(f"{path}:{line_no}:{name}")
|
||||
break
|
||||
if findings:
|
||||
print("secret_pattern_check=fail")
|
||||
for finding in findings:
|
||||
print(finding)
|
||||
sys.exit(2)
|
||||
print("secret_pattern_check=ok")
|
||||
PY
|
||||
|
||||
dependency-review:
|
||||
name: Dependency review
|
||||
runs-on: ubuntu-latest
|
||||
if: github.event_name == 'pull_request'
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
lfs: false
|
||||
|
||||
- name: Dependency Review
|
||||
uses: actions/dependency-review-action@v4
|
||||
Reference in New Issue
Block a user