File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 1- # SPDX-License-Identifier: PMPL-1.0-or-later
1+ # SPDX-License-Identifier: PMPL-1.0
22name : CodeQL Security Analysis
33
44on :
99 schedule :
1010 - cron : ' 0 6 * * 1'
1111
12+ # Estate guardrail: cancel superseded runs so re-pushes / rebased PR
13+ # updates do not pile up queued runs against the shared account-wide
14+ # Actions concurrency pool. Applied only to read-only check workflows
15+ # (no publish/mutation), so cancelling a superseded run is always safe.
16+ concurrency :
17+ group : ${{ github.workflow }}-${{ github.ref }}
18+ cancel-in-progress : true
19+
1220permissions :
1321 contents : read
1422
@@ -30,17 +38,12 @@ jobs:
3038 uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
3139
3240 - name : Initialize CodeQL
33- uses : github/codeql-action/init@38697555549f1db7851b81482ff19f1fa5c4fedc # v3.28.1
41+ uses : github/codeql-action/init@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v3
3442 with :
3543 languages : ${{ matrix.language }}
3644 build-mode : ${{ matrix.build-mode }}
3745
3846 - name : Perform CodeQL Analysis
39- uses : github/codeql-action/analyze@38697555549f1db7851b81482ff19f1fa5c4fedc # v3.28.1
47+ uses : github/codeql-action/analyze@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v3
4048 with :
4149 category : " /language:${{ matrix.language }}"
42-
43- - name : K9-SVC Validation
44- run : |
45- echo "K9-SVC validation"
46- [ -d .machine_readable/contractiles ] && echo "Contractiles present" || echo "No contractiles"
Original file line number Diff line number Diff line change 3939 publish_results : true
4040
4141 - name : Upload SARIF
42- uses : github/codeql-action/upload-sarif@38697555549f1db7851b81482ff19f1fa5c4fedc # v4
42+ uses : github/codeql-action/upload-sarif@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v4
4343 with :
4444 sarif_file : results.sarif
4545
Original file line number Diff line number Diff line change 1- # SPDX-License-Identifier: PMPL-1.0-or-later
1+ # SPDX-License-Identifier: PMPL-1.0
22name : OSSF Scorecard
33on :
44 push :
3636 results_format : sarif
3737
3838 - name : Upload results
39- uses : github/codeql-action/upload-sarif@38697555549f1db7851b81482ff19f1fa5c4fedc # v3.31.8
39+ uses : github/codeql-action/upload-sarif@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v3.31.8
4040 with :
4141 sarif_file : results.sarif
Original file line number Diff line number Diff line change 1- # SPDX-License-Identifier: PMPL-1.0-or-later
1+ # SPDX-License-Identifier: PMPL-1.0
22# Prevention workflow - scans for hardcoded secrets before they reach main
33name : Secret Scanner
44
2727 fetch-depth : 0 # Full history for scanning
2828
2929 - name : TruffleHog Secret Scan
30- uses : trufflesecurity/trufflehog@6c64db94d5b2e09d7e0948fb6bd3166cc6fffbc7 # v3
30+ uses : trufflesecurity/trufflehog@6c05c4a00b91aa542267d8e32a8254774799d68d # v3
3131 with :
32- extra_args : --only-verified --fail
32+ # The v3 action injects --fail automatically on pull_request events.
33+ # Passing --fail here triggers "flag 'fail' cannot be repeated".
34+ extra_args : --only-verified
3335
3436 gitleaks :
3537 runs-on : ubuntu-latest
@@ -46,12 +48,15 @@ jobs:
4648 # Rust-specific: Check for hardcoded crypto values
4749 rust-secrets :
4850 runs-on : ubuntu-latest
49- if : hashFiles('**/Cargo.toml') != ''
5051 steps :
5152 - uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4
5253
5354 - name : Check for hardcoded secrets in Rust
5455 run : |
56+ if ! find . -name Cargo.toml -not -path './target/*' -print -quit | grep -q .; then
57+ echo 'No Cargo.toml found — skipping Rust secrets check'
58+ exit 0
59+ fi
5560 # Patterns that suggest hardcoded secrets
5661 PATTERNS=(
5762 'const.*SECRET.*=.*"'
You can’t perform that action at this time.
0 commit comments