1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
name: Security
# Quiet-public. The jobs below stay commented until Snapif is meant to be found.
# Uncomment one job at a time. Do not add a badge, a README pitch, or a publish.
on:
workflow_dispatch:
permissions:
contents: read
concurrency:
group: security-${{ github.ref }}
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
jobs:
hold:
name: Hold
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2
with:
egress-policy: audit
- run: echo "CodeQL, Dependency Review, Scorecard, and FOSSA stay commented"
# codeql:
# name: CodeQL
# runs-on: ubuntu-latest
# timeout-minutes: 30
# permissions:
# actions: read
# contents: read
# security-events: write
# strategy:
# fail-fast: false
# matrix:
# include:
# - language: rust
# build-mode: manual
# - language: actions
# build-mode: none
# steps:
# - uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2
# with:
# egress-policy: audit
# - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
# with:
# persist-credentials: false
# - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master
# if: matrix.language == 'rust'
# with:
# toolchain: "1.95"
# - uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
# with:
# languages: ${{ matrix.language }}
# build-mode: ${{ matrix.build-mode }}
# queries: security-and-quality
# - name: Build Rust
# if: matrix.build-mode == 'manual'
# run: cargo build --locked --all-targets
# - uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
# with:
# category: "/language:${{ matrix.language }}"
# dependency-review:
# name: Dependency Review
# if: github.event_name == 'pull_request'
# runs-on: ubuntu-latest
# timeout-minutes: 10
# steps:
# - uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2
# with:
# egress-policy: audit
# - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
# with:
# persist-credentials: false
# - uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0
# scorecard:
# name: Scorecard
# runs-on: ubuntu-latest
# timeout-minutes: 15
# permissions:
# security-events: write
# id-token: write
# contents: read
# actions: read
# steps:
# - uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2
# with:
# egress-policy: audit
# - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
# with:
# persist-credentials: false
# - uses: ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc # v2.4.4
# with:
# results_format: sarif
# results_file: results.sarif
# publish_results: true
# fossa:
# name: FOSSA
# runs-on: ubuntu-latest
# timeout-minutes: 15
# steps:
# - uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2
# with:
# egress-policy: audit
# - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
# with:
# persist-credentials: false
# fetch-depth: 0
# - uses: fossas/fossa-action@29693cc50323968e039056be419b32989fc5880c # v2.0.0
# with:
# api-key: ${{ secrets.FOSSA_API_KEY }}