ci: add Dependabot and security checks - #43
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 📝 WalkthroughWalkthroughAdds weekly Dependabot updates for GitHub Actions, Cargo, Rust toolchains, and Swift packages. Adds Cargo dependency policies for advisories, licenses, dependency versions, and sources. Adds a GitHub Actions workflow that runs dependency review, zizmor, and cargo-deny checks under the configured triggers and permissions. Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Merge Risk: 🔵 Low · up to Dependency updates remain reviewable, but the new check can miss advisories for dependencies whose scope GitHub cannot classify. Include the unknown scope before relying on this check. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The new checks improve dependency oversight, but the pull-request gate does not block findings assigned an unknown dependency scope. That can leave some Swift dependency changes outside the intended blocking check. Updates are proposed as pull requests, not merged automatically. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Comment |
There was a problem hiding this comment.
Note
Quiet mode is enabled, so only the most important comments were posted inline. Other review comments are grouped below.
🟡 Other comments (1)
.github/workflows/origin89-security.yml-29-29 (1)
29-29: 🔒 Security & Privacy | 🛡️ Detected with Advanced Tier | 🟡 Minor | ⚡ Quick winSecurity Misconfiguration
Reachability: External
Exploitability: Moderate
CWE: CWE-693Fail dependency review for unknown-scope dependencies.
fail-on-scopesomitsunknown. GitHub can assignunknownto Swift packages when it cannot classify their scope, so a moderate-or-higher advisory can pass this check.Include the unknown scope
- fail-on-scopes: runtime, development + fail-on-scopes: runtime, development, unknown
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: QUIET
Plan: Advanced
Run ID: b1b8371d-54a9-4839-87d9-befd7bd83822
📒 Files selected for processing (3)
.github/dependabot.yml.github/workflows/origin89-security.ymldeny.toml
Limit details: You’ve used all 10 included reviews currently available.
Change
Adopts the dependency and security baseline from origin89hq/engineering#28.
.github/dependabot.ymlproposes weekly updates for GitHub Actions, the Cargo workspace at/,rust-toolchain.toml, and the Swift packages the Xcode project pins. Minor and patch updates are grouped per ecosystem, majors arrive as separate PRs, and every entry waits a seven-day cooldown, the minimum zizmor 1.30.1 accepts. Nothing auto-merges.The Swift entry points at
/apps/ios. The localPackage.swiftfiles there (SetupKit, SetupCore, SetupBench) have only path dependencies; the one remote package,origin89hq/uiat exact version 0.4.0, is declared inOrigin89.xcodeprojand pinned in itsproject.xcworkspace/xcshareddata/swiftpm/Package.resolved. Dependabot's Swift ecosystem supports this Xcode-managed layout when the directory has noPackage.swift: it updatesPackage.resolvedand theXCRemoteSwiftPackageReferenceversion inproject.pbxproj(dependabot/dependabot-core#14587). Upstream reports thatoriginHashmay not be refreshed (dependabot/dependabot-core#7694), so the first Swift PR should be opened in Xcode or built byjust checkbefore merging..github/workflows/origin89-security.ymladds dependency review on pull requests, a zizmor audit of the workflows, and cargo-deny with the shareddeny.toml. A new RustSec advisory reports on pull requests without blocking them and fails the weekly andmainruns.deny.tomlrecords one license exception set: the eight UniFFI crates (uniffi,uniffi_bindgen,uniffi_core,uniffi_internal_macros,uniffi_macros,uniffi_meta,uniffi_pipeline,uniffi_udl) are MPL-2.0 (mozilla/uniffi-rs). MPL-2.0 is file-level copyleft that applies to changes in its own files, which this repository uses unmodified, so each crate gets alicenses.exceptionsentry instead of widening the sharedallowlist.Validation
cargo deny --manifest-path Cargo.toml check: failed on the eight MPL-2.0 UniFFI crates before the exceptions; advisories, bans, licenses and sources ok after.uvx zizmor@1.30.1 --offline --min-severity medium .github/: no findings (5 suppressed).actionlint: clean.Dependabot's handling of the Xcode
Package.resolvedis checked against the dependabot-core source and issues, not by a live run; the first scheduled run will show it.