Skip to content

ci: add Dependabot and security checks - #43

Merged
lemarier merged 2 commits into
mainfrom
lemarier/dependabot
Sep 27, 2026
Merged

lemarier merged 2 commits into
mainfrom
lemarier/dependabot

Conversation

@lemarier

@lemarier lemarier commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Change

Adopts the dependency and security baseline from origin89hq/engineering#28. .github/dependabot.yml proposes weekly updates for GitHub Actions, the Cargo workspace at /, rust-toolchain.toml, and the Swift packages the Xcode project pins. Minor and patch updates are grouped per ecosystem, majors arrive as separate PRs, and every entry waits a seven-day cooldown, the minimum zizmor 1.30.1 accepts. Nothing auto-merges.

The Swift entry points at /apps/ios. The local Package.swift files there (SetupKit, SetupCore, SetupBench) have only path dependencies; the one remote package, origin89hq/ui at exact version 0.4.0, is declared in Origin89.xcodeproj and pinned in its project.xcworkspace/xcshareddata/swiftpm/Package.resolved. Dependabot's Swift ecosystem supports this Xcode-managed layout when the directory has no Package.swift: it updates Package.resolved and the XCRemoteSwiftPackageReference version in project.pbxproj (dependabot/dependabot-core#14587). Upstream reports that originHash may not be refreshed (dependabot/dependabot-core#7694), so the first Swift PR should be opened in Xcode or built by just check before merging.

.github/workflows/origin89-security.yml adds dependency review on pull requests, a zizmor audit of the workflows, and cargo-deny with the shared deny.toml. A new RustSec advisory reports on pull requests without blocking them and fails the weekly and main runs.

deny.toml records one license exception set: the eight UniFFI crates (uniffi, uniffi_bindgen, uniffi_core, uniffi_internal_macros, uniffi_macros, uniffi_meta, uniffi_pipeline, uniffi_udl) are MPL-2.0 (mozilla/uniffi-rs). MPL-2.0 is file-level copyleft that applies to changes in its own files, which this repository uses unmodified, so each crate gets a licenses.exceptions entry instead of widening the shared allow list.

Validation

  • cargo deny --manifest-path Cargo.toml check: failed on the eight MPL-2.0 UniFFI crates before the exceptions; advisories, bans, licenses and sources ok after.
  • uvx zizmor@1.30.1 --offline --min-severity medium .github/: no findings (5 suppressed).
  • actionlint: clean.

Dependabot's handling of the Xcode Package.resolved is checked against the dependabot-core source and issues, not by a live run; the first scheduled run will show it.

Copilot AI lite review requested due to automatic review settings September 27, 2026 12:02

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T12:06:55.318637Z 32771ab PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

📝 Walkthrough

Walkthrough

Adds weekly Dependabot updates for GitHub Actions, Cargo, Rust toolchains, and Swift packages. Adds Cargo dependency policies for advisories, licenses, dependency versions, and sources. Adds a GitHub Actions workflow that runs dependency review, zizmor, and cargo-deny checks under the configured triggers and permissions.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Merge Risk: 🔵 Low · up to 32771

Dependency updates remain reviewable, but the new check can miss advisories for dependencies whose scope GitHub cannot classify. Include the unknown scope before relying on this check.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 32771

The new checks improve dependency oversight, but the pull-request gate does not block findings assigned an unknown dependency scope. That can leave some Swift dependency changes outside the intended blocking check. Updates are proposed as pull requests, not merged automatically.

Retained concerns

  • Low · security · observed: The newly added pull-request dependency gate fails on runtime and development findings, but not findings assigned unknown scope. A moderate-or-higher finding on a Swift dependency can therefore be reported without failing this gate when assigned unknown scope.
Security review details

Security Blast Radius

  • inferred — The independently affected scope is a dependency-changing pull request whose finding is assigned unknown scope, rather than a grant of repository-write authority to the workflow. Whether a particular Swift update receives that classification remains unconfirmed by an action run.

Security Findings and Attack Paths

  • observed — The retained finding identifies a gap in the new blocking policy: a pull request adding a vulnerable dependency assigned unknown scope can pass the dependency-review failure threshold despite a moderate-or-higher finding. It does not establish automatic merge or execution of that dependency.

Trust Boundaries and Controls

  • observed — Dependency changes enter through pull requests and are checked by a job without continue-on-error. Its explicit scope filter limits which findings can fail that job; the main and scheduled runs do not run dependency review.

Resilience and Maintainability Implications

  • observed — Cargo advisory checks retain normal failure behavior on main and scheduled runs, but that recovery signal is separate from the pull-request-only dependency review of Swift changes.

Hardening Proposals

  • proposed — If Swift dependencies are intended to be covered by the blocking gate, include unknown scope in its failure policy and confirm the classification with an actual Swift dependency update.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly and concisely describes the main changes: adding Dependabot configuration and security checks.
Description check ✅ Passed The description includes the required Change and Validation sections. It explains the configuration, security behavior, license exceptions, validation commands, results, and the unperformed live Depen…

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

Quiet mode is enabled, so only the most important comments were posted inline. Other review comments are grouped below.

🟡 Other comments (1)
.github/workflows/origin89-security.yml-29-29 (1)

29-29: 🔒 Security & Privacy | 🛡️ Detected with Advanced Tier | 🟡 Minor | ⚡ Quick win

Security Misconfiguration

Reachability: External
Exploitability: Moderate
CWE: CWE-693

Fail dependency review for unknown-scope dependencies.

fail-on-scopes omits unknown. GitHub can assign unknown to Swift packages when it cannot classify their scope, so a moderate-or-higher advisory can pass this check.

Include the unknown scope
-          fail-on-scopes: runtime, development
+          fail-on-scopes: runtime, development, unknown

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: QUIET

Plan: Advanced

Run ID: b1b8371d-54a9-4839-87d9-befd7bd83822

📥 Commits

Reviewing files that changed from the base of the PR and between 124a8cc and 32771ab.

📒 Files selected for processing (3)
  • .github/dependabot.yml
  • .github/workflows/origin89-security.yml
  • deny.toml

Limit details: You’ve used all 10 included reviews currently available.

@lemarier
lemarier merged commit 4f91e22 into main Sep 27, 2026
7 checks passed
@lemarier
lemarier deleted the lemarier/dependabot branch September 27, 2026 12:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants