Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
56 changes: 56 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
# Started from origin89hq/engineering templates/dependabot.yml; see its docs/dependencies.md.
version: 2

updates:
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
cooldown:
default-days: 7
groups:
actions:
patterns: ["*"]
update-types: [minor, patch]
commit-message:
prefix: ci

- package-ecosystem: cargo
directories: [/]
schedule:
interval: weekly
cooldown:
default-days: 7
groups:
cargo:
patterns: ["*"]
update-types: [minor, patch]
commit-message:
prefix: chore
include: scope

- package-ecosystem: rust-toolchain
directory: /
schedule:
interval: weekly
cooldown:
default-days: 7
commit-message:
prefix: chore
include: scope

# The Xcode project pins its remote packages in the project's Package.resolved;
# the local Package.swift files under apps/ios have no remote dependencies.
- package-ecosystem: swift
directory: /apps/ios
schedule:
interval: weekly
cooldown:
default-days: 7
groups:
swift:
patterns: ["*"]
update-types: [minor, patch]
commit-message:
prefix: chore
include: scope
67 changes: 67 additions & 0 deletions .github/workflows/origin89-security.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
# Copy to .github/workflows/origin89-security.yml; see engineering's docs/dependencies.md.
# Delete the cargo-deny job in repositories without a Cargo.lock, and the
# dependency-review job in private repositories without GitHub Advanced Security.
name: origin89-security

on:
push:
branches: [main]
pull_request:
# New advisories arrive without a code change.
schedule:
- cron: "17 6 * * 1"

permissions:
contents: read

jobs:
dependency-review:
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0
with:
fail-on-severity: moderate
fail-on-scopes: runtime, development
# Checked only for dependencies the pull request adds. Unknown
# licenses are reported without failing.
allow-licenses: >-
0BSD, Apache-2.0, BlueOak-1.0.0, BSD-2-Clause, BSD-3-Clause,
CC-BY-4.0, CC0-1.0, ISC, MIT, MPL-2.0, Python-2.0, Unicode-3.0,
Unlicense, Zlib

zizmor:
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- uses: zizmorcore/zizmor-action@cc914d7f3750a2d13d75c7f184a1060aa0e9d482 # v0.6.4
with:
version: 1.30.1
advanced-security: false
annotations: true
min-severity: medium

cargo-deny:
runs-on: ubuntu-latest
timeout-minutes: 10
strategy:
fail-fast: false
matrix:
checks: [advisories, bans licenses sources]
# A new advisory should not block unrelated pull requests; the scheduled
# and default-branch runs still fail on it.
continue-on-error: ${{ github.event_name == 'pull_request' && matrix.checks == 'advisories' }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- uses: EmbarkStudios/cargo-deny-action@3c6349835b2b7b196a839186cb8b78e02f7b5f25 # v2.1.1
with:
command: check ${{ matrix.checks }}
41 changes: 41 additions & 0 deletions deny.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
# Copy to the Cargo workspace root; see engineering's docs/dependencies.md.
# Add a license or exception only after reading the crate's terms, and record why.

[advisories]
yanked = "deny"

[licenses]
# The shared list covers several repositories; unused entries are expected.
unused-allowed-license = "allow"
allow = [
"Apache-2.0",
"Apache-2.0 WITH LLVM-exception",
"BSD-2-Clause",
"BSD-3-Clause",
"ISC",
"MIT",
"Unicode-3.0",
"Zlib",
]

# UniFFI (mozilla/uniffi-rs) is MPL-2.0: file-level copyleft that applies to
# changes in its own files, which this repository uses unmodified.
exceptions = [
{ crate = "uniffi", allow = ["MPL-2.0"] },
{ crate = "uniffi_bindgen", allow = ["MPL-2.0"] },
{ crate = "uniffi_core", allow = ["MPL-2.0"] },
{ crate = "uniffi_internal_macros", allow = ["MPL-2.0"] },
{ crate = "uniffi_macros", allow = ["MPL-2.0"] },
{ crate = "uniffi_meta", allow = ["MPL-2.0"] },
{ crate = "uniffi_pipeline", allow = ["MPL-2.0"] },
{ crate = "uniffi_udl", allow = ["MPL-2.0"] },
]

[bans]
multiple-versions = "warn"
wildcards = "deny"
allow-wildcard-paths = true

[sources]
unknown-registry = "deny"
unknown-git = "deny"
Loading