ci: add Dependabot and security checks - #11
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 📝 WalkthroughWalkthroughDependabot now checks GitHub Actions and npm updates weekly, groups minor and patch updates, and applies a seven-day cooldown. The new Estimated code review effort: 2 (Simple) | ~10 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Comment |
There was a problem hiding this comment.
Note
Quiet mode is enabled, so only the most important comments were posted inline. Other review comments are grouped below.
🟡 Other comments (1)
.github/workflows/origin89-security.yml-27-27 (1)
27-27: 🔒 Security & Privacy | 🛡️ Detected with Advanced Tier | 🟡 Minor | ⚡ Quick winSecurity Misconfiguration
Reachability: External
CWE: CWE-693Include
unknowninfail-on-scopes.
unknownis a supported dependency scope. A moderate-or-higher vulnerability with that scope will not fail this check while the list contains onlyruntime, development.Update the scope list
- fail-on-scopes: runtime, development + fail-on-scopes: runtime, development, unknown
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: QUIET
Plan: Advanced
Run ID: 4dfcc30e-4fd8-4918-98be-d9f98d1598c7
📒 Files selected for processing (2)
.github/dependabot.yml.github/workflows/origin89-security.yml
Limit details: You’ve used all 10 included reviews currently available.
Change
Adopt the Dependabot and security baseline from origin89hq/engineering#28. Dependabot opens weekly PRs grouping minor and patch updates per ecosystem, with majors as separate PRs and a 7-day cooldown. It covers GitHub Actions at
/and/.github/actions/setup-node, and npm (pnpm) at/. Nothing auto-merges.origin89-securityruns dependency review on pull requests and a zizmor audit of the workflows on pull requests, pushes tomain, and a weekly schedule. There is no Cargo workspace, so the cargo-deny job is omitted.The seven-day cooldown is the minimum zizmor 1.30.1 accepts, so no cooldown ignore is needed; security updates are not delayed.
Validation
uvx zizmor@1.30.1 --offline --min-severity medium .github/: no findings. Without.github/zizmor.yml, thedependabot-cooldownaudit flags each 7-day cooldown as below its 7-day default.actionlint: clean on all workflows.dependabot.ymland the new workflow as YAML.origin89-securityruns on this PR. Dependabot reads its config from the default branch, so update PRs start after merge.