diff --git a/.github/actions/setup-duckdb/action.yml b/.github/actions/setup-duckdb/action.yml index a2c26a366..2d6b30479 100644 --- a/.github/actions/setup-duckdb/action.yml +++ b/.github/actions/setup-duckdb/action.yml @@ -4,7 +4,7 @@ runs: using: composite steps: - shell: bash - run: | + run: | # zizmor: ignore[github-env] appends a fixed RUNNER_TEMP path holding the checksum-verified CLI set -euo pipefail archive="$RUNNER_TEMP/duckdb-cli.zip" install_dir="$RUNNER_TEMP/duckdb-cli" diff --git a/.github/actions/setup/action.yml b/.github/actions/setup/action.yml index 912f696d7..3d58503b9 100644 --- a/.github/actions/setup/action.yml +++ b/.github/actions/setup/action.yml @@ -7,7 +7,7 @@ runs: with: node-version: 24 package-manager-cache: false - - uses: pnpm/action-setup@f520eceda224fe1a4aed5a2a27a194379a409996 # v6 + - uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 # v6 with: run_install: false cache: true diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 000000000..a1146f5b1 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,36 @@ +# See origin89hq/engineering docs/dependencies.md. +version: 2 + +updates: + # Composite actions are not scanned from the root directory. + - package-ecosystem: github-actions + directories: + - / + - /.github/actions/setup + - /.github/actions/setup-duckdb + schedule: + interval: weekly + cooldown: + default-days: 7 + groups: + actions: + patterns: ["*"] + update-types: [minor, patch] + commit-message: + prefix: ci + + # pnpm workspaces use the npm ecosystem from the directory holding the lockfile. + - package-ecosystem: npm + directory: / + schedule: + interval: weekly + # At least pnpm's minimumReleaseAge, or the frozen install rejects the update. + cooldown: + default-days: 7 + groups: + npm: + patterns: ["*"] + update-types: [minor, patch] + commit-message: + prefix: chore + include: scope diff --git a/.github/workflows/origin89-security.yml b/.github/workflows/origin89-security.yml new file mode 100644 index 000000000..408bd69a3 --- /dev/null +++ b/.github/workflows/origin89-security.yml @@ -0,0 +1,47 @@ +# See origin89hq/engineering docs/dependencies.md. +name: origin89-security + +on: + push: + branches: [main] + pull_request: + # New advisories arrive without a code change. + schedule: + - cron: "17 6 * * 1" + +permissions: + contents: read + +jobs: + dependency-review: + if: github.event_name == 'pull_request' + runs-on: ubuntu-latest + timeout-minutes: 5 + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + with: + persist-credentials: false + - uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0 + with: + fail-on-severity: moderate + fail-on-scopes: runtime, development + # Checked only for dependencies the pull request adds. Unknown + # licenses are reported without failing. + allow-licenses: >- + 0BSD, Apache-2.0, BlueOak-1.0.0, BSD-2-Clause, BSD-3-Clause, + CC-BY-4.0, CC0-1.0, ISC, MIT, MPL-2.0, Python-2.0, Unicode-3.0, + Unlicense, Zlib + + zizmor: + runs-on: ubuntu-latest + timeout-minutes: 5 + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + with: + persist-credentials: false + - uses: zizmorcore/zizmor-action@cc914d7f3750a2d13d75c7f184a1060aa0e9d482 # v0.6.4 + with: + version: 1.30.1 + advanced-security: false + annotations: true + min-severity: medium diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 67d2f7a8d..3955c8773 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -9,7 +9,7 @@ name: Publish the dataset # much again when it is retired. That is about $2.50 a version, and four merges that touched # records in a day were four of them for one day's figures. A day's merges now go out together. # `workflow_dispatch` publishes at once when something should not wait. -on: +on: # zizmor: ignore[dangerous-triggers] reviewed: only the manual main-branch deploy triggers it, and it checks out main, not the run's head schedule: # Eleven hours after the daily pull opens its pull request, so a day's records go out the # evening they are merged.