ci: add the org Semgrep workflow, CODEOWNERS and Dependabot config - #1
Open
davidberenstein1957 wants to merge 9 commits into
Open
davidberenstein1957 wants to merge 9 commits into
davidberenstein1957 wants to merge 9 commits into
Conversation
Runs p/default and p/trailofbits at ERROR severity with --baseline-commit set to the pull request base, so existing findings do not fail it. The image and checkout are pinned by digest and SHA.
Python's recursive glob skips hidden folders, so .github/ was never checked. git ls-files includes them, and yq ships on ubuntu-latest.
Every ecosystem waits 7 days before proposing a new release. The Semgrep job uses the container image: form, and a docker entry for /.github/workflows lets Dependabot bump its tag and digest. Also removes the root dependabot.yaml, which Dependabot never reads; .github/dependabot.yml is the config.
This was referenced Sep 28, 2026
davidberenstein1957
force-pushed
the
ci/default-check-and-dependabot
branch
from
September 29, 2026 10:35
eb1eb4f to
5a8411c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
This PR adds
.github/workflows/semgrep.yml, the Semgrep workflow that an org ruleset will require on every repository's default branch, and a Dependabot config for this repository.semgrep.ymlp/defaultandp/trailofbitsat ERROR severity with--baseline-commitset to the pull request base, so it only fails on findings the pull request adds. The image is pinned by digest and the job needs noSEMGREP_APP_TOKEN. It triggers onpull_requestonly, because ruleset workflows ignore other events.Every action in
semgrep.ymlis pinned to a full commit SHA, with the version in a trailing comment. Dependabot'sgithub-actionsupdates keep the SHA and the comment current.Dependabot
.github/dependabot.ymluses directory globs where several folders share an ecosystem, so new folders are covered without a config change. It runs weekly, groups minor and patch updates into one PR per ecosystem, and caps open pull requests at 50. Dependabot PRs get no Actions secrets./Notes
dependabot.yamlis outside.github/, so GitHub ignores it. It can be deleted in a separate change.Hardening
.github/CODEOWNERSassignssemgrep.ymland the CODEOWNERS file itself to@PrunaAI/safety, because every repository's merges depend on that workflow. It is enforced once this repository's ruleset requires code owner review.Before merging
Remove the required
defaultcheck from this repository's ruleset, then merge this PR before the others. After that, create the org ruleset with the rule "Require workflows to pass before merging" pointing atPrunaAI/.github,.github/workflows/semgrep.yml, refmain. The org and repo rule changes are tracked in PrunaAI/prunatree#639.Testing
dependabot.ymlvalidated withcheck-jsonschema --builtin-schema vendor.dependabot.semgrep.ymlchecked withactionlint.Commits