Skip to content

ci: add the org Semgrep workflow, CODEOWNERS and Dependabot config - #1

Open
davidberenstein1957 wants to merge 9 commits into
mainfrom
ci/default-check-and-dependabot
Open

davidberenstein1957 wants to merge 9 commits into
mainfrom
ci/default-check-and-dependabot

Conversation

@davidberenstein1957

@davidberenstein1957 davidberenstein1957 commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

What and why

This PR adds .github/workflows/semgrep.yml, the Semgrep workflow that an org ruleset will require on every repository's default branch, and a Dependabot config for this repository.

semgrep.yml

p/default and p/trailofbits at ERROR severity with --baseline-commit set to the pull request base, so it only fails on findings the pull request adds. The image is pinned by digest and the job needs no SEMGREP_APP_TOKEN. It triggers on pull_request only, because ruleset workflows ignore other events.

Every action in semgrep.yml is pinned to a full commit SHA, with the version in a trailing comment. Dependabot's github-actions updates keep the SHA and the comment current.

Dependabot

.github/dependabot.yml uses directory globs where several folders share an ecosystem, so new folders are covered without a config change. It runs weekly, groups minor and patch updates into one PR per ecosystem, and caps open pull requests at 50. Dependabot PRs get no Actions secrets.

  • github-actions: /

Notes

  • The root-level dependabot.yaml is outside .github/, so GitHub ignores it. It can be deleted in a separate change.

Hardening

  • .github/CODEOWNERS assigns semgrep.yml and the CODEOWNERS file itself to @PrunaAI/safety, because every repository's merges depend on that workflow. It is enforced once this repository's ruleset requires code owner review.

Before merging

Remove the required default check from this repository's ruleset, then merge this PR before the others. After that, create the org ruleset with the rule "Require workflows to pass before merging" pointing at PrunaAI/.github, .github/workflows/semgrep.yml, ref main. The org and repo rule changes are tracked in PrunaAI/prunatree#639.

Testing

  • dependabot.yml validated with check-jsonschema --builtin-schema vendor.dependabot.
  • semgrep.yml checked with actionlint.

Commits

  • 503cccc ci: add default status check and Dependabot config
  • 0529242 ci: pin actions in default workflow to commit SHAs
  • 7b04e0a ci: raise the Dependabot open pull request limit to 50
  • dc7a3aa ci: effectively remove the Dependabot open pull request limit
  • 3652b7e ci: add a Semgrep job for findings a pull request adds
  • 3d9af74 ci: turn the default workflow into the org Semgrep workflow
  • eb1eb4f ci: harden workflows and cap Dependabot pull requests

Python's recursive glob skips hidden folders, so .github/ was never
checked. git ls-files includes them, and yq ships on ubuntu-latest.
Every ecosystem waits 7 days before proposing a new release. The Semgrep
job uses the container image: form, and a docker entry for
/.github/workflows lets Dependabot bump its tag and digest.

Also removes the root dependabot.yaml, which Dependabot never reads;
.github/dependabot.yml is the config.
@davidberenstein1957 davidberenstein1957 changed the title ci: add default status check and Dependabot config ci: add the org Semgrep workflow, CODEOWNERS and Dependabot config Sep 28, 2026
@davidberenstein1957
davidberenstein1957 force-pushed the ci/default-check-and-dependabot branch from eb1eb4f to 5a8411c Compare September 29, 2026 10:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant