diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 0000000..a7355a9 --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1,2 @@ +/.github/workflows/semgrep.yml @PrunaAI/safety +/.github/CODEOWNERS @PrunaAI/safety diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..988b02a --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,20 @@ +version: 2 +updates: + - package-ecosystem: github-actions + cooldown: + default-days: 7 + directories: + - "/" + schedule: + interval: weekly + groups: + minor-and-patch: + patterns: ["*"] + update-types: [minor, patch] + - package-ecosystem: docker + directories: + - "/.github/workflows" + schedule: + interval: weekly + cooldown: + default-days: 7 diff --git a/.github/workflows/semgrep.yml b/.github/workflows/semgrep.yml new file mode 100644 index 0000000..6eac129 --- /dev/null +++ b/.github/workflows/semgrep.yml @@ -0,0 +1,22 @@ +name: semgrep + +on: + pull_request: + +permissions: + contents: read + +jobs: + semgrep: + runs-on: ubuntu-latest + container: + image: semgrep/semgrep:1.178.0@sha256:32e459968daabe7ab86968184a29109b9564aa00392401156f9788452b42786b + steps: + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + with: + fetch-depth: 0 + - name: Semgrep (only findings this pull request adds) + run: | + git config --global --add safe.directory "$GITHUB_WORKSPACE" + semgrep scan --config p/trailofbits --config p/default --severity ERROR --error --metrics off \ + --baseline-commit "${{ github.event.pull_request.base.sha }}" diff --git a/dependabot.yaml b/dependabot.yaml deleted file mode 100644 index ec85b2e..0000000 --- a/dependabot.yaml +++ /dev/null @@ -1,12 +0,0 @@ -version: 2 - -updates: - - package-ecosystem: "github-actions" - directory: "/" - schedule: - interval: "weekly" - - - package-ecosystem: "pip" - directory: "/" - schedule: - interval: "weekly"