From 627d81157d39b79c9632e53e5152b5e76bb2d2ea Mon Sep 17 00:00:00 2001 From: David Berenstein Date: Thu, 24 Sep 2026 21:01:54 +0900 Subject: [PATCH 01/10] ci: add default status check and Dependabot config --- .github/dependabot.yml | 12 ++++++++++++ .github/workflows/default.yml | 25 +++++++++++++++++++++++++ 2 files changed, 37 insertions(+) create mode 100644 .github/dependabot.yml create mode 100644 .github/workflows/default.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..8796223 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,12 @@ +version: 2 +updates: + - package-ecosystem: github-actions + directories: + - "/" + schedule: + interval: weekly + groups: + minor-and-patch: + patterns: ["*"] + update-types: [minor, patch] + open-pull-requests-limit: 5 diff --git a/.github/workflows/default.yml b/.github/workflows/default.yml new file mode 100644 index 0000000..12b1f17 --- /dev/null +++ b/.github/workflows/default.yml @@ -0,0 +1,25 @@ +name: default + +on: + pull_request: + push: + branches: [main] + +permissions: + contents: read + +jobs: + default: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - name: Validate YAML files + run: | + python3 -c " + import glob, sys, yaml + files = glob.glob('**/*.yml', recursive=True) + glob.glob('**/*.yaml', recursive=True) + for f in files: + with open(f) as fh: + yaml.safe_load(fh) + print(f'ok: {f}') + " From 565d6bc3e5f80c6034e4ae1d8cf8f6ef01bbbc99 Mon Sep 17 00:00:00 2001 From: David Berenstein Date: Thu, 24 Sep 2026 21:07:21 +0900 Subject: [PATCH 02/10] ci: pin actions in default workflow to commit SHAs --- .github/workflows/default.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/default.yml b/.github/workflows/default.yml index 12b1f17..997eb60 100644 --- a/.github/workflows/default.yml +++ b/.github/workflows/default.yml @@ -12,7 +12,7 @@ jobs: default: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: Validate YAML files run: | python3 -c " From a993c4a2d3d7f4ce96c553f80143b0807dc2951d Mon Sep 17 00:00:00 2001 From: David Berenstein Date: Fri, 25 Sep 2026 11:04:08 +0900 Subject: [PATCH 03/10] ci: raise the Dependabot open pull request limit to 50 --- .github/dependabot.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 8796223..ec7ec46 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -9,4 +9,4 @@ updates: minor-and-patch: patterns: ["*"] update-types: [minor, patch] - open-pull-requests-limit: 5 + open-pull-requests-limit: 50 From 99699429d9bfb0849731a91972662178319b5bed Mon Sep 17 00:00:00 2001 From: David Berenstein Date: Fri, 25 Sep 2026 11:08:53 +0900 Subject: [PATCH 04/10] ci: effectively remove the Dependabot open pull request limit --- .github/dependabot.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index ec7ec46..f49b0ee 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -9,4 +9,4 @@ updates: minor-and-patch: patterns: ["*"] update-types: [minor, patch] - open-pull-requests-limit: 50 + open-pull-requests-limit: 1000 From 2c7d00213b715226cac274394cf69a9a38a6d057 Mon Sep 17 00:00:00 2001 From: David Berenstein Date: Fri, 25 Sep 2026 17:59:00 +0900 Subject: [PATCH 05/10] ci: add a Semgrep job for findings a pull request adds Runs p/default and p/trailofbits at ERROR severity with --baseline-commit set to the pull request base, so existing findings do not fail it. The image and checkout are pinned by digest and SHA. --- .github/workflows/default.yml | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/.github/workflows/default.yml b/.github/workflows/default.yml index 997eb60..5d4ecc9 100644 --- a/.github/workflows/default.yml +++ b/.github/workflows/default.yml @@ -23,3 +23,17 @@ jobs: yaml.safe_load(fh) print(f'ok: {f}') " + + semgrep: + if: github.event_name == 'pull_request' + runs-on: ubuntu-latest + container: semgrep/semgrep:1.178.0@sha256:32e459968daabe7ab86968184a29109b9564aa00392401156f9788452b42786b + steps: + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + with: + fetch-depth: 0 + - name: Semgrep (only findings this pull request adds) + run: | + git config --global --add safe.directory "$GITHUB_WORKSPACE" + semgrep scan --config p/trailofbits --config p/default --severity ERROR --error --metrics off \ + --baseline-commit "${{ github.event.pull_request.base.sha }}" From f11890763c3cab87e29800b6e73f51837a2fc3b4 Mon Sep 17 00:00:00 2001 From: David Berenstein Date: Mon, 28 Sep 2026 10:52:01 +0900 Subject: [PATCH 06/10] ci: validate YAML with yq over git ls-files Python's recursive glob skips hidden folders, so .github/ was never checked. git ls-files includes them, and yq ships on ubuntu-latest. --- .github/workflows/default.yml | 10 +--------- 1 file changed, 1 insertion(+), 9 deletions(-) diff --git a/.github/workflows/default.yml b/.github/workflows/default.yml index 5d4ecc9..432b4e7 100644 --- a/.github/workflows/default.yml +++ b/.github/workflows/default.yml @@ -14,15 +14,7 @@ jobs: steps: - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: Validate YAML files - run: | - python3 -c " - import glob, sys, yaml - files = glob.glob('**/*.yml', recursive=True) + glob.glob('**/*.yaml', recursive=True) - for f in files: - with open(f) as fh: - yaml.safe_load(fh) - print(f'ok: {f}') - " + run: git ls-files -z '*.yml' '*.yaml' | xargs -0 -n1 yq e '.' > /dev/null semgrep: if: github.event_name == 'pull_request' From a90a69be9c70259232accdfaacb73e3763031308 Mon Sep 17 00:00:00 2001 From: David Berenstein Date: Mon, 28 Sep 2026 12:50:40 +0900 Subject: [PATCH 07/10] ci: add a 7-day Dependabot cooldown and track the Semgrep image Every ecosystem waits 7 days before proposing a new release. The Semgrep job uses the container image: form, and a docker entry for /.github/workflows lets Dependabot bump its tag and digest. Also removes the root dependabot.yaml, which Dependabot never reads; .github/dependabot.yml is the config. --- .github/dependabot.yml | 9 +++++++++ .github/workflows/default.yml | 3 ++- dependabot.yaml | 12 ------------ 3 files changed, 11 insertions(+), 13 deletions(-) delete mode 100644 dependabot.yaml diff --git a/.github/dependabot.yml b/.github/dependabot.yml index f49b0ee..e26d8b6 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,6 +1,8 @@ version: 2 updates: - package-ecosystem: github-actions + cooldown: + default-days: 7 directories: - "/" schedule: @@ -10,3 +12,10 @@ updates: patterns: ["*"] update-types: [minor, patch] open-pull-requests-limit: 1000 + - package-ecosystem: docker + directories: + - "/.github/workflows" + schedule: + interval: weekly + cooldown: + default-days: 7 diff --git a/.github/workflows/default.yml b/.github/workflows/default.yml index 432b4e7..968a345 100644 --- a/.github/workflows/default.yml +++ b/.github/workflows/default.yml @@ -19,7 +19,8 @@ jobs: semgrep: if: github.event_name == 'pull_request' runs-on: ubuntu-latest - container: semgrep/semgrep:1.178.0@sha256:32e459968daabe7ab86968184a29109b9564aa00392401156f9788452b42786b + container: + image: semgrep/semgrep:1.178.0@sha256:32e459968daabe7ab86968184a29109b9564aa00392401156f9788452b42786b steps: - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: diff --git a/dependabot.yaml b/dependabot.yaml deleted file mode 100644 index ec85b2e..0000000 --- a/dependabot.yaml +++ /dev/null @@ -1,12 +0,0 @@ -version: 2 - -updates: - - package-ecosystem: "github-actions" - directory: "/" - schedule: - interval: "weekly" - - - package-ecosystem: "pip" - directory: "/" - schedule: - interval: "weekly" From a9f4a6d6418769147d3042dc5ed067db27a0d420 Mon Sep 17 00:00:00 2001 From: David Berenstein Date: Mon, 28 Sep 2026 20:22:28 +0900 Subject: [PATCH 08/10] ci: turn the default workflow into the org Semgrep workflow --- .github/workflows/{default.yml => semgrep.yml} | 12 +----------- 1 file changed, 1 insertion(+), 11 deletions(-) rename .github/workflows/{default.yml => semgrep.yml} (67%) diff --git a/.github/workflows/default.yml b/.github/workflows/semgrep.yml similarity index 67% rename from .github/workflows/default.yml rename to .github/workflows/semgrep.yml index 968a345..6eac129 100644 --- a/.github/workflows/default.yml +++ b/.github/workflows/semgrep.yml @@ -1,23 +1,13 @@ -name: default +name: semgrep on: pull_request: - push: - branches: [main] permissions: contents: read jobs: - default: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - - name: Validate YAML files - run: git ls-files -z '*.yml' '*.yaml' | xargs -0 -n1 yq e '.' > /dev/null - semgrep: - if: github.event_name == 'pull_request' runs-on: ubuntu-latest container: image: semgrep/semgrep:1.178.0@sha256:32e459968daabe7ab86968184a29109b9564aa00392401156f9788452b42786b From 5a8411c910aea7404439710f5957d298f11c6d1c Mon Sep 17 00:00:00 2001 From: David Berenstein Date: Mon, 28 Sep 2026 22:57:45 +0900 Subject: [PATCH 09/10] ci: harden workflows and cap Dependabot pull requests --- .github/CODEOWNERS | 2 ++ .github/dependabot.yml | 2 +- 2 files changed, 3 insertions(+), 1 deletion(-) create mode 100644 .github/CODEOWNERS diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 0000000..a7355a9 --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1,2 @@ +/.github/workflows/semgrep.yml @PrunaAI/safety +/.github/CODEOWNERS @PrunaAI/safety diff --git a/.github/dependabot.yml b/.github/dependabot.yml index e26d8b6..cbaec02 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -11,7 +11,7 @@ updates: minor-and-patch: patterns: ["*"] update-types: [minor, patch] - open-pull-requests-limit: 1000 + open-pull-requests-limit: 50 - package-ecosystem: docker directories: - "/.github/workflows" From 3e1db992b7f333bb09aa2eee4bbe684eb66629b8 Mon Sep 17 00:00:00 2001 From: David Berenstein Date: Wed, 30 Sep 2026 11:45:46 +0900 Subject: [PATCH 10/10] ci: use the default Dependabot open pull request limit Drop open-pull-requests-limit: 50 so each entry falls back to the default of 5. The weekly schedule and grouping stay the same, and security updates are not subject to the limit. --- .github/dependabot.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index cbaec02..988b02a 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -11,7 +11,6 @@ updates: minor-and-patch: patterns: ["*"] update-types: [minor, patch] - open-pull-requests-limit: 50 - package-ecosystem: docker directories: - "/.github/workflows"