diff --git a/.github/workflows/GitGuardian.yml b/.github/workflows/GitGuardian.yml index c7293a5..b72684e 100644 --- a/.github/workflows/GitGuardian.yml +++ b/.github/workflows/GitGuardian.yml @@ -9,10 +9,22 @@ on: permissions: contents: read +# No concurrency group is defined on purpose. For push and workflow_dispatch +# runs alike, ggshield selects GITHUB_PUSH_BASE_SHA..GITHUB_SHA, falling back to +# GITHUB_DEFAULT_BRANCH..GITHUB_SHA when the push base is empty and then to +# GITHUB_SHA~1... when that range yields no commits. On the default branch that +# last fallback covers only the head commit, so a run is not guaranteed to +# re-cover an earlier run's commits. GitHub retains a single pending run per +# concurrency group, so a third rapid push would evict the second run even with +# cancel-in-progress: false. Runner time is traded for complete scan coverage. + jobs: scanning: name: GitGuardian Scan runs-on: ubuntu-latest + timeout-minutes: 20 + permissions: + contents: read steps: - name: Harden the runner (Audit all outbound calls) uses: step-security/harden-runner@95d9a5deda9de15063e7595e9719c11c38c90ae2 # v2.13.2 @@ -23,6 +35,7 @@ jobs: uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0 with: fetch-depth: 0 # fetch all history so multiple commits can be scanned + persist-credentials: false # scan-only job; no git write-back is performed - name: GitGuardian Scan uses: GitGuardian/ggshield/actions/secret@e4f45829b9b6f4664fe70d2a4dcd307a6833f422 # v1.43.0 env: diff --git a/.github/workflows/MegaLinter.yml b/.github/workflows/MegaLinter.yml index 3ecbcfc..ec153b4 100644 --- a/.github/workflows/MegaLinter.yml +++ b/.github/workflows/MegaLinter.yml @@ -26,6 +26,7 @@ jobs: megalinter: name: MegaLinter runs-on: ubuntu-latest + timeout-minutes: 45 permissions: contents: read @@ -44,6 +45,7 @@ jobs: with: # Pull requests need history for diff linting; main pushes validate all code. fetch-depth: ${{ github.event_name == 'pull_request' && '0' || '1' }} + persist-credentials: false # lint-only job; no git write-back is performed # MegaLinter - name: MegaLinter @@ -83,10 +85,13 @@ jobs: # Uncomment to disable copy-paste and spell checks # DISABLE: COPYPASTE,SPELL - DISABLE_ERRORS: true + # Quality gate policy: MegaLinter still reports every finding, but only the + # linters listed in ENABLE_ERRORS_LINTERS fail the build. ACTION_ACTIONLINT + # is enforced because the workflow files it covers are verified clean today. + # Remaining linters stay advisory until a clean baseline is established for + # them; see https://github.com/SamErde/PowerShell/issues/18. + ENABLE_ERRORS_LINTERS: ACTION_ACTIONLINT DISABLE_LINTERS: SPELL_LYCHEE - # Uncomment DISABLE_ERRORS_LINTERS if you want to turn errors back on selectively. - # DISABLE_ERRORS_LINTERS: REPOSITORY_DEVSKIM,REPOSITORY_KICS,REPOSITORY_CHECKOV,POWERSHELL_POWERSHELL,SPELL_CSPELL # Upload MegaLinter artifacts - name: Archive production artifacts diff --git a/.github/workflows/PSScriptAnalyzer.yml b/.github/workflows/PSScriptAnalyzer.yml index e6edd36..418af71 100644 --- a/.github/workflows/PSScriptAnalyzer.yml +++ b/.github/workflows/PSScriptAnalyzer.yml @@ -22,9 +22,9 @@ jobs: permissions: contents: read # for actions/checkout to fetch code security-events: write # for github/codeql-action/upload-sarif to upload SARIF results - actions: read # only required for a private repository by github/codeql-action/upload-sarif to get the Action run status name: 🕵️‍♂️ PSScriptAnalyzer runs-on: ubuntu-latest + timeout-minutes: 20 steps: - name: Harden the runner (Audit all outbound calls) uses: step-security/harden-runner@95d9a5deda9de15063e7595e9719c11c38c90ae2 # v2.13.2 @@ -32,6 +32,8 @@ jobs: egress-policy: audit - uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0 + with: + persist-credentials: false # analysis-only job; no git write-back is performed - name: 🕵️‍♂️ Run PSScriptAnalyzer uses: microsoft/psscriptanalyzer-action@6b2948b1944407914a58661c49941824d149734f