Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions .github/workflows/GitGuardian.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,10 +9,22 @@ on:
permissions:
contents: read

# No concurrency group is defined on purpose. For push and workflow_dispatch
# runs alike, ggshield selects GITHUB_PUSH_BASE_SHA..GITHUB_SHA, falling back to
# GITHUB_DEFAULT_BRANCH..GITHUB_SHA when the push base is empty and then to
# GITHUB_SHA~1... when that range yields no commits. On the default branch that
# last fallback covers only the head commit, so a run is not guaranteed to
# re-cover an earlier run's commits. GitHub retains a single pending run per
# concurrency group, so a third rapid push would evict the second run even with
# cancel-in-progress: false. Runner time is traded for complete scan coverage.

jobs:
scanning:
name: GitGuardian Scan
runs-on: ubuntu-latest
timeout-minutes: 20
permissions:
contents: read
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@95d9a5deda9de15063e7595e9719c11c38c90ae2 # v2.13.2
Expand All @@ -23,6 +35,7 @@ jobs:
uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
with:
fetch-depth: 0 # fetch all history so multiple commits can be scanned
persist-credentials: false # scan-only job; no git write-back is performed
- name: GitGuardian Scan
uses: GitGuardian/ggshield/actions/secret@e4f45829b9b6f4664fe70d2a4dcd307a6833f422 # v1.43.0
env:
Expand Down
11 changes: 8 additions & 3 deletions .github/workflows/MegaLinter.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,7 @@ jobs:
megalinter:
name: MegaLinter
runs-on: ubuntu-latest
timeout-minutes: 45

permissions:
contents: read
Expand All @@ -44,6 +45,7 @@ jobs:
with:
# Pull requests need history for diff linting; main pushes validate all code.
fetch-depth: ${{ github.event_name == 'pull_request' && '0' || '1' }}
persist-credentials: false # lint-only job; no git write-back is performed

# MegaLinter
- name: MegaLinter
Expand Down Expand Up @@ -83,10 +85,13 @@ jobs:

# Uncomment to disable copy-paste and spell checks
# DISABLE: COPYPASTE,SPELL
DISABLE_ERRORS: true
# Quality gate policy: MegaLinter still reports every finding, but only the
# linters listed in ENABLE_ERRORS_LINTERS fail the build. ACTION_ACTIONLINT
# is enforced because the workflow files it covers are verified clean today.
# Remaining linters stay advisory until a clean baseline is established for
# them; see https://github.com/SamErde/PowerShell/issues/18.
ENABLE_ERRORS_LINTERS: ACTION_ACTIONLINT
Comment thread
SamErde marked this conversation as resolved.
DISABLE_LINTERS: SPELL_LYCHEE
# Uncomment DISABLE_ERRORS_LINTERS if you want to turn errors back on selectively.
# DISABLE_ERRORS_LINTERS: REPOSITORY_DEVSKIM,REPOSITORY_KICS,REPOSITORY_CHECKOV,POWERSHELL_POWERSHELL,SPELL_CSPELL

# Upload MegaLinter artifacts
- name: Archive production artifacts
Expand Down
4 changes: 3 additions & 1 deletion .github/workflows/PSScriptAnalyzer.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,16 +22,18 @@ jobs:
permissions:
contents: read # for actions/checkout to fetch code
security-events: write # for github/codeql-action/upload-sarif to upload SARIF results
actions: read # only required for a private repository by github/codeql-action/upload-sarif to get the Action run status
name: 🕵️‍♂️ PSScriptAnalyzer
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@95d9a5deda9de15063e7595e9719c11c38c90ae2 # v2.13.2
with:
egress-policy: audit

- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
with:
persist-credentials: false # analysis-only job; no git write-back is performed

- name: 🕵️‍♂️ Run PSScriptAnalyzer
uses: microsoft/psscriptanalyzer-action@6b2948b1944407914a58661c49941824d149734f
Expand Down
Loading