Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
65 changes: 61 additions & 4 deletions .github/workflows/private-security-bundle-free.yml
Original file line number Diff line number Diff line change
Expand Up @@ -87,11 +87,65 @@ jobs:
printf 'PRIVATE_SECURITY_BUNDLE_SCRIPT=%s\n' \
"$source_root/scripts/run_private_security_bundle.sh" >> "$GITHUB_ENV"

- name: Set up pinned uv
uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0
- name: Detect baked uv
id: baked-uv
shell: bash
run: |
set -euo pipefail
available=false
if command -v uv >/dev/null 2>&1 && [[ "$(uv --version)" == "uv 0.11.30"* ]]; then
available=true
fi
printf 'available=%s\n' "$available" >> "$GITHUB_OUTPUT"

- name: Restore pinned uv archive
if: ${{ steps.baked-uv.outputs.available != 'true' }}
id: uv-archive
uses: NDDev-OpenNetwork/github-actions/actions/tool-cache@bcacca8a41c5b8117716fcbeb0006ab83fd0d0f5 # v1.0.0
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
with:
url: https://github.com/astral-sh/uv/releases/download/0.11.30/uv-x86_64-unknown-linux-gnu.tar.gz
sha256: 04bc7d180d6138bf6dc08387acf507a823f397a98fea55da36b0ccc7fbce3b68
output: ${{ runner.temp }}/private-security-tools/uv.tar.gz
max-bytes: '67108864'

- name: Install pinned uv fallback
if: ${{ steps.baked-uv.outputs.available != 'true' }}
shell: bash
run: |
set -euo pipefail
install -d -m 0700 "$RUNNER_TEMP/private-security-tools/uv"
tar --extract --gzip --file "$RUNNER_TEMP/private-security-tools/uv.tar.gz" \
--directory "$RUNNER_TEMP/private-security-tools/uv"
install -d -m 0700 "$RUNNER_TEMP/private-security-tools/bin"
install -m 0755 "$RUNNER_TEMP/private-security-tools/uv/uv-x86_64-unknown-linux-gnu/uv" \
"$RUNNER_TEMP/private-security-tools/bin/uv"
install -m 0755 "$RUNNER_TEMP/private-security-tools/uv/uv-x86_64-unknown-linux-gnu/uvx" \
"$RUNNER_TEMP/private-security-tools/bin/uvx"
printf '%s\n' "$RUNNER_TEMP/private-security-tools/bin" >> "$GITHUB_PATH"

- name: Restore actionlint archive
uses: NDDev-OpenNetwork/github-actions/actions/tool-cache@bcacca8a41c5b8117716fcbeb0006ab83fd0d0f5 # v1.0.0
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
with:
url: https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_amd64.tar.gz
sha256: 8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8
output: ${{ runner.temp }}/private-security-tools/actionlint.tar.gz
max-bytes: '16777216'

- name: Restore OSV-Scanner binary
uses: NDDev-OpenNetwork/github-actions/actions/tool-cache@bcacca8a41c5b8117716fcbeb0006ab83fd0d0f5 # v1.0.0
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
with:
url: https://github.com/google/osv-scanner/releases/download/v2.5.0/osv-scanner_linux_amd64
sha256: edcfc41d257db36148f065055655fe3fcfc434b0b423ea67468a84c207524e0c
output: ${{ runner.temp }}/private-security-tools/osv-scanner
max-bytes: '268435456'

- name: Restore gitleaks archive
uses: NDDev-OpenNetwork/github-actions/actions/tool-cache@bcacca8a41c5b8117716fcbeb0006ab83fd0d0f5 # v1.0.0
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
with:
version: 0.11.30
enable-cache: false
url: https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_linux_x64.tar.gz
sha256: 551f6fc83ea457d62a0d98237cbad105af8d557003051f41f3e7ca7b3f2470eb
output: ${{ runner.temp }}/private-security-tools/gitleaks.tar.gz
max-bytes: '16777216'

- name: Run consolidated security gates without SARIF upload
shell: bash
Expand All @@ -105,6 +159,9 @@ jobs:
OSV_SARIF_PATH: ${{ runner.temp }}/private-security-osv.sarif
GITLEAKS_SARIF_PATH: ${{ runner.temp }}/private-security-gitleaks.sarif
ACTIONLINT_LOG_PATH: ${{ runner.temp }}/private-security-actionlint.log
ACTIONLINT_ARCHIVE_PATH: ${{ runner.temp }}/private-security-tools/actionlint.tar.gz
OSV_SCANNER_PATH: ${{ runner.temp }}/private-security-tools/osv-scanner
GITLEAKS_ARCHIVE_PATH: ${{ runner.temp }}/private-security-tools/gitleaks.tar.gz
run: "$PRIVATE_SECURITY_BUNDLE_SCRIPT"

- name: Upload redacted security evidence
Expand Down
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,10 @@ The project follows Semantic Versioning.

### Changed

- Routed the consolidated private security bundle's pinned uv, actionlint,
OSV-Scanner and gitleaks artifacts through the public immutable tool-cache
action. Baked uv is reused without setup; GitHub-hosted and cache-miss jobs
retain the same checksum-verified upstream fallback.
- Strengthened the consolidated private-free security bundle without adding a
placement: actionlint logs plus Zizmor, OSV and fully redacted Gitleaks SARIF
are always retained as a one-day artifact, including on aggregate failure.
Expand Down
9 changes: 9 additions & 0 deletions catalog/cache-contract.yml
Original file line number Diff line number Diff line change
Expand Up @@ -75,6 +75,15 @@ producers:
upstream_default: null
default_caches: true
note: A cache action by construction; callers opt in by adding the step.
- action: NDDev-OpenNetwork/github-actions/actions/tool-cache
control: null
upstream_default: null
default_caches: false
note: >-
Cache use is conditional on a complete per-job Drakkars assignment.
GitHub-hosted runners and malformed or unavailable assignments use the
checksum-verified upstream path; private writes remain inside the
caller's injected trust prefix.

# Where a cache must be refused, and why. Each rule names the exact input and
# value the workflow has to carry; the check fails if the step is missing it.
Expand Down
16 changes: 15 additions & 1 deletion catalog/tools.yml
Original file line number Diff line number Diff line change
Expand Up @@ -506,7 +506,6 @@ tools:
- .github/workflows/ci.yml
- .github/workflows/maintenance.yml
- .github/workflows/nddev-security-bundle.yml
- .github/workflows/private-security-bundle-free.yml
- .github/workflows/private-static.yml
- .github/workflows/python-ci.yml
- .github/workflows/qt-ci.yml
Expand All @@ -518,6 +517,21 @@ tools:
- .github/workflows/zizmor-sarif.yml
last_verified: "2026-07-20"

- id: nddev-tool-cache
name: NDDev-OpenNetwork/github-actions/actions/tool-cache
homepage: "https://github.com/NDDev-OpenNetwork/github-actions/tree/main/actions/tool-cache"
kind: action
current_version: "v1.0.0"
pin: "NDDev-OpenNetwork/github-actions@bcacca8a41c5b8117716fcbeb0006ab83fd0d0f5"
used_by:
- .github/workflows/private-security-bundle-free.yml
last_verified: "2026-08-23"
notes: >-
Signed tag v1.0.0 resolves to the exact pinned repository commit.
Checksum-addressed immutable tool artifacts use the caller's injected
trust-scoped RustFS identity on private runners and the same verified
upstream fallback on GitHub-hosted runners.

- id: setup-bun
name: oven-sh/setup-bun
homepage: "https://github.com/oven-sh/setup-bun"
Expand Down
16 changes: 13 additions & 3 deletions scripts/run_private_security_bundle.sh
Original file line number Diff line number Diff line change
Expand Up @@ -45,18 +45,28 @@ trap cleanup EXIT
install -d -m 0700 "$tool_root/bin"
export PATH="$tool_root/bin:$PATH"

curl -fsSL --retry 5 --retry-max-time 120 -o "$tool_root/actionlint.tar.gz" \
use_or_download() {
local supplied=$1 output=$2 url=$3
if [[ -n "$supplied" ]]; then
[[ "$supplied" == "$RUNNER_TEMP"/* && -f "$supplied" && ! -L "$supplied" ]]
install -m 0600 "$supplied" "$output"
return
fi
curl -fsSL --retry 5 --retry-max-time 120 -o "$output" "$url"
}

use_or_download "${ACTIONLINT_ARCHIVE_PATH:-}" "$tool_root/actionlint.tar.gz" \
"https://github.com/rhysd/actionlint/releases/download/v${actionlint_version}/actionlint_${actionlint_version}_linux_amd64.tar.gz"
printf '%s %s\n' "$actionlint_sha256" "$tool_root/actionlint.tar.gz" | sha256sum -c -
tar -xzf "$tool_root/actionlint.tar.gz" -C "$tool_root/bin" actionlint
chmod 0700 "$tool_root/bin/actionlint"

curl -fsSL --retry 5 --retry-max-time 120 -o "$tool_root/osv-scanner" \
use_or_download "${OSV_SCANNER_PATH:-}" "$tool_root/osv-scanner" \
"https://github.com/google/osv-scanner/releases/download/v${osv_version}/osv-scanner_linux_amd64"
printf '%s %s\n' "$osv_sha256" "$tool_root/osv-scanner" | sha256sum -c -
install -m 0700 "$tool_root/osv-scanner" "$tool_root/bin/osv-scanner"

curl -fsSL --retry 5 --retry-max-time 120 -o "$tool_root/gitleaks.tar.gz" \
use_or_download "${GITLEAKS_ARCHIVE_PATH:-}" "$tool_root/gitleaks.tar.gz" \
"https://github.com/gitleaks/gitleaks/releases/download/v${gitleaks_version}/gitleaks_${gitleaks_version}_linux_x64.tar.gz"
test "$(wc -c < "$tool_root/gitleaks.tar.gz" | tr -d '[:space:]')" = "$gitleaks_size"
printf '%s %s\n' "$gitleaks_sha256" "$tool_root/gitleaks.tar.gz" | sha256sum -c -
Expand Down
Loading