Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
65 changes: 61 additions & 4 deletions .github/workflows/private-security-bundle-free.yml
Original file line number Diff line number Diff line change
Expand Up @@ -87,11 +87,65 @@
printf 'PRIVATE_SECURITY_BUNDLE_SCRIPT=%s\n' \
"$source_root/scripts/run_private_security_bundle.sh" >> "$GITHUB_ENV"

- name: Set up pinned uv
uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0
- name: Detect baked uv
id: baked-uv
shell: bash
run: |
set -euo pipefail
available=false
if command -v uv >/dev/null 2>&1 && [[ "$(uv --version)" == "uv 0.11.30"* ]]; then
available=true
fi
printf 'available=%s\n' "$available" >> "$GITHUB_OUTPUT"

- name: Restore pinned uv archive
if: ${{ steps.baked-uv.outputs.available != 'true' }}
id: uv-archive
uses: NDDev-OpenNetwork/github-actions/actions/tool-cache@bcacca8a41c5b8117716fcbeb0006ab83fd0d0f5
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
with:
url: https://github.com/astral-sh/uv/releases/download/0.11.30/uv-x86_64-unknown-linux-gnu.tar.gz
sha256: 04bc7d180d6138bf6dc08387acf507a823f397a98fea55da36b0ccc7fbce3b68
output: ${{ runner.temp }}/private-security-tools/uv.tar.gz
max-bytes: '67108864'

- name: Install pinned uv fallback
if: ${{ steps.baked-uv.outputs.available != 'true' }}
shell: bash
run: |
set -euo pipefail
install -d -m 0700 "$RUNNER_TEMP/private-security-tools/uv"
tar --extract --gzip --file "$RUNNER_TEMP/private-security-tools/uv.tar.gz" \
--directory "$RUNNER_TEMP/private-security-tools/uv"
install -d -m 0700 "$RUNNER_TEMP/private-security-tools/bin"
install -m 0755 "$RUNNER_TEMP/private-security-tools/uv/uv-x86_64-unknown-linux-gnu/uv" \
"$RUNNER_TEMP/private-security-tools/bin/uv"
install -m 0755 "$RUNNER_TEMP/private-security-tools/uv/uv-x86_64-unknown-linux-gnu/uvx" \
"$RUNNER_TEMP/private-security-tools/bin/uvx"
printf '%s\n' "$RUNNER_TEMP/private-security-tools/bin" >> "$GITHUB_PATH"

- name: Restore actionlint archive
uses: NDDev-OpenNetwork/github-actions/actions/tool-cache@bcacca8a41c5b8117716fcbeb0006ab83fd0d0f5
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
with:
url: https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_amd64.tar.gz
sha256: 8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8
output: ${{ runner.temp }}/private-security-tools/actionlint.tar.gz
max-bytes: '16777216'

- name: Restore OSV-Scanner binary
uses: NDDev-OpenNetwork/github-actions/actions/tool-cache@bcacca8a41c5b8117716fcbeb0006ab83fd0d0f5
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
with:
url: https://github.com/google/osv-scanner/releases/download/v2.5.0/osv-scanner_linux_amd64
sha256: edcfc41d257db36148f065055655fe3fcfc434b0b423ea67468a84c207524e0c
output: ${{ runner.temp }}/private-security-tools/osv-scanner
max-bytes: '268435456'

- name: Restore gitleaks archive
uses: NDDev-OpenNetwork/github-actions/actions/tool-cache@bcacca8a41c5b8117716fcbeb0006ab83fd0d0f5
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
with:
version: 0.11.30
enable-cache: false
url: https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_linux_x64.tar.gz
sha256: 551f6fc83ea457d62a0d98237cbad105af8d557003051f41f3e7ca7b3f2470eb
output: ${{ runner.temp }}/private-security-tools/gitleaks.tar.gz
max-bytes: '16777216'

- name: Run consolidated security gates without SARIF upload
shell: bash
Expand All @@ -105,6 +159,9 @@
OSV_SARIF_PATH: ${{ runner.temp }}/private-security-osv.sarif
GITLEAKS_SARIF_PATH: ${{ runner.temp }}/private-security-gitleaks.sarif
ACTIONLINT_LOG_PATH: ${{ runner.temp }}/private-security-actionlint.log
ACTIONLINT_ARCHIVE_PATH: ${{ runner.temp }}/private-security-tools/actionlint.tar.gz
OSV_SCANNER_PATH: ${{ runner.temp }}/private-security-tools/osv-scanner
GITLEAKS_ARCHIVE_PATH: ${{ runner.temp }}/private-security-tools/gitleaks.tar.gz
run: "$PRIVATE_SECURITY_BUNDLE_SCRIPT"

- name: Upload redacted security evidence
Expand Down
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,10 @@ The project follows Semantic Versioning.

### Changed

- Routed the consolidated private security bundle's pinned uv, actionlint,
OSV-Scanner and gitleaks artifacts through the public immutable tool-cache
action. Baked uv is reused without setup; GitHub-hosted and cache-miss jobs
retain the same checksum-verified upstream fallback.
- Strengthened the consolidated private-free security bundle without adding a
placement: actionlint logs plus Zizmor, OSV and fully redacted Gitleaks SARIF
are always retained as a one-day artifact, including on aggregate failure.
Expand Down
16 changes: 13 additions & 3 deletions scripts/run_private_security_bundle.sh
Original file line number Diff line number Diff line change
Expand Up @@ -45,18 +45,28 @@ trap cleanup EXIT
install -d -m 0700 "$tool_root/bin"
export PATH="$tool_root/bin:$PATH"

curl -fsSL --retry 5 --retry-max-time 120 -o "$tool_root/actionlint.tar.gz" \
use_or_download() {
local supplied=$1 output=$2 url=$3
if [[ -n "$supplied" ]]; then
[[ "$supplied" == "$RUNNER_TEMP"/* && -f "$supplied" && ! -L "$supplied" ]]
install -m 0600 "$supplied" "$output"
return
fi
curl -fsSL --retry 5 --retry-max-time 120 -o "$output" "$url"
}

use_or_download "${ACTIONLINT_ARCHIVE_PATH:-}" "$tool_root/actionlint.tar.gz" \
"https://github.com/rhysd/actionlint/releases/download/v${actionlint_version}/actionlint_${actionlint_version}_linux_amd64.tar.gz"
printf '%s %s\n' "$actionlint_sha256" "$tool_root/actionlint.tar.gz" | sha256sum -c -
tar -xzf "$tool_root/actionlint.tar.gz" -C "$tool_root/bin" actionlint
chmod 0700 "$tool_root/bin/actionlint"

curl -fsSL --retry 5 --retry-max-time 120 -o "$tool_root/osv-scanner" \
use_or_download "${OSV_SCANNER_PATH:-}" "$tool_root/osv-scanner" \
"https://github.com/google/osv-scanner/releases/download/v${osv_version}/osv-scanner_linux_amd64"
printf '%s %s\n' "$osv_sha256" "$tool_root/osv-scanner" | sha256sum -c -
install -m 0700 "$tool_root/osv-scanner" "$tool_root/bin/osv-scanner"

curl -fsSL --retry 5 --retry-max-time 120 -o "$tool_root/gitleaks.tar.gz" \
use_or_download "${GITLEAKS_ARCHIVE_PATH:-}" "$tool_root/gitleaks.tar.gz" \
"https://github.com/gitleaks/gitleaks/releases/download/v${gitleaks_version}/gitleaks_${gitleaks_version}_linux_x64.tar.gz"
test "$(wc -c < "$tool_root/gitleaks.tar.gz" | tr -d '[:space:]')" = "$gitleaks_size"
printf '%s %s\n' "$gitleaks_sha256" "$tool_root/gitleaks.tar.gz" | sha256sum -c -
Expand Down
Loading