Skip to content

ci: add Dependabot and security checks - #14

Open
lemarier wants to merge 3 commits into
mainfrom
lemarier/dependabot
Open

lemarier wants to merge 3 commits into
mainfrom
lemarier/dependabot

Conversation

@lemarier

@lemarier lemarier commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Change

Adds Dependabot version updates and the shared origin89-security workflow from origin89hq/engineering#28. Updates run weekly with minor and patch releases grouped per ecosystem, majors as separate PRs, and a seven-day cooldown; nothing auto-merges. The workflow runs dependency review on pull requests and a zizmor audit of the workflows on pull requests, pushes to main, and weekly. There is no Cargo workspace, so the cargo-deny job is omitted.

Dependabot covers GitHub Actions in the workflows and the setup-node composite action, the pnpm workspace through the npm ecosystem at the root, and the Compose library's Gradle build in platforms/compose. The Swift ecosystem is left out because Package.swift declares no remote packages.

The seven-day cooldown is the minimum zizmor 1.30.1 accepts, so no cooldown ignore is needed; security updates are not delayed.

Validation

  • uvx zizmor@1.30.1 --offline --min-severity medium .github/: no findings.
  • actionlint: the new workflow is clean; it reports only the existing concurrency.queue key in release-swift.yml, which actionlint 1.7.12 does not recognise and this PR does not touch.
  • check-jsonschema with the Dependabot and GitHub workflow schemas: both new files pass.
  • Not checked: whether Dependabot's Gradle updater refreshes platforms/compose/ui/gradle.lockfile; the first Gradle PR will show it.
  • The new workflow has not run yet; this PR is its first run.

Copilot AI lite review requested due to automatic review settings September 27, 2026 12:01

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: QUIET

Plan: Advanced

Run ID: 9bdde12f-ce55-4c04-a3da-df0fd9fc7667

📥 Commits

Reviewing files that changed from the base of the PR and between 50e3188 and 66cd9f1.

📒 Files selected for processing (4)
  • .github/actions/setup-node/action.yml
  • .github/dependabot.yml
  • .github/workflows/origin89-security.yml
  • .github/workflows/publish-react.yml

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The changes update pinned pnpm/action-setup references in the setup action and four publishing jobs. They add weekly Dependabot checks for GitHub Actions, npm, and Gradle. They also add a workflow that runs dependency review and zizmor checks on configured triggers.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Merge Risk: ⚪ Minimal · up to 66cd9

The configured checks match their stated event scopes. No actionable merge-blocking issue remains after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 66cd9

Pull requests gain dependency checks, but the weekly run does not check existing dependencies for newly disclosed advisories. This was not a loss of an existing scheduled check; the workflow has not yet run.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The uncovered scheduled case concerns dependencies already on main when a new advisory appears. Whether changes can enter main without the pull-request check depends on branch controls not established here.

Security Findings and Attack Paths

  • observed — The retained finding identifies a real event-to-control gap: the weekly run cannot execute dependency review. Because the workflow is new and main had no scheduled dependency-review job, this is not established as a PR-introduced increase in effective exposure.

Trust Boundaries and Controls

  • observed — Dependency review applies moderate-or-higher severity checks to pull-request dependency additions; the zizmor job audits workflows rather than substituting for a scheduled dependency check.

Hardening Proposals

  • proposed — If weekly detection of newly disclosed advisories is an intended guarantee, add a scheduled control designed to inspect existing dependencies; the pull-request-only dependency-review job cannot provide it.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main changes: adding Dependabot configuration and security checks.
Description check ✅ Passed The description accurately explains the Dependabot configuration, security workflow, update schedule, coverage, exclusions, and validation results.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T12:05:21.129960Z 4cdc8fe PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4cdc8fe725

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

fail-on-scopes: runtime, development
# Checked only for dependencies the pull request adds. Unknown
# licenses are reported without failing.
allow-licenses: >-

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Avoid failing PRs for unknown dependency licenses

When GitHub cannot determine a newly introduced dependency's license, allow-licenses treats that dependency as outside the allowlist and the dependency-review action fails the job. This contradicts the adjacent report-only comment and can block otherwise acceptable pull requests, including Dependabot updates; unknown-license dependencies must be explicitly exempted with allow-dependencies-licenses, or the license policy needs to be configured differently.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants