Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
36 changes: 36 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
# Dependabot config for .NET / NuGet API repos.
# main is replaced by the rollout script with `develop` (if the
# repo has that branch) or the repo's actual default branch otherwise.
version: 2
updates:
- package-ecosystem: "nuget"
directory: "/"
target-branch: "main"
schedule:
interval: "weekly"
day: "monday"
time: "06:00"
timezone: "Asia/Amman"
open-pull-requests-limit: 10
groups:
nuget-minor-patch:
update-types: ["minor", "patch"]
labels:
- "dependencies"
- "nuget"

- package-ecosystem: "github-actions"
directory: "/"
target-branch: "main"
schedule:
interval: "weekly"
day: "monday"
time: "06:00"
timezone: "Asia/Amman"
open-pull-requests-limit: 5
groups:
actions-minor-patch:
update-types: ["minor", "patch"]
labels:
- "dependencies"
- "github-actions"
38 changes: 38 additions & 0 deletions .github/workflows/critical-vuln-check.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
# =============================================================================
# Critical Dependabot Vulnerability Check — Caller template
# =============================================================================
# USAGE:
# Copy this file to your repo at .github/workflows/critical-vuln-check.yml.
# No REPLACE values needed — this template requires no customization.
#
# WHAT IT DOES:
# Runs on every PR targeting main or develop. Fails if the repository has
# any open CRITICAL-severity Dependabot alert.
#
# Enforcement differs by target branch via each repo's OWN branch
# protection settings (not by anything in this file):
# - On `main`: mark this check REQUIRED in branch protection — merge
# is physically blocked while a critical alert is open.
# - On `develop`: leave this check NOT required — it still shows as a
# failing/red check (a visible warning) without blocking
# the merge.
# =============================================================================
name: Critical Vulnerability Check
run-name: vuln-check-${{ github.event.pull_request.number }}

on:
pull_request:
branches: [main, develop]

# critical-vuln-gate.yml's own job requests these two scopes -- a caller can
# only narrow permissions for a nested reusable-workflow job, never widen
# them, so these must be granted here or the whole file fails to parse.
permissions:
contents: write
security-events: read
Comment on lines +31 to +32

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Description: Inspect the reusable workflow to verify its actual permission requirements.
# Fetch the critical-vuln-gate.yml workflow file from simplify9/.github

gh api repos/simplify9/.github/contents/.github/workflows/critical-vuln-gate.yml \
  --jq '.content' | base64 -d | grep -A5 'permissions:'

Repository: simplify9/SW-CloudFiles

Length of output: 443


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Inspect the reusable action invoked by the workflow to see which permissions it actually needs.
gh api repos/simplify9/.github/contents/.github/actions/check-critical-vulns/action.yml --jq '.content' | base64 -d

printf '\n---\n'

# If the action is implemented via script, inspect the script entrypoint too.
gh api repos/simplify9/.github/contents/.github/actions/check-critical-vulns --jq '.[] | .path' | sed -n '1,20p'

Repository: simplify9/SW-CloudFiles

Length of output: 10844


Drop contents: write here — this gate only queries Dependabot alerts and the reusable action takes a PAT/App token, so repository write access is unused. Narrow the job to the minimum scope needed.

🧰 Tools
🪛 zizmor (1.26.1)

[error] 31-31: overly broad permissions (excessive-permissions): contents: write is overly broad at the workflow level

(excessive-permissions)


[warning] 31-31: permissions without explanatory comments (undocumented-permissions): needs an explanatory comment

(undocumented-permissions)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/critical-vuln-check.yml around lines 31 - 32, Remove the
contents: write permission from the workflow permissions block, retaining only
security-events: read for the Dependabot alert check and reusable action.

Source: Path instructions


jobs:
vuln-gate:
uses: simplify9/.github/.github/workflows/critical-vuln-gate.yml@main

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Unpinned reusable workflow simplify9/.github/.github/workflows/critical-vuln-gate.yml@main — supply-chain risk.

Both workflows reference the same reusable workflow via a mutable @main branch ref. If simplify9/.github's main branch is compromised, arbitrary code executes with contents: write and security-events: read in every consuming repo. Pin to a commit SHA in both files.

  • .github/workflows/critical-vuln-check.yml#L36-L36: Replace @main with a pinned commit SHA.
  • .github/workflows/dependabot-auto-merge.yml#L35-L35: Replace @main with the same pinned commit SHA.
🧰 Tools
🪛 zizmor (1.26.1)

[error] 36-36: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

📍 Affects 2 files
  • .github/workflows/critical-vuln-check.yml#L36-L36 (this comment)
  • .github/workflows/dependabot-auto-merge.yml#L35-L35
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/critical-vuln-check.yml at line 36, Pin the reusable
workflow reference to an immutable commit SHA instead of the mutable `@main` ref.
Update .github/workflows/critical-vuln-check.yml:36 and
.github/workflows/dependabot-auto-merge.yml:35 to use the same verified SHA for
simplify9/.github/.github/workflows/critical-vuln-gate.yml.

Sources: Path instructions, Linters/SAST tools

secrets:
dependabot-alerts-token: ${{ secrets.DEPENDABOT_ALERTS_TOKEN }}
61 changes: 61 additions & 0 deletions .github/workflows/dependabot-auto-merge.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
# =============================================================================
# Dependabot Auto-Merge — Caller template
# =============================================================================
# USAGE:
# Copy this file to your repo at .github/workflows/dependabot-auto-merge.yml.
# No REPLACE values needed.
#
# WHAT IT DOES:
# Auto-merges a Dependabot PR ONLY when ALL of the following hold:
# - The PR author is dependabot[bot]
# - The update is a semver PATCH bump (never minor/major)
# - The ecosystem is npm, nuget, pub, bundler, or github-actions
# (NEVER docker — base image bumps always need manual review)
# - This repo currently has no open critical Dependabot alert (re-checked
# here explicitly — see workflow-templates/critical-vuln-check.yml's
# header for why this can't just `needs:` that file's job)
# "Auto-merge" here means GitHub's native auto-merge feature: it still
# waits for the repo's actual required status checks (build/test) to pass
# before merging — this workflow does not bypass those.
# =============================================================================
name: Dependabot Auto-Merge

on:
pull_request:
branches: [main, develop]
Comment on lines +23 to +25

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚀 Performance & Scalability | 🔵 Trivial

Missing concurrency control allows redundant runs.

Multiple pushes to the same Dependabot PR trigger parallel workflow runs. Adding a concurrency group cancels superseded runs and saves CI minutes.

♻️ Proposed fix
 on:
   pull_request:
     branches: [main, develop]

+concurrency:
+  group: dependabot-auto-merge-${{ github.event.pull_request.number }}
+  cancel-in-progress: true
+
 permissions:
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
on:
pull_request:
branches: [main, develop]
on:
pull_request:
branches: [main, develop]
concurrency:
group: dependabot-auto-merge-${{ github.event.pull_request.number }}
cancel-in-progress: true
🧰 Tools
🪛 zizmor (1.26.1)

[warning] 23-25: insufficient job-level concurrency limits (concurrency-limits): workflow is missing concurrency setting

(concurrency-limits)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/dependabot-auto-merge.yml around lines 23 - 25, Add a
concurrency configuration to the workflow containing the pull_request trigger,
using a group keyed to the workflow and pull request identity and enabling
cancellation of in-progress runs so newer Dependabot updates supersede older
runs.

Source: Linters/SAST tools


permissions:
pull-requests: write
contents: write
security-events: read

jobs:
vuln-gate:
if: ${{ github.actor == 'dependabot[bot]' }}
uses: simplify9/.github/.github/workflows/critical-vuln-gate.yml@main
secrets:
dependabot-alerts-token: ${{ secrets.DEPENDABOT_ALERTS_TOKEN }}

auto-merge:
needs: vuln-gate
if: ${{ github.actor == 'dependabot[bot]' }}
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Fetch Dependabot metadata
id: metadata
uses: dependabot/fetch-metadata@v2

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🔵 Trivial

dependabot/fetch-metadata@v2 pinned to tag, not SHA.

While this is a first-party GitHub action, SHA pinning is recommended for security-sensitive workflows. A compromised tag would execute with pull-requests: write and contents: write in this repo's context.

🔒 Proposed fix
-        uses: dependabot/fetch-metadata@v2
+        uses: dependabot/fetch-metadata@<full-commit-sha>
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
uses: dependabot/fetch-metadata@v2
uses: dependabot/fetch-metadata@<full-commit-sha>
🧰 Tools
🪛 zizmor (1.26.1)

[error] 47-47: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/dependabot-auto-merge.yml at line 47, Pin the
dependabot/fetch-metadata action in the workflow to a full commit SHA instead of
the mutable v2 tag, while preserving the existing action version and permissions
configuration.

Source: Linters/SAST tools

with:
github-token: ${{ secrets.GITHUB_TOKEN }}

- name: Enable auto-merge for eligible patch bumps
if: |
steps.metadata.outputs.update-type == 'version-update:semver-patch' &&
contains(fromJSON('["npm_and_yarn", "nuget", "pub", "bundler", "github_actions"]'), steps.metadata.outputs.package-ecosystem)
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_URL: ${{ github.event.pull_request.html_url }}
run: |
set -euo pipefail
echo "::notice title=🤖 [AUTO-MERGE] Enabling auto-merge::${PR_URL} — patch-level ${{ steps.metadata.outputs.package-ecosystem }} bump, vuln gate passed"
gh pr merge --auto --squash "$PR_URL"
Comment on lines +58 to +61

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

Template injection in echo via inline expansion.

${{ steps.metadata.outputs.package-ecosystem }} is expanded directly into the run block. While the value is Dependabot-controlled and the job is gated on dependabot[bot] actor, use an environment variable for defense-in-depth — PR_URL is already passed this way.

As per path instructions, GitHub Actions changes should be checked for shell injection risks and untrusted input used in scripts.

🛡️ Proposed fix
         env:
           GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
           PR_URL: ${{ github.event.pull_request.html_url }}
+          PACKAGE_ECOSYSTEM: ${{ steps.metadata.outputs.package-ecosystem }}
         run: |
           set -euo pipefail
-          echo "::notice title=🤖 [AUTO-MERGE] Enabling auto-merge::${PR_URL} — patch-level ${{ steps.metadata.outputs.package-ecosystem }} bump, vuln gate passed"
+          echo "::notice title=🤖 [AUTO-MERGE] Enabling auto-merge::${PR_URL} — patch-level ${PACKAGE_ECOSYSTEM} bump, vuln gate passed"
           gh pr merge --auto --squash "$PR_URL"
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
run: |
set -euo pipefail
echo "::notice title=🤖 [AUTO-MERGE] Enabling auto-merge::${PR_URL} — patch-level ${{ steps.metadata.outputs.package-ecosystem }} bump, vuln gate passed"
gh pr merge --auto --squash "$PR_URL"
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_URL: ${{ github.event.pull_request.html_url }}
PACKAGE_ECOSYSTEM: ${{ steps.metadata.outputs.package-ecosystem }}
run: |
set -euo pipefail
echo "::notice title=🤖 [AUTO-MERGE] Enabling auto-merge::${PR_URL} — patch-level ${PACKAGE_ECOSYSTEM} bump, vuln gate passed"
gh pr merge --auto --squash "$PR_URL"
🧰 Tools
🪛 zizmor (1.26.1)

[info] 60-60: code injection via template expansion (template-injection): may expand into attacker-controllable code

(template-injection)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/dependabot-auto-merge.yml around lines 58 - 61, Replace
the inline GitHub Actions expression for
steps.metadata.outputs.package-ecosystem in the run block with a job-step
environment variable, then reference that variable in the notice command
alongside PR_URL. Keep the existing auto-merge command and behavior unchanged.

Sources: Path instructions, Linters/SAST tools

Loading