diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 72d41c0..53c097f 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,32 +1,21 @@ # SPDX-License-Identifier: MPL-2.0 -{ - name: "Governance", - on: { - push: { - branches: [ - "main", - "master", - ], - }, - pull_request: { - branches: [ - "main", - "master", - ], - }, - workflow_dispatch: null, - }, - concurrency: { - group: "${{ github.workflow }}-${{ github.ref }}", - cancel-in-progress: true, - }, - permissions: { - actions: "read", # required by the reusable workflow (staleness check reads workflow runs) - contents: "read", - }, - jobs: { - governance: { - uses: "hyperpolymath/standards/.github/workflows/governance-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc", - }, - }, -} +name: Governance + +on: + push: + branches: [main, master] + pull_request: + branches: [main, master] + workflow_dispatch: + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +permissions: + actions: read # required by the reusable workflow (staleness check reads workflow runs) + contents: read + +jobs: + governance: + uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index eebb714..8cd4783 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,38 +1,31 @@ # SPDX-License-Identifier: MPL-2.0 # SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell -{ - name: "Mirror to Git Forges", - on: { - push: { - branches: [ - "main", - ], - }, - workflow_dispatch: null, - }, - concurrency: { - group: "${{ github.workflow }}-${{ github.ref }}", - cancel-in-progress: false, - }, - permissions: { - actions: "read", # required by the reusable workflow - contents: "read", - }, - jobs: { - mirror: { - uses: "hyperpolymath/standards/.github/workflows/mirror-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc", - # Each forge job is still gated on vars._MIRROR_ENABLED, inside the - # callee. Explicit secrets map, no secrets: inherit; these seven are the - # callee's complete optional contract at 900c42c70b968e11a2bca04bf0ce050be5c286dc. - secrets: { - GITLAB_SSH_KEY: "${{ secrets.GITLAB_SSH_KEY }}", - BITBUCKET_SSH_KEY: "${{ secrets.BITBUCKET_SSH_KEY }}", - CODEBERG_SSH_KEY: "${{ secrets.CODEBERG_SSH_KEY }}", - SOURCEHUT_SSH_KEY: "${{ secrets.SOURCEHUT_SSH_KEY }}", - DISROOT_SSH_KEY: "${{ secrets.DISROOT_SSH_KEY }}", - GITEA_SSH_KEY: "${{ secrets.GITEA_SSH_KEY }}", - RADICLE_KEY: "${{ secrets.RADICLE_KEY }}", - }, - }, - }, -} +name: Mirror to Git Forges + +on: + push: + branches: [main] + workflow_dispatch: + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: false + +permissions: + actions: read # required by the reusable workflow + contents: read + +jobs: + mirror: + uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc + # Each forge job is still gated on vars._MIRROR_ENABLED, inside the + # callee. Explicit secrets map, no secrets: inherit; these seven are the + # callee's complete optional contract at 900c42c70b968e11a2bca04bf0ce050be5c286dc. + secrets: + GITLAB_SSH_KEY: ${{ secrets.GITLAB_SSH_KEY }} + BITBUCKET_SSH_KEY: ${{ secrets.BITBUCKET_SSH_KEY }} + CODEBERG_SSH_KEY: ${{ secrets.CODEBERG_SSH_KEY }} + SOURCEHUT_SSH_KEY: ${{ secrets.SOURCEHUT_SSH_KEY }} + DISROOT_SSH_KEY: ${{ secrets.DISROOT_SSH_KEY }} + GITEA_SSH_KEY: ${{ secrets.GITEA_SSH_KEY }} + RADICLE_KEY: ${{ secrets.RADICLE_KEY }} diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index ae8ad02..83e700e 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,27 +1,22 @@ # SPDX-License-Identifier: MPL-2.0 -{ - name: "Scorecards supply-chain security", - on: { - branch_protection_rule: null, - schedule: [ - { - cron: "23 4 * * 1", - }, - ], - }, - permissions: "read-all", - jobs: { - analysis: { - uses: "hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc", - # A job-level map replaces the workflow-level one, so every scope the - # callee's jobs request must be listed here. actions: read is new in the - # callee since 81dbf2dd. No secrets: the callee declares and reads none. - permissions: { - actions: "read", - contents: "read", - security-events: "write", - id-token: "write", - }, - }, - }, -} +name: Scorecards supply-chain security + +on: + branch_protection_rule: + schedule: + - cron: '23 4 * * 1' + +permissions: + contents: read + +jobs: + analysis: + uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc + # A job-level map replaces the workflow-level one, so every scope the + # callee's jobs request must be listed here. actions: read is new in the + # callee since 81dbf2dd. No secrets: the callee declares and reads none. + permissions: + actions: read + contents: read + security-events: write + id-token: write diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index 1f3a824..57740e8 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -8,26 +8,20 @@ # No `secrets:` line, deliberately: the reusable references no secrets # (gitleaks runs as a checksum-verified binary, not gitleaks-action), so # `secrets: inherit` would only hand it every repo and org secret (CWE-250). -{ - name: "Secret Scanner", - on: { - pull_request: null, - push: { - branches: [ - "main", - ], - }, - }, - concurrency: { - group: "${{ github.workflow }}-${{ github.ref }}", - cancel-in-progress: true, - }, - permissions: { - contents: "read", - }, - jobs: { - scan: { - uses: "hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc", - }, - }, -} +name: Secret Scanner + +on: + pull_request: + push: + branches: [main] + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +permissions: + contents: read + +jobs: + scan: + uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc