Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
51 changes: 20 additions & 31 deletions .github/workflows/governance.yml
Original file line number Diff line number Diff line change
@@ -1,32 +1,21 @@
# SPDX-License-Identifier: MPL-2.0
{
name: "Governance",
on: {
push: {
branches: [
"main",
"master",
],
},
pull_request: {
branches: [
"main",
"master",
],
},
workflow_dispatch: null,
},
concurrency: {
group: "${{ github.workflow }}-${{ github.ref }}",
cancel-in-progress: true,
},
permissions: {
actions: "read", # required by the reusable workflow (staleness check reads workflow runs)
contents: "read",
},
jobs: {
governance: {
uses: "hyperpolymath/standards/.github/workflows/governance-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc",
},
},
}
name: Governance

on:
push:
branches: [main, master]
pull_request:
branches: [main, master]
workflow_dispatch:

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

permissions:
actions: read # required by the reusable workflow (staleness check reads workflow runs)
contents: read

jobs:
governance:
uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc
65 changes: 29 additions & 36 deletions .github/workflows/mirror.yml
Original file line number Diff line number Diff line change
@@ -1,38 +1,31 @@
# SPDX-License-Identifier: MPL-2.0
# SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell
{
name: "Mirror to Git Forges",
on: {
push: {
branches: [
"main",
],
},
workflow_dispatch: null,
},
concurrency: {
group: "${{ github.workflow }}-${{ github.ref }}",
cancel-in-progress: false,
},
permissions: {
actions: "read", # required by the reusable workflow
contents: "read",
},
jobs: {
mirror: {
uses: "hyperpolymath/standards/.github/workflows/mirror-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc",
# Each forge job is still gated on vars.<FORGE>_MIRROR_ENABLED, inside the
# callee. Explicit secrets map, no secrets: inherit; these seven are the
# callee's complete optional contract at 900c42c70b968e11a2bca04bf0ce050be5c286dc.
secrets: {
GITLAB_SSH_KEY: "${{ secrets.GITLAB_SSH_KEY }}",
BITBUCKET_SSH_KEY: "${{ secrets.BITBUCKET_SSH_KEY }}",
CODEBERG_SSH_KEY: "${{ secrets.CODEBERG_SSH_KEY }}",
SOURCEHUT_SSH_KEY: "${{ secrets.SOURCEHUT_SSH_KEY }}",
DISROOT_SSH_KEY: "${{ secrets.DISROOT_SSH_KEY }}",
GITEA_SSH_KEY: "${{ secrets.GITEA_SSH_KEY }}",
RADICLE_KEY: "${{ secrets.RADICLE_KEY }}",
},
},
},
}
name: Mirror to Git Forges

on:
push:
branches: [main]
workflow_dispatch:

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: false

permissions:
actions: read # required by the reusable workflow
contents: read

jobs:
mirror:
uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc
# Each forge job is still gated on vars.<FORGE>_MIRROR_ENABLED, inside the
# callee. Explicit secrets map, no secrets: inherit; these seven are the
# callee's complete optional contract at 900c42c70b968e11a2bca04bf0ce050be5c286dc.
secrets:
GITLAB_SSH_KEY: ${{ secrets.GITLAB_SSH_KEY }}
BITBUCKET_SSH_KEY: ${{ secrets.BITBUCKET_SSH_KEY }}
CODEBERG_SSH_KEY: ${{ secrets.CODEBERG_SSH_KEY }}
SOURCEHUT_SSH_KEY: ${{ secrets.SOURCEHUT_SSH_KEY }}
DISROOT_SSH_KEY: ${{ secrets.DISROOT_SSH_KEY }}
GITEA_SSH_KEY: ${{ secrets.GITEA_SSH_KEY }}
RADICLE_KEY: ${{ secrets.RADICLE_KEY }}
47 changes: 21 additions & 26 deletions .github/workflows/scorecard.yml
Original file line number Diff line number Diff line change
@@ -1,27 +1,22 @@
# SPDX-License-Identifier: MPL-2.0
{
name: "Scorecards supply-chain security",
on: {
branch_protection_rule: null,
schedule: [
{
cron: "23 4 * * 1",
},
],
},
permissions: "read-all",
jobs: {
analysis: {
uses: "hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc",
# A job-level map replaces the workflow-level one, so every scope the
# callee's jobs request must be listed here. actions: read is new in the
# callee since 81dbf2dd. No secrets: the callee declares and reads none.
permissions: {
actions: "read",
contents: "read",
security-events: "write",
id-token: "write",
},
},
},
}
name: Scorecards supply-chain security

on:
branch_protection_rule:
schedule:
- cron: '23 4 * * 1'

permissions:
contents: read

jobs:
analysis:
uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc
# A job-level map replaces the workflow-level one, so every scope the
# callee's jobs request must be listed here. actions: read is new in the
# callee since 81dbf2dd. No secrets: the callee declares and reads none.
permissions:
actions: read
contents: read
security-events: write
id-token: write
40 changes: 17 additions & 23 deletions .github/workflows/secret-scanner.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,26 +8,20 @@
# No `secrets:` line, deliberately: the reusable references no secrets
# (gitleaks runs as a checksum-verified binary, not gitleaks-action), so
# `secrets: inherit` would only hand it every repo and org secret (CWE-250).
{
name: "Secret Scanner",
on: {
pull_request: null,
push: {
branches: [
"main",
],
},
},
concurrency: {
group: "${{ github.workflow }}-${{ github.ref }}",
cancel-in-progress: true,
},
permissions: {
contents: "read",
},
jobs: {
scan: {
uses: "hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc",
},
},
}
name: Secret Scanner

on:
pull_request:
push:
branches: [main]

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
scan:
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc
Loading