Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 1 addition & 19 deletions .github/workflows/container-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -344,25 +344,7 @@ jobs:
env:
CODEX_SECURITY_IMAGE: ${{ steps.manifest.outputs.candidate }}
shell: bash
run: |
set -euo pipefail
mkdir -p results state
chmod 700 results state
printf 'id,repository,revision\n' > repositories.csv
CODEX_SECURITY_USER="$(id -u):$(id -g)"
export CODEX_SECURITY_USER
docker compose config --quiet
docker compose run --rm codex-security --version
if output="$(docker compose run --rm codex-security 2>&1)"; then
echo 'An empty repository CSV must not start a security scan.' >&2
exit 1
else
status=$?
fi
if [[ "$status" -ne 2 ]] || ! grep -Fq 'Multiscan CSV must contain at least one repository.' <<< "$output"; then
printf 'Unexpected empty-repository scan behavior:\n%s\n' "$output" >&2
exit 1
fi
run: source docker/verify-container-compose.sh

attest:
name: attest-verified-multiarchitecture-candidate
Expand Down
20 changes: 1 addition & 19 deletions .github/workflows/container-validate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -150,25 +150,7 @@ jobs:
env:
CODEX_SECURITY_IMAGE: codex-security:release-candidate
shell: bash
run: |
set -euo pipefail
mkdir -p results state
chmod 700 results state
printf 'id,repository,revision\n' > repositories.csv
CODEX_SECURITY_USER="$(id -u):$(id -g)"
export CODEX_SECURITY_USER
docker compose config --quiet
docker compose run --rm codex-security --version
if output="$(docker compose run --rm codex-security 2>&1)"; then
echo 'An empty repository CSV must not start a security scan.' >&2
exit 1
else
status=$?
fi
if [[ "$status" -ne 2 ]] || ! grep -Fq 'Multiscan CSV must contain at least one repository.' <<< "$output"; then
printf 'Unexpected empty-repository scan behavior:\n%s\n' "$output" >&2
exit 1
fi
run: source docker/verify-container-compose.sh

- name: Verify hardened AppArmor Compose override
env:
Expand Down
9 changes: 4 additions & 5 deletions .github/workflows/node-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -74,7 +74,8 @@ jobs:
plugin_changed=true
fi
case "$path" in
.github/workflows/* | .github/actions/* | .github/actionlint.yaml | .github/zizmor.yml)
.github/workflows/* | .github/actions/* | .github/actionlint.yaml | .github/zizmor.yml | \
docker/verify-container-compose.sh)
workflow_quality=true
;;
esac
Expand All @@ -83,10 +84,8 @@ jobs:
.github/actions/download-native/* | Dockerfile | \
Dockerfile.dockerignore | compose.yaml | compose.apparmor.yaml | \
compose.findings.yaml | compose.runner.yaml | docker/* | \
plugins/codex-security/* | sdk/typescript/*)
container_validate=true
;;
.github/workflows/container-ci.yml | .github/workflows/container-release.yml | \
plugins/codex-security/* | sdk/typescript/* | \
.github/workflows/container-ci.yml | .github/workflows/container-release.yml | \
.github/workflows/container-validate.yml)
container_validate=true
;;
Expand Down
4 changes: 3 additions & 1 deletion .github/workflows/workflow-quality.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,8 @@ jobs:
env:
# Enforce correctness diagnostics without changing existing shell style.
SHELLCHECK_OPTS: --severity=warning
run: actionlint -color
run: |
actionlint -color
shellcheck docker/verify-container-compose.sh
- name: Check workflow security
run: zizmor --offline --strict-collection --min-severity medium --format github --config .github/zizmor.yml .github
20 changes: 20 additions & 0 deletions docker/verify-container-compose.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
#!/usr/bin/env bash

set -euo pipefail
mkdir -p results state
chmod 700 results state
printf 'id,repository,revision\n' > repositories.csv
CODEX_SECURITY_USER="$(id -u):$(id -g)"
export CODEX_SECURITY_USER
docker compose config --quiet
docker compose run --rm codex-security --version
if output="$(docker compose run --rm codex-security 2>&1)"; then
echo 'An empty repository CSV must not start a security scan.' >&2
exit 1
else
status=$?
fi
if [[ "$status" -ne 2 ]] || ! grep -Fq 'Multiscan CSV must contain at least one repository.' <<< "$output"; then
printf 'Unexpected empty-repository scan behavior:\n%s\n' "$output" >&2
exit 1
fi
1 change: 1 addition & 0 deletions sdk/typescript/tests-ts/workflow-quality.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,7 @@ bashTest(
],
["pull_request", false, [".github/actionlint.yaml"], "true"],
["pull_request", false, [".github/zizmor.yml"], "true"],
["pull_request", false, ["docker/verify-container-compose.sh"], "true"],
["pull_request", false, ["sdk/typescript/src/index.ts"], "false"],
["pull_request", false, ["README.md"], "false"],
] as const) {
Expand Down
Loading