Skip to content

ci: reuse shared security workflows - #333

Merged
EmersonBraun merged 2 commits into
mainfrom
codex/reusable-security-callers
Oct 3, 2026
Merged

EmersonBraun merged 2 commits into
mainfrom
codex/reusable-security-callers

Conversation

@EmersonBraun

Copy link
Copy Markdown
Member

What

  • Replace local CodeQL, Scorecard, dependency review, and npm audit implementations with reusable workflow callers pinned to 5a584290feaaa0a800a28d24583d16f15102bea1.
  • Keep the root npm audit --omit=dev --audit-level=high and the docs npm audit --prefix apps/docs --audit-level=high semantics in separate reusable callers.

Why

  • Centralize reusable security checks while preserving the repository's existing triggers, severity thresholds, and required check labels where supported.

How

  • Keep CodeQL on javascript-typescript, security-and-quality, and build-mode: none.
  • Use minimal caller permissions required by the shared CodeQL, Scorecard, dependency-review, and audit workflows.
  • Leave CI, check, and publish workflows unchanged.

Reuse

Validation

  • actionlint .github/workflows/codeql.yml .github/workflows/scorecard.yml .github/workflows/dependency-review.yml — passed.
  • npm run check on Node 22 — passed (326 tests and documentation gates).
  • npm pack --dry-run — passed.
  • PR checks will be reported after the Actions runs finish.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@EmersonBraun
EmersonBraun merged commit 4c57423 into main Oct 3, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants