Skip to content

ASDD review (publish) #51

ASDD review (publish)

ASDD review (publish) #51

# ASDD - advisory PR review (PUBLISH half).
#
# SECURITY-CRITICAL. This workflow holds the only write scope in the review pipeline. It runs AFTER
# pr-review.yml via workflow_run, in the BASE repo context. It NEVER reads untrusted PR content: it
# consumes only the review.json artifact the analysis job produced, treats it as DATA, runs every action
# through the policy decision point, and posts an ADVISORY comment. It never merges.
#
# - write scope lives here, isolated from the untrusted-input job.
# - the artifact is data; actions are a fixed allow-list (comment), never shell-exec'd.
# - policy-check.sh authorises each action before it runs; merge is denied.
name: ASDD review (publish)
on:
workflow_run:
workflows: ["ASDD review"]
types: [completed]
permissions:
contents: read
# actions: read is required to download the analysis job's artifact across runs
# (workflow_run + actions/download-artifact with run-id). Without it the download
# fails with "Resource not accessible by integration". Read-only; no new write scope.
actions: read
pull-requests: write
issues: write
statuses: write
jobs:
publish:
if: github.event.workflow_run.conclusion == 'success'
runs-on: ubuntu-latest
steps:
- name: Check out base repo (trusted scripts only)
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
persist-credentials: false
- name: Download the review artifact (data, not instructions)
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: asdd-review
run-id: ${{ github.event.workflow_run.id }}
github-token: ${{ secrets.GITHUB_TOKEN }}
path: artifact
- name: Policy decision point - authorise the post action
env:
ASDD_PHASE: advisory
run: bash .github/asdd/policy-check.sh comment artifact/review.json
- name: Policy decision point - authorise the set-status action
env:
ASDD_PHASE: advisory
run: bash .github/asdd/policy-check.sh set-status artifact/review.json
- name: Set the merge-gating status (security block / request-changes => failure)
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
REPO: ${{ github.repository }}
run: bash .github/asdd/set-status.sh artifact/review.json
- name: Post the advisory review comment
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
REPO: ${{ github.repository }}
run: bash .github/asdd/post-review.sh artifact/review.json
- name: Export the audit ledger to the adopter's private sink
# STANDARD 1.3. This is the write-scoped context, and it reads ONLY ASDD-produced records, never
# untrusted PR content, so the sink credential is never present where a fork's input is handled.
# Inert unless audit.sink is configured; refuses the governed repo and any public destination.
if: always()
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
AUDIT_SINK_TOKEN: ${{ secrets.AUDIT_SINK_TOKEN }}
GITHUB_REPOSITORY: ${{ github.repository }}
run: bash .github/asdd/audit-export.sh artifact/audit.jsonl