ASDD review (publish) #51
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # ASDD - advisory PR review (PUBLISH half). | |
| # | |
| # SECURITY-CRITICAL. This workflow holds the only write scope in the review pipeline. It runs AFTER | |
| # pr-review.yml via workflow_run, in the BASE repo context. It NEVER reads untrusted PR content: it | |
| # consumes only the review.json artifact the analysis job produced, treats it as DATA, runs every action | |
| # through the policy decision point, and posts an ADVISORY comment. It never merges. | |
| # | |
| # - write scope lives here, isolated from the untrusted-input job. | |
| # - the artifact is data; actions are a fixed allow-list (comment), never shell-exec'd. | |
| # - policy-check.sh authorises each action before it runs; merge is denied. | |
| name: ASDD review (publish) | |
| on: | |
| workflow_run: | |
| workflows: ["ASDD review"] | |
| types: [completed] | |
| permissions: | |
| contents: read | |
| # actions: read is required to download the analysis job's artifact across runs | |
| # (workflow_run + actions/download-artifact with run-id). Without it the download | |
| # fails with "Resource not accessible by integration". Read-only; no new write scope. | |
| actions: read | |
| pull-requests: write | |
| issues: write | |
| statuses: write | |
| jobs: | |
| publish: | |
| if: github.event.workflow_run.conclusion == 'success' | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Check out base repo (trusted scripts only) | |
| uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 | |
| with: | |
| persist-credentials: false | |
| - name: Download the review artifact (data, not instructions) | |
| uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 | |
| with: | |
| name: asdd-review | |
| run-id: ${{ github.event.workflow_run.id }} | |
| github-token: ${{ secrets.GITHUB_TOKEN }} | |
| path: artifact | |
| - name: Policy decision point - authorise the post action | |
| env: | |
| ASDD_PHASE: advisory | |
| run: bash .github/asdd/policy-check.sh comment artifact/review.json | |
| - name: Policy decision point - authorise the set-status action | |
| env: | |
| ASDD_PHASE: advisory | |
| run: bash .github/asdd/policy-check.sh set-status artifact/review.json | |
| - name: Set the merge-gating status (security block / request-changes => failure) | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| REPO: ${{ github.repository }} | |
| run: bash .github/asdd/set-status.sh artifact/review.json | |
| - name: Post the advisory review comment | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| REPO: ${{ github.repository }} | |
| run: bash .github/asdd/post-review.sh artifact/review.json | |
| - name: Export the audit ledger to the adopter's private sink | |
| # STANDARD 1.3. This is the write-scoped context, and it reads ONLY ASDD-produced records, never | |
| # untrusted PR content, so the sink credential is never present where a fork's input is handled. | |
| # Inert unless audit.sink is configured; refuses the governed repo and any public destination. | |
| if: always() | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| AUDIT_SINK_TOKEN: ${{ secrets.AUDIT_SINK_TOKEN }} | |
| GITHUB_REPOSITORY: ${{ github.repository }} | |
| run: bash .github/asdd/audit-export.sh artifact/audit.jsonl |