Skip to content

feat: research-fed detection⇄evasion loop, coordination/QUIC/FP-gate rungs, grounding harness #517

feat: research-fed detection⇄evasion loop, coordination/QUIC/FP-gate rungs, grounding harness

feat: research-fed detection⇄evasion loop, coordination/QUIC/FP-gate rungs, grounding harness #517

Workflow file for this run

# .github/workflows/security — supply-chain + secret-scanning posture.
# Secret scan, license-isolation gate, SBOM artifact, and OpenSSF Scorecard.
name: security
on:
push: { branches: [main] }
pull_request:
schedule: [{ cron: "0 6 * * 1" }]
permissions:
contents: read
jobs:
secrets:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with: { fetch-depth: 0 }
- uses: gitleaks/gitleaks-action@ff98106e4c7b2bc287b24eaf42907196329070c7 # v2
license-isolation:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
with: { python-version: "3.12" }
- run: python3 scripts/check_license_isolation.py
sbom:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0
with: { format: spdx-json, output-file: sbom.spdx.json }
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with: { name: sbom, path: sbom.spdx.json }
scorecard:
runs-on: ubuntu-latest
permissions:
security-events: write
id-token: write
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with: { persist-credentials: false }
- uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
with: { results_file: results.sarif, results_format: sarif }
- uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2
with: { sarif_file: results.sarif }