Skip to content

chore(ci): add secure runner across workflows - #914

Merged
grandizzy merged 1 commit into
masterfrom
centaur/secure-runner-1789751313
Sep 18, 2026
Merged

grandizzy merged 1 commit into
masterfrom
centaur/secure-runner-1789751313

Conversation

@decofe

@decofe decofe commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Add the pinned secure-runner action before checkout in build, test, formatting, typo, CodeQL, and release-branch sync jobs, with job-scoped OIDC permissions. The matrix generator and final result aggregation do not install dependencies and are unchanged.

Foundry/solc binaries and Git dependencies are not covered by registry package checks.

Validation: actionlint passed (with existing Depot labels configured where needed), git diff --check passed, and a YAML coverage audit confirmed the first-step ordering, OIDC permissions, preserved triggers/matrices, and intended exclusions. Offline zizmor introduced no new findings relative to the base branch; existing findings remain. GitHub CI and workflows triggered only by schedules/releases/Dependabot still require runtime validation.

The action's documented fork-PR fallback skips package-policy enforcement when GitHub withholds OIDC. Existing caches are retained and are not rescanned.

Prepared with AI assistance.

Prompted by: @grandizzy

Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
@grandizzy
grandizzy marked this pull request as ready for review September 18, 2026 17:18
@grandizzy
grandizzy enabled auto-merge (squash) September 18, 2026 17:18
@grandizzy
grandizzy merged commit 3e577a1 into master Sep 18, 2026
20 checks passed
@grandizzy
grandizzy deleted the centaur/secure-runner-1789751313 branch September 18, 2026 17:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants