Commit Graph
13 Commits
Author SHA1 Message Date
Jon Ross-Perkins b73387fc84 Update workflows for security hardening. (#4192)
Also a small pass on workflow names.

Note, I'm a little concerned that the test/nightly release/pre-commit
endpoints may be fragile. At the same time, it's also where it may be
most useful, to prevent network access by arbitrary test code. I think
this is imperfect, but maybe we can try it out and see if it's much of
an issue.

Note, the discord wiki action is currently broken, this should fix it.
2024-08-06 23:14:23 +00:00
Jon Ross-Perkins 52bf4e618c Switch the resolve action to push (#3998)
https://github.com/Ardiannn08/resolve-outdated-comment documents this as
using push. My guess is that's the root of
https://github.com/carbon-language/carbon-lang/actions/runs/9259644459/job/25471949664;
if this doesn't fix it, we'll probably just need to remove it.
2024-05-28 16:09:25 +00:00
Richard Smith d01a80b7cc Delete CarbonInfraBot comments with no replies when they become outdated. (#3982) 2024-05-24 14:57:59 +00:00
Jon Ross-Perkins 97816a3598 Use https://app.stepsecurity.io/secureworkflow to improve workflow security. (#3879)
This is coming out of advice from
https://securityscorecards.dev/viewer/?uri=github.com/carbon-language/carbon-lang

Updates action versions and pins by checksum. This is something we
already do in other places, and doing it with actions just seems
consistent.

Trying to add token permissions at the same time.

step-security/harden-runner is being set up to monitor network traffic
for actions, with the idea that we'd set it to block unexpected traffic
in the future.

Note, https://app.stepsecurity.io/secureworkflow generates the pinned
checksums and adds the harden-runner. In some cases it added token
permissions, but we have a couple it doesn't recognize (`gh` executions,
other custom commands, jlumbroso/free-disk-space, reviewdog/action-setup
as examples) so I'm trying to guess my best.

Because these are workflows, testing is limited.
2024-04-15 14:40:38 +00:00
Jon Ross-Perkins 36c05bd573 Opt out of pre-commit suggestions (#3858)
Due to my workflow, I prefer to run `pre-commit` locally when I forget
to after an amend. While reviewdog can be helpful in the UI, it's mostly
making me mark comments as resolved as part of re-pushing. Rather than
continuing with this, maybe opting out is best?
2024-04-04 18:31:36 +00:00
Jon Ross-Perkins 0405fff68c Update to checkout v4 (#3759)
Noticed due to
https://github.com/carbon-language/carbon-lang/actions/runs/8207272518

```
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: actions/checkout@v3. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.
```

I'm expecting we can just update the version number on these.
2024-03-08 20:25:04 +00:00
Jon Ross-Perkins 1d2b7db482 Switch reviewdog to a bespoke secret. (#3757)
This uses a token from the low-privilege CarbonInfraBot, which should
allow us to separate out permission for Google's CLA bot.
2024-03-08 16:41:36 +00:00
Richard Smith 56d70dc3a2 Provide a git checkout for reviewdog. (#3754)
It shouldn't actually need or use this, but it fails if there's no
`.git` directory at all.
2024-03-08 00:18:29 +00:00
Richard Smith b0dc6d2996 Pass the event path to reviewdog, not to cat. (#3753)
Should hopefully cause suggestions to be successfully created.
2024-03-07 23:28:06 +00:00
Richard Smith 2424ea16ea Use reviewdog rather than suggestion-bot to create suggestions. (#3752) 2024-03-07 22:57:18 +00:00
Richard Smith 43bfbbe6d5 Explicitly pass in github token to download action. (#3751) 2024-03-07 22:00:24 +00:00
Richard Smith 648f0ccd78 Unify pre-commit actions and attempt to fix suggestion-bot (#3750) 2024-03-07 21:44:49 +00:00
Richard Smith 61ea4f8344 Use suggestion-bot to convert pre-commit errors in PRs with fixes into code review suggestions. (#3746)
This can't be done directly from a `pull_request` action, because that's
run without write privileges. This is done for security reasons, because
it runs in the context of the pull request branch. So instead, we
perform this in two steps:

- The `pull_request` action runs `pre-commit` and uploads an artifact
containing the diffs and the event information (which is only used to
extract the pull request number).
- A separate `workflow_run` action is triggered when the `pre-commit`
action finishes. This action is privileged, and should be able to
download the artifact and create corresponding suggestions.

Unfortunately, due to the permissions model in play here, the second
half of this appears to only be testable live in production.

For now, we're splitting the pre-commit action into two actions -- one
to run on PRs and one to run when actually merging commits -- so that
the suggestions are only triggered in the former case. It might be
possible to recombine these using data in the `workflow_run` invocation
to tell them apart, but the documentation here isn't very good so I've
made this PR dump out that event information so that we can look at it
and see if it contains the relevant information.
2024-03-07 20:54:17 +00:00