Auditor plugin: Psalm (lint) — PHP analysis #493
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| pull_request: | |
| branches: [main] | |
| push: | |
| branches: [main] | |
| schedule: | |
| - cron: '23 4 * * 1' | |
| workflow_dispatch: {} | |
| permissions: {} | |
| concurrency: | |
| group: codeybox-ci-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| build-test: | |
| name: build and deterministic tests | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0 | |
| with: | |
| dotnet-version: 10.0.x | |
| - run: dotnet restore CodeyBox.slnx | |
| - run: dotnet build CodeyBox.slnx --configuration Release --no-restore | |
| - name: deterministic tests | |
| run: dotnet test tests/CodeyBox.Tests/CodeyBox.Tests.csproj --configuration Release --no-build --filter 'requires_multipass!=true' | |
| - name: admin tests | |
| run: dotnet test tools/CodeyBox.Admin/tests/CodeyBox.Admin.Tests/CodeyBox.Admin.Tests.csproj --configuration Release --no-build | |
| - name: dependency vulnerability audit | |
| run: dotnet list CodeyBox.slnx package --vulnerable --include-transitive | |
| # Non-Linux hosts support only the remote-executor topology | |
| # (docs/concepts/host-platforms.md): no local VM providers, no nftables. | |
| # These jobs prove the declared scope — the orchestrator builds and the | |
| # platform-matrix/path tests pass — without claiming isolation that has | |
| # not been exercised on these hosts. | |
| build-test-macos: | |
| name: build and platform tests (macos) | |
| runs-on: macos-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0 | |
| with: | |
| dotnet-version: 10.0.x | |
| - run: dotnet restore CodeyBox.slnx | |
| - run: dotnet build CodeyBox.slnx --configuration Release --no-restore | |
| - name: platform matrix and path tests | |
| run: dotnet test tests/CodeyBox.Tests/CodeyBox.Tests.csproj --configuration Release --no-build --filter 'FullyQualifiedName~HostPlatform|FullyQualifiedName~HostPath|FullyQualifiedName~RepoHygiene' | |
| build-test-windows: | |
| name: build and platform tests (windows) | |
| runs-on: windows-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0 | |
| with: | |
| dotnet-version: 10.0.x | |
| - run: ./build.ps1 restore CodeyBox.slnx | |
| - run: ./build.ps1 build CodeyBox.slnx --configuration Release --no-restore | |
| - name: platform matrix and path tests | |
| run: ./build.ps1 test tests/CodeyBox.Tests/CodeyBox.Tests.csproj --configuration Release --no-build --filter 'FullyQualifiedName~HostPlatform|FullyQualifiedName~HostPath|FullyQualifiedName~RepoHygiene' | |
| codeql: | |
| name: CodeQL | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| security-events: write | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0 | |
| with: | |
| dotnet-version: 10.0.x | |
| - uses: github/codeql-action/init@5595ccaf912efad79be6eef63a5619ff05969be3 # v4 | |
| with: | |
| languages: csharp | |
| queries: security-extended | |
| - run: dotnet build CodeyBox.slnx --configuration Release | |
| - uses: github/codeql-action/analyze@24c7eb380a2dc368f2d129e4c65e51d172983a1e # v4 | |
| dependency-review: | |
| name: dependency review | |
| # Enable only after GitHub's dependency graph is available for this | |
| # repository. The build job always runs a .NET vulnerability audit; this | |
| # supplemental PR-diff review is enabled with ENABLE_GITHUB_DEPENDENCY_REVIEW. | |
| if: github.event_name == 'pull_request' && vars.ENABLE_GITHUB_DEPENDENCY_REVIEW == 'true' | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: actions/dependency-review-action@cc4f6536e38d1126c5e3b0683d469a14f23bfea4 # v3 | |
| with: | |
| fail-on-severity: moderate | |
| security-scans: | |
| name: secrets, workflow, and filesystem security | |
| runs-on: ubuntu-latest | |
| permissions: | |
| actions: read | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| persist-credentials: false | |
| - name: Scan committed history for secrets | |
| uses: gitleaks/gitleaks-action@e0c47f4f8be36e29cdc102c57e68cb5cbf0e8d1e # v3.0.0 | |
| env: | |
| GITHUB_TOKEN: ${{ github.token }} | |
| - name: Audit GitHub Actions workflows | |
| uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2 | |
| with: | |
| inputs: .github/workflows | |
| collect: workflows | |
| online-audits: false | |
| persona: regular | |
| min-severity: low | |
| min-confidence: medium | |
| version: v1.29.0 | |
| advanced-security: false | |
| annotations: true | |
| - name: Scan filesystem dependencies, misconfiguration, and secrets | |
| run: >- | |
| docker run --rm | |
| --mount type=bind,source="$GITHUB_WORKSPACE",target=/src,readonly | |
| --workdir /src | |
| aquasec/trivy@sha256:16f1ee8462d0ba07dd69239150d60ba7b591c55e02dfc33a3fc19710b861d180 | |
| fs --scanners vuln,misconfig,secret --severity HIGH,CRITICAL --ignore-unfixed --exit-code 1 . |