Skip to content

Auditor plugin: Psalm (lint) — PHP analysis #493

Auditor plugin: Psalm (lint) — PHP analysis

Auditor plugin: Psalm (lint) — PHP analysis #493

Workflow file for this run

name: CI
on:
pull_request:
branches: [main]
push:
branches: [main]
schedule:
- cron: '23 4 * * 1'
workflow_dispatch: {}
permissions: {}
concurrency:
group: codeybox-ci-${{ github.ref }}
cancel-in-progress: true
jobs:
build-test:
name: build and deterministic tests
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with:
dotnet-version: 10.0.x
- run: dotnet restore CodeyBox.slnx
- run: dotnet build CodeyBox.slnx --configuration Release --no-restore
- name: deterministic tests
run: dotnet test tests/CodeyBox.Tests/CodeyBox.Tests.csproj --configuration Release --no-build --filter 'requires_multipass!=true'
- name: admin tests
run: dotnet test tools/CodeyBox.Admin/tests/CodeyBox.Admin.Tests/CodeyBox.Admin.Tests.csproj --configuration Release --no-build
- name: dependency vulnerability audit
run: dotnet list CodeyBox.slnx package --vulnerable --include-transitive
# Non-Linux hosts support only the remote-executor topology
# (docs/concepts/host-platforms.md): no local VM providers, no nftables.
# These jobs prove the declared scope — the orchestrator builds and the
# platform-matrix/path tests pass — without claiming isolation that has
# not been exercised on these hosts.
build-test-macos:
name: build and platform tests (macos)
runs-on: macos-latest
permissions:
contents: read
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with:
dotnet-version: 10.0.x
- run: dotnet restore CodeyBox.slnx
- run: dotnet build CodeyBox.slnx --configuration Release --no-restore
- name: platform matrix and path tests
run: dotnet test tests/CodeyBox.Tests/CodeyBox.Tests.csproj --configuration Release --no-build --filter 'FullyQualifiedName~HostPlatform|FullyQualifiedName~HostPath|FullyQualifiedName~RepoHygiene'
build-test-windows:
name: build and platform tests (windows)
runs-on: windows-latest
permissions:
contents: read
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with:
dotnet-version: 10.0.x
- run: ./build.ps1 restore CodeyBox.slnx
- run: ./build.ps1 build CodeyBox.slnx --configuration Release --no-restore
- name: platform matrix and path tests
run: ./build.ps1 test tests/CodeyBox.Tests/CodeyBox.Tests.csproj --configuration Release --no-build --filter 'FullyQualifiedName~HostPlatform|FullyQualifiedName~HostPath|FullyQualifiedName~RepoHygiene'
codeql:
name: CodeQL
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with:
dotnet-version: 10.0.x
- uses: github/codeql-action/init@5595ccaf912efad79be6eef63a5619ff05969be3 # v4
with:
languages: csharp
queries: security-extended
- run: dotnet build CodeyBox.slnx --configuration Release
- uses: github/codeql-action/analyze@24c7eb380a2dc368f2d129e4c65e51d172983a1e # v4
dependency-review:
name: dependency review
# Enable only after GitHub's dependency graph is available for this
# repository. The build job always runs a .NET vulnerability audit; this
# supplemental PR-diff review is enabled with ENABLE_GITHUB_DEPENDENCY_REVIEW.
if: github.event_name == 'pull_request' && vars.ENABLE_GITHUB_DEPENDENCY_REVIEW == 'true'
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/dependency-review-action@cc4f6536e38d1126c5e3b0683d469a14f23bfea4 # v3
with:
fail-on-severity: moderate
security-scans:
name: secrets, workflow, and filesystem security
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- name: Scan committed history for secrets
uses: gitleaks/gitleaks-action@e0c47f4f8be36e29cdc102c57e68cb5cbf0e8d1e # v3.0.0
env:
GITHUB_TOKEN: ${{ github.token }}
- name: Audit GitHub Actions workflows
uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2
with:
inputs: .github/workflows
collect: workflows
online-audits: false
persona: regular
min-severity: low
min-confidence: medium
version: v1.29.0
advanced-security: false
annotations: true
- name: Scan filesystem dependencies, misconfiguration, and secrets
run: >-
docker run --rm
--mount type=bind,source="$GITHUB_WORKSPACE",target=/src,readonly
--workdir /src
aquasec/trivy@sha256:16f1ee8462d0ba07dd69239150d60ba7b591c55e02dfc33a3fc19710b861d180
fs --scanners vuln,misconfig,secret --severity HIGH,CRITICAL --ignore-unfixed --exit-code 1 .