Repository navigation
Fix document evidence validation rejecting exact source quotes #600
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Malicious PR Security Review | |
| on: | |
| pull_request: | |
| branches: | |
| - Development | |
| - paullizer-react-v2-ui # Temporary: remove when paullizer-react-v2-ui merges into Development (#1571) | |
| paths: | |
| - 'application/**' | |
| - 'deployers/**' | |
| - 'docker-customization/**' | |
| - 'scripts/**' | |
| - 'functional_tests/**' | |
| - 'ui_tests/**' | |
| - 'requirements*.txt' | |
| - '**/requirements*.txt' | |
| - '**/package.json' | |
| - '**/package-lock.json' | |
| - '**/npm-shrinkwrap.json' | |
| - '**/pnpm-lock.yaml' | |
| - '**/yarn.lock' | |
| - '**/pyproject.toml' | |
| - '**/poetry.lock' | |
| - '**/Pipfile' | |
| - '**/Pipfile.lock' | |
| - '**/Dockerfile' | |
| - '.github/workflows/**' | |
| - '.github/prompts/**' | |
| - '.github/instructions/**' | |
| - 'docs/**' | |
| workflow_dispatch: | |
| inputs: | |
| base_ref: | |
| description: 'Base ref or SHA for the review range' | |
| required: true | |
| default: 'Development' | |
| head_ref: | |
| description: 'Head ref or SHA for the review range. Defaults to the workflow SHA.' | |
| required: false | |
| default: '' | |
| full_file_scan: | |
| description: 'Scan full changed files instead of only changed lines' | |
| type: boolean | |
| required: false | |
| default: false | |
| verify_release_age: | |
| description: 'Query PyPI/npm metadata for the seven-day dependency gate' | |
| type: boolean | |
| required: false | |
| default: true | |
| fail_on_findings: | |
| description: 'Fail on all findings instead of only blockers' | |
| type: boolean | |
| required: false | |
| default: false | |
| fail_on_unverified_release_age: | |
| description: 'Fail when dependency release age cannot be verified' | |
| type: boolean | |
| required: false | |
| default: false | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| jobs: | |
| malicious-pr-security-review: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - name: Set up Python | |
| uses: actions/setup-python@v7 | |
| with: | |
| python-version: '3.12' | |
| - name: Resolve review range | |
| id: review-range | |
| shell: bash | |
| run: | | |
| if [[ "${{ github.event_name }}" == "pull_request" ]]; then | |
| echo "base_sha=${{ github.event.pull_request.base.sha }}" >> "$GITHUB_OUTPUT" | |
| echo "head_sha=${{ github.sha }}" >> "$GITHUB_OUTPUT" | |
| exit 0 | |
| fi | |
| git fetch --all --prune | |
| base_ref="${{ inputs.base_ref }}" | |
| head_ref="${{ inputs.head_ref }}" | |
| if [[ -z "$head_ref" ]]; then | |
| head_ref="${{ github.sha }}" | |
| fi | |
| base_sha="$(git rev-parse "origin/${base_ref}^{commit}" 2>/dev/null || git rev-parse "${base_ref}^{commit}")" | |
| head_sha="$(git rev-parse "${head_ref}^{commit}")" | |
| echo "base_sha=$base_sha" >> "$GITHUB_OUTPUT" | |
| echo "head_sha=$head_sha" >> "$GITHUB_OUTPUT" | |
| - name: Run malicious PR static security review | |
| env: | |
| BASE_SHA: ${{ steps.review-range.outputs.base_sha }} | |
| HEAD_SHA: ${{ steps.review-range.outputs.head_sha }} | |
| run: | | |
| review_args=( | |
| --base-sha "$BASE_SHA" | |
| --head-sha "$HEAD_SHA" | |
| --report-file artifacts/malicious-pr-security-review.md | |
| ) | |
| if [[ "${{ github.event_name }}" == "workflow_dispatch" && "${{ inputs.full_file_scan }}" == "true" ]]; then | |
| review_args+=(--full-file) | |
| fi | |
| if [[ "${{ github.event_name }}" != "workflow_dispatch" || "${{ inputs.verify_release_age }}" == "true" ]]; then | |
| review_args+=(--verify-release-age) | |
| fi | |
| if [[ "${{ github.event_name }}" == "workflow_dispatch" && "${{ inputs.fail_on_findings }}" == "true" ]]; then | |
| review_args+=(--fail-on-findings) | |
| fi | |
| if [[ "${{ github.event_name }}" == "workflow_dispatch" && "${{ inputs.fail_on_unverified_release_age }}" == "true" ]]; then | |
| review_args+=(--fail-on-unverified-release-age) | |
| fi | |
| python scripts/check_malicious_pr_security_review.py "${review_args[@]}" | |
| - name: Publish review summary | |
| if: always() | |
| run: | | |
| if [[ -f artifacts/malicious-pr-security-review.md ]]; then | |
| cat artifacts/malicious-pr-security-review.md >> "$GITHUB_STEP_SUMMARY" | |
| else | |
| echo "Malicious PR security review report was not created." >> "$GITHUB_STEP_SUMMARY" | |
| fi | |
| - name: Upload review report | |
| if: always() | |
| uses: actions/upload-artifact@v7 | |
| with: | |
| name: malicious-pr-security-review | |
| path: artifacts/malicious-pr-security-review.md | |
| if-no-files-found: warn |