Skip to content

feat: Add security-gates and update README - #1304

Closed
emrecanvurallll wants to merge 3 commits into
mainfrom
add-security-gates-latest
Closed

emrecanvurallll wants to merge 3 commits into
mainfrom
add-security-gates-latest

Conversation

@emrecanvurallll

@emrecanvurallll emrecanvurallll commented Jul 31, 2026 •

Copy link
Copy Markdown
Contributor

This PR adds security-gates workflow and updates README with OpenSSF Scorecard badge.

Summary by CodeRabbit

  • New Features
    • Added automated security checks for changes targeting the main development branches.
    • Added an OpenSSF Scorecard badge to provide visibility into the project’s security practices.

Comment thread .github/workflows/security-gates.yml Dismissed
Comment thread .github/workflows/security-gates.yml Dismissed
Comment thread .github/workflows/security-gates.yml Dismissed
@coderabbitai

coderabbitai Bot commented Jul 31, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 235fec08-ab2d-423f-9497-f8d8aa41d9a9

📥 Commits

Reviewing files that changed from the base of the PR and between 7ba494b and f60c24f.

📒 Files selected for processing (1)
  • README.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • README.md

📝 Walkthrough

Walkthrough

The pull request adds a GitHub Actions security-gates workflow for pushes and pull requests to main or master. It also adds an OpenSSF Scorecard badge to the README.

Changes

Security posture

Layer / File(s) Summary
Security gates workflow
.github/workflows/security-gates.yml
Adds branch-specific push and pull-request triggers, a validation job, and a reusable security-gates job with inherited secrets and read/write security permissions.
Scorecard badge
README.md
Adds an OpenSSF Scorecard badge and link before the existing centered logo.

Estimated code review effort: 2 (Simple) | ~10 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely summarizes the security-gates workflow and README update.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch add-security-gates-latest

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
.github/workflows/security-gates.yml (1)

13-14: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win

Replace the no-op validation step.

Validate Workflow only prints a message and always succeeds. It does not validate the workflow or the reusable workflow contract. If branch protection requires this check, it can report success without performing validation. Add a real workflow/schema check or remove the job.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/security-gates.yml around lines 13 - 14, Replace the no-op
run command in the “Validate Workflow” step with an actual GitHub Actions
workflow/schema validation that verifies the workflow and reusable workflow
contract, or remove the validation job if no suitable check is available; do not
leave a command that merely prints success.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/security-gates.yml:
- Line 22: Replace the `secrets: inherit` directive in the security-gates.yml
workflow with an explicit mapping that lists only the specific secrets required
by the Trendyol/security-actions reusable workflow, or remove the secrets
directive entirely if that workflow does not require any secrets. This prevents
unnecessary exposure of all caller secrets to the reusable workflow that
processes pull request code.

---

Nitpick comments:
In @.github/workflows/security-gates.yml:
- Around line 13-14: Replace the no-op run command in the “Validate Workflow”
step with an actual GitHub Actions workflow/schema validation that verifies the
workflow and reusable workflow contract, or remove the validation job if no
suitable check is available; do not leave a command that merely prints success.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: a0baf8a0-6f75-4ec9-9fb4-a7ca70ad43b1

📥 Commits

Reviewing files that changed from the base of the PR and between 672f5a4 and 7ba494b.

📒 Files selected for processing (2)
  • .github/workflows/security-gates.yml
  • README.md

actions: read
contents: read
security-events: write
secrets: inherit

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== workflow file =="
if [ -f .github/workflows/security-gates.yml ]; then
  nl -ba .github/workflows/security-gates.yml | sed -n '1,120p'
else
  echo "missing .github/workflows/security-gates.yml"
fi

echo
echo "== workflow refs to security-actions =="
rg -n "Trendyol/security-actions|security-actions|secrets:" .github/workflows || true

echo
echo "== workflow triggers summary =="
python3 - <<'PY'
from pathlib import Path
p=Path('.github/workflows/security-gates.yml')
if p.exists():
    text=p.read_text()
    for line in text.splitlines():
        if ('pull_request' in line or 'pull_request' in text) and not line.strip().startswith('#'):
            print(line)
PY

Repository: Trendyol/stove

Length of output: 1914


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== repository existence =="
git ls-files .github/workflows/security-gates.yml

echo
echo "== relevant workflow file =="
nl -ba .github/workflows/security-gates.yml | sed -n '1,140p'

echo
echo "== references to Trendyol/security-actions =="
rg -n "Trendyol/security-actions|uses: Trendyol|pull_request|workflow_call|secrets: inherit|secrets:" .github/workflows || true

Repository: Trendyol/stove

Length of output: 1914


🌐 Web query:

Trendyol security-actions repository main branch

💡 Result:

The Trendyol/security-actions repository on GitHub uses master as its default branch [1]. While the repository does not maintain a main branch, it is a common practice for other repositories within the Trendyol organization to reference this repository's workflows using the master tag (e.g., using @master in reusable workflow configurations) [1][2][3][4]. There is no official evidence of a main branch existing in the Trendyol/security-actions repository [1].

Citations:


🌐 Web query:

Trendyol/security-actions call.yml pull_request secrets inherit

💡 Result:

The secrets: inherit keyword in GitHub Actions is a configuration option used when calling reusable workflows to implicitly pass all secrets from the caller workflow to the called (reusable) workflow [1][2]. Regarding the Trendyol/security-actions repository specifically, while some internal Trendyol project configurations have used secrets: inherit when calling security-gates.yml [3], it is not a mandatory or hardcoded requirement for the action itself. The action is designed to be called as a reusable workflow [4][5], and users may choose to pass secrets implicitly via inherit or explicitly by mapping specific secrets [6][1][7]. Security best practices generally advise against using secrets: inherit because it violates the principle of least privilege [8][7][9][10]. By passing all available secrets, the downstream workflow gains access to credentials it may not actually need, increasing the blast radius if that workflow is compromised [8][7][10]. Many security tools and linters, such as OpenRewrite [10], zizmor, and others [7][9], now flag secrets: inherit as a security risk and recommend explicit secret mapping instead [8][7][10]. If you are implementing this, you should evaluate whether your security gates truly require access to all of your repository's secrets; if they do not, it is safer to explicitly pass only the required ones using the secrets: mapping block [6][8][7].

Citations:


Pass only the secrets required by Trendyol/security-actions.

secrets: inherit includes every caller secret when the reusable workflow runs. This workflow is triggered by pull requests, so inherited secrets may become available to a called workflow that processes PR code. Set secrets: to an explicit mapping with only required secrets, or remove it if no secret is needed.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/security-gates.yml at line 22, Replace the `secrets:
inherit` directive in the security-gates.yml workflow with an explicit mapping
that lists only the specific secrets required by the Trendyol/security-actions
reusable workflow, or remove the secrets directive entirely if that workflow
does not require any secrets. This prevents unnecessary exposure of all caller
secrets to the reusable workflow that processes pull request code.

Source: Linters/SAST tools

@osoykan osoykan closed this Jul 31, 2026
@osoykan
osoykan deleted the add-security-gates-latest branch July 31, 2026 08:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants