feat: Add security-gates and update README - #1304
emrecanvurallll wants to merge 3 commits into
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
📝 WalkthroughWalkthroughThe pull request adds a GitHub Actions security-gates workflow for pushes and pull requests to ChangesSecurity posture
Estimated code review effort: 2 (Simple) | ~10 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🧹 Nitpick comments (1)
.github/workflows/security-gates.yml (1)
13-14: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick winReplace the no-op validation step.
Validate Workflowonly prints a message and always succeeds. It does not validate the workflow or the reusable workflow contract. If branch protection requires this check, it can report success without performing validation. Add a real workflow/schema check or remove the job.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/security-gates.yml around lines 13 - 14, Replace the no-op run command in the “Validate Workflow” step with an actual GitHub Actions workflow/schema validation that verifies the workflow and reusable workflow contract, or remove the validation job if no suitable check is available; do not leave a command that merely prints success.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/security-gates.yml:
- Line 22: Replace the `secrets: inherit` directive in the security-gates.yml
workflow with an explicit mapping that lists only the specific secrets required
by the Trendyol/security-actions reusable workflow, or remove the secrets
directive entirely if that workflow does not require any secrets. This prevents
unnecessary exposure of all caller secrets to the reusable workflow that
processes pull request code.
---
Nitpick comments:
In @.github/workflows/security-gates.yml:
- Around line 13-14: Replace the no-op run command in the “Validate Workflow”
step with an actual GitHub Actions workflow/schema validation that verifies the
workflow and reusable workflow contract, or remove the validation job if no
suitable check is available; do not leave a command that merely prints success.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: a0baf8a0-6f75-4ec9-9fb4-a7ca70ad43b1
📒 Files selected for processing (2)
.github/workflows/security-gates.ymlREADME.md
| actions: read | ||
| contents: read | ||
| security-events: write | ||
| secrets: inherit |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo "== workflow file =="
if [ -f .github/workflows/security-gates.yml ]; then
nl -ba .github/workflows/security-gates.yml | sed -n '1,120p'
else
echo "missing .github/workflows/security-gates.yml"
fi
echo
echo "== workflow refs to security-actions =="
rg -n "Trendyol/security-actions|security-actions|secrets:" .github/workflows || true
echo
echo "== workflow triggers summary =="
python3 - <<'PY'
from pathlib import Path
p=Path('.github/workflows/security-gates.yml')
if p.exists():
text=p.read_text()
for line in text.splitlines():
if ('pull_request' in line or 'pull_request' in text) and not line.strip().startswith('#'):
print(line)
PYRepository: Trendyol/stove
Length of output: 1914
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo "== repository existence =="
git ls-files .github/workflows/security-gates.yml
echo
echo "== relevant workflow file =="
nl -ba .github/workflows/security-gates.yml | sed -n '1,140p'
echo
echo "== references to Trendyol/security-actions =="
rg -n "Trendyol/security-actions|uses: Trendyol|pull_request|workflow_call|secrets: inherit|secrets:" .github/workflows || trueRepository: Trendyol/stove
Length of output: 1914
🌐 Web query:
Trendyol security-actions repository main branch
💡 Result:
The Trendyol/security-actions repository on GitHub uses master as its default branch [1]. While the repository does not maintain a main branch, it is a common practice for other repositories within the Trendyol organization to reference this repository's workflows using the master tag (e.g., using @master in reusable workflow configurations) [1][2][3][4]. There is no official evidence of a main branch existing in the Trendyol/security-actions repository [1].
Citations:
- 1: https://github.com/Trendyol/security-actions
- 2: https://github.com/Trendyol/gurubu/blob/main/.github/workflows/security-gates.yml
- 3: Trendyol/android-dev-tools@develop...add-security-gates-latest
- 4: https://github.com/Trendyol/nest-swagger-checker-lint/blob/master/.github/workflows/security-gates.yml
🌐 Web query:
Trendyol/security-actions call.yml pull_request secrets inherit
💡 Result:
The secrets: inherit keyword in GitHub Actions is a configuration option used when calling reusable workflows to implicitly pass all secrets from the caller workflow to the called (reusable) workflow [1][2]. Regarding the Trendyol/security-actions repository specifically, while some internal Trendyol project configurations have used secrets: inherit when calling security-gates.yml [3], it is not a mandatory or hardcoded requirement for the action itself. The action is designed to be called as a reusable workflow [4][5], and users may choose to pass secrets implicitly via inherit or explicitly by mapping specific secrets [6][1][7]. Security best practices generally advise against using secrets: inherit because it violates the principle of least privilege [8][7][9][10]. By passing all available secrets, the downstream workflow gains access to credentials it may not actually need, increasing the blast radius if that workflow is compromised [8][7][10]. Many security tools and linters, such as OpenRewrite [10], zizmor, and others [7][9], now flag secrets: inherit as a security risk and recommend explicit secret mapping instead [8][7][10]. If you are implementing this, you should evaluate whether your security gates truly require access to all of your repository's secrets; if they do not, it is safer to explicitly pass only the required ones using the secrets: mapping block [6][8][7].
Citations:
- 1: https://docs.github.com/en/actions/how-tos/reuse-automations/reuse-workflows
- 2: https://github.blog/changelog/2022-05-03-github-actions-simplify-using-secrets-with-reusable-workflows/
- 3: Trendyol/android-dev-tools@develop...add-security-gates-latest
- 4: https://github.com/Trendyol/security-actions
- 5: https://github.com/Trendyol/gurubu/blob/main/.github/workflows/security-gates.yml
- 6: https://sadamkhan.spiralsync.com/blog/quick-tips/github-actions-reusable-workflows
- 7: https://actsense.dev/vulnerabilities/secrets_inherit/
- 8: fix: replace secrets: inherit with explicit secret mappings in CI/CD workflows nhs-england-tools/repository-template#213
- 9: https://earthly.dev/lunar/guardrails/github-actions/no-secrets-inherit/
- 10: https://docs.openrewrite.org/recipes/github/security/secretsinherit
Pass only the secrets required by Trendyol/security-actions.
secrets: inherit includes every caller secret when the reusable workflow runs. This workflow is triggered by pull requests, so inherited secrets may become available to a called workflow that processes PR code. Set secrets: to an explicit mapping with only required secrets, or remove it if no secret is needed.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/security-gates.yml at line 22, Replace the `secrets:
inherit` directive in the security-gates.yml workflow with an explicit mapping
that lists only the specific secrets required by the Trendyol/security-actions
reusable workflow, or remove the secrets directive entirely if that workflow
does not require any secrets. This prevents unnecessary exposure of all caller
secrets to the reusable workflow that processes pull request code.
Source: Linters/SAST tools
This PR adds security-gates workflow and updates README with OpenSSF Scorecard badge.
Summary by CodeRabbit