ci: add OSV-Scanner, license compliance, and semantic PR title guards - #437
Conversation
Reviewer's GuideAdds three CI workflows to enforce supply chain security scanning, license compliance auditing, and semantic PR title conventions, all running on GitHub Actions for pushes and PRs to main (plus a scheduled OSV scan). File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
carlitotate12160-tech has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
Important Review available on request
Reviews should be triggered manually for repositories with fewer than 10 stars. Select Trigger review above or comment ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
PR Summary by QodoCI: add OSV-Scanner, license compliance, and semantic PR title checks
AI Description
Diagram
High-Level Assessment
Files changed (3)
|
There was a problem hiding this comment.
Hey - I've found 1 issue, and left some high level feedback:
- In
semantic-pr.yml, consider whetherpull_request_targetis strictly necessary, as it runs with elevated permissions on code from forks;pull_requestmay be safer if you don’t rely on access to the base repo’s workflow context. - The OSV scanner is configured with
--lockfile=pyproject.toml, which isn’t a conventional lockfile; if you usepoetry.lock,requirements.txt, or another lockfile, explicitly point OSV at that to avoid incomplete dependency coverage. - The allowlist in
license-compliance.ymlis currently hard-coded; consider centralizing or templating the allowed-license configuration so it’s easier to maintain and keeps the workflow focused on execution rather than policy.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments
- In `semantic-pr.yml`, consider whether `pull_request_target` is strictly necessary, as it runs with elevated permissions on code from forks; `pull_request` may be safer if you don’t rely on access to the base repo’s workflow context.
- The OSV scanner is configured with `--lockfile=pyproject.toml`, which isn’t a conventional lockfile; if you use `poetry.lock`, `requirements.txt`, or another lockfile, explicitly point OSV at that to avoid incomplete dependency coverage.
- The allowlist in `license-compliance.yml` is currently hard-coded; consider centralizing or templating the allowed-license configuration so it’s easier to maintain and keeps the workflow focused on execution rather than policy.
## Individual Comments
### Comment 1
<location path=".github/workflows/osv-scanner.yml" line_range="30-31" />
<code_context>
+ with:
+ persist-credentials: false
+
+ - name: Run OSV-Scanner
+ uses: google/osv-scanner-action/osv-scanner-action@v1.9.2
+ with:
+ scan-args: |-
</code_context>
<issue_to_address>
**issue (bug_risk):** OSV scanner action reference looks incorrect and may not resolve to the intended action.
GitHub Actions should be referenced as `owner/repo@version`. For OSV Scanner, the correct identifier is `google/osv-scanner-action@v1.9.2`. The extra `/osv-scanner-action` segment will prevent the workflow from running because GitHub will look for a nested repository that doesn’t exist. Please update the `uses` value accordingly.
</issue_to_address>Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
| - name: Run OSV-Scanner | ||
| uses: google/osv-scanner-action/osv-scanner-action@v1.9.2 |
There was a problem hiding this comment.
issue (bug_risk): OSV scanner action reference looks incorrect and may not resolve to the intended action.
GitHub Actions should be referenced as owner/repo@version. For OSV Scanner, the correct identifier is google/osv-scanner-action@v1.9.2. The extra /osv-scanner-action segment will prevent the workflow from running because GitHub will look for a nested repository that doesn’t exist. Please update the uses value accordingly.
| persist-credentials: false | ||
|
|
||
| - name: Run OSV-Scanner | ||
| uses: google/osv-scanner-action/osv-scanner-action@v1.9.2 |
There was a problem hiding this comment.
3rd party Github Actions should be pinned - high severity
A third-party GitHub Action was imported, and is not pinned via a hash. This leaves your CI/CD at risk for potential supply chain attacks, if the affected GitHub Action is compromised.
| uses: google/osv-scanner-action/osv-scanner-action@v1.9.2 | |
| uses: google/osv-scanner-action/osv-scanner-action@764c91816374ff2d8fc2095dab36eecd42d61638 # v1.9.2 |
Reply @AikidoSec ignore: [REASON] to ignore this issue.
More info
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Validate PR Title Format | ||
| uses: amannn/action-semantic-pull-request@v5 |
There was a problem hiding this comment.
3rd party Github Actions should be pinned - high severity
A third-party GitHub Action was imported, and is not pinned via a hash. This leaves your CI/CD at risk for potential supply chain attacks, if the affected GitHub Action is compromised.
| uses: amannn/action-semantic-pull-request@v5 | |
| uses: amannn/action-semantic-pull-request@e32d7e603df1aa1ba07e981f2a23455dee596825 # v5 |
Reply @AikidoSec ignore: [REASON] to ignore this issue.
More info
Code Review by Qodo
1. Wrong OSV lockfile
|
| name: Semantic PR Linter | ||
|
|
||
| on: | ||
| pull_request_target: |
There was a problem hiding this comment.
1. Non-security semantic pr workflow 📘 Rule violation § Compliance
The new Semantic PR Linter workflow enforces Conventional Commit title formatting, which is not a cybersecurity-focused capability. This violates the requirement that Agent-Alpha changes stay scoped to cybersecurity-related functionality.
Agent Prompt
## Issue description
A new CI workflow (`.github/workflows/semantic-pr.yml`) was added to enforce PR title semantics (Conventional Commits). This is developer governance/formatting rather than cybersecurity functionality, which violates the repo’s scope restriction.
## Issue Context
The PR is intended to add security guards (OSV scanning, license compliance). The semantic PR title linter is orthogonal to those security controls.
## Fix Focus Areas
- .github/workflows/semantic-pr.yml[1-38]
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
| scan-args: |- | ||
| --lockfile=pyproject.toml | ||
| --recursive | ||
| . |
There was a problem hiding this comment.
2. Wrong osv lockfile 🐞 Bug ≡ Correctness
The OSV workflow passes "--lockfile=pyproject.toml", but this repo does not contain a resolved lockfile and pyproject.toml mostly declares unpinned dependencies, so the scan may be ineffective (no concrete versions) or fail depending on OSV-Scanner’s supported lockfile formats.
Agent Prompt
## Issue description
The OSV workflow uses `--lockfile=pyproject.toml`, but `pyproject.toml` is not a resolved lockfile in this repo. This can lead to OSV-Scanner not having concrete versions to assess (or rejecting the input) and therefore not delivering the intended vulnerability coverage.
## Issue Context
- The repo contains `pyproject.toml` (dependency declarations) and `requirements.txt`, but no actual lockfile (e.g., `poetry.lock`, `uv.lock`, `requirements.lock`).
## Fix (recommended)
Choose one of:
1) **Remove the explicit lockfile flag** and rely on recursive scanning of supported manifests/requirements, OR
2) **Point `--lockfile` at an actual resolved input** (e.g., add/commit a lockfile generated from `pyproject.toml` and scan that), OR
3) If `requirements.txt` is intended to be the source of truth, scan it explicitly.
## Fix Focus Areas
- .github/workflows/osv-scanner.yml[30-36]
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
| run: | | ||
| python -m pip install --upgrade pip | ||
| pip install -e . | ||
| pip install pip-licenses |
There was a problem hiding this comment.
3. License audit will drift 🐞 Bug ☼ Reliability
license-compliance installs dependencies on an ephemeral runner via pip install -e ., but most dependencies in pyproject.toml are unpinned, so license results can change over time without code changes and can unexpectedly start failing when upstream releases/metadata change.
Agent Prompt
## Issue description
The license audit workflow resolves dependencies at runtime on a fresh runner (`pip install -e .`). Because the project dependencies are mostly unpinned, the installed dependency graph can change between runs, making compliance results non-reproducible and prone to unexpected failures.
## Issue Context
`pyproject.toml` declares many dependencies without fixed versions, so `pip` will select whatever is current at install time.
## Fix (recommended)
- Introduce and commit a reproducible lock/constraints file for CI compliance checks (e.g., `requirements.lock` generated from `pyproject.toml`), then install from that in the workflow before running `pip-licenses`.
- Alternatively, if `requirements.txt` is intended to be authoritative, expand it to fully capture the dependency set and install from it in the workflow.
## Fix Focus Areas
- .github/workflows/license-compliance.yml[33-41]
- pyproject.toml[5-37]
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
| - name: Validate PR Title Format | ||
| uses: amannn/action-semantic-pull-request@v5 | ||
| env: | ||
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} |
There was a problem hiding this comment.
4. Unpinned third-party actions 🐞 Bug ⛨ Security
The new workflows reference third-party GitHub Actions via mutable tags (e.g., amannn/action-semantic-pull-request@v5, google/osv-scanner-action@v1.9.2), which can change without review and increases CI supply-chain risk.
Agent Prompt
## Issue description
Workflows should reference actions by immutable commit SHA to prevent tag retargeting (supply-chain hardening). This PR introduces new third-party action references via tags.
## Issue Context
`step-security/harden-runner` is already pinned to a commit SHA in the same workflows, indicating an existing hardening pattern.
## Fix
- Replace tagged action refs with commit-SHA-pinned refs, leaving the human-readable version as a comment, e.g.:
- `uses: amannn/action-semantic-pull-request@<sha> # v5.x.x`
- `uses: google/osv-scanner-action/osv-scanner-action@<sha> # v1.9.2`
## Fix Focus Areas
- .github/workflows/semantic-pr.yml[20-23]
- .github/workflows/osv-scanner.yml[20-32]
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
There was a problem hiding this comment.
carlitotate12160-tech has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
Summary
Summary by Sourcery
Add CI safeguards for supply chain security, license compliance, and semantic PR title validation.
CI: