Skip to content

ci: 🎡 CI/CD、自動化、セキュリティおよび品質チェック設定の統一 - #55

Merged
genzouw merged 10 commits into
mainfrom
feature/ci-cd-and-security-alignment
May 21, 2026
Merged

genzouw merged 10 commits into
mainfrom
feature/ci-cd-and-security-alignment

Conversation

@genzouw

@genzouw genzouw commented May 21, 2026 •

Copy link
Copy Markdown
Owner

概要

本リポジトリに、genzouwオーナーのパブリックリポジトリ共通の最新CI/CDパイプライン、自動化ツール、SaaS連携、およびセキュリティスキャン設定を導入します。

導入される内容

  • 静的セキュリティスキャン:
    • CodeQLによる高度なソースコードセキュリティ脆弱性スキャン。
    • Gitleaksによるコミット履歴・PR上の機密情報(APIキー、シークレット)漏洩検知。
    • Trivyによるファイルシステムや構成ミス、既知の脆弱性スキャン。
  • 自動化・品質管理:
    • CodeRabbitによる日本語でのAIパワードPR自動レビュー。
    • ActionlintによるGitHub Actionsワークフローファイルの構文・静的解析チェック。
    • Markdownlintによるマークダウンドキュメントの品質・書式チェック。
    • 競合検知時の自動通知通知(pr_conflict_notify)。
    • Stale Issue / PR管理の自動化。
  • 共通フォーマット・ドキュメントテンプレート:
    • Prettierによる統一コードスタイル。
    • PR作成時にセルフチェックを促すPRテンプレート(PULL_REQUEST_TEMPLATE.md)。

Summary by CodeRabbit

  • Chores
    • CI/CD強化:定期セキュリティスキャン・ワークフローを追加/更新、依存アクション参照を更新
    • PR管理改善:自動コンフリクト通知と自動staleクローズを導入
    • 開発環境強化:コミットメッセージ検査・コミット前フック・フォーマット/リンター実行を追加
  • Configuration
    • レビュー設定を厳格化:言語設定・レビュープロファイル・パス別レビュー指針と除外ルールを整理
  • Docs
    • PRテンプレートを再構成し、デプロイ注意やセルフチェックを明確化
  • Style
    • フォーマット設定と一部スタイル記法を整備

Review Change Stack

## Summary

- パブリックリポジトリ共通の最新のCI/CDパイプライン、自動化ツール、SaaS連携、セキュリティスキャン設定を導入。
- CodeQL(高度なコード脆弱性スキャン)ワークフローを追加。
- Gitleaks(シークレット漏洩防止スキャン)ワークフローを追加。
- Trivy(FS脆弱性・設定不備スキャン)ワークフローを追加。
- Actionlint、Markdownlint、Stale Issue/PR管理、PR競合自動通知などの自動化設定を追加。
- CodeRabbit(AI PR日本語自動レビュー)設定を追加。
- 共通コードフォーマット(Prettier)およびドキュメント品質用のルールを追加。
- 開発時・PR時のセルフチェックを促すPRテンプレート(PULL_REQUEST_TEMPLATE.md)を導入。
@gemini-code-assist

Copy link
Copy Markdown

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

本プルリクエストは、リポジトリ全体の CI/CD パイプライン、自動化ツール、およびセキュリティ設定を包括的に刷新・統一するものです。開発からデプロイに至るまでのプロセスを自動化し、セキュリティ脆弱性や機密情報の漏洩を未然に防ぐための堅牢な基盤を構築することを目的としています。

Highlights

  • CI/CD パイプラインの強化: CodeQL、Gitleaks、Trivy などのセキュリティスキャンツールを導入し、開発環境の安全性を向上させました。
  • 自動化と品質管理の導入: CodeRabbit による自動レビュー、Actionlint、Markdownlint、および Husky を活用したコミット前チェックを実装し、コード品質の維持を自動化しました。
  • 開発プロセスの標準化: Prettier によるコードフォーマットの統一と、詳細な PR テンプレートの導入により、開発者間の作業効率とレビューの質を向上させました。
Ignored Files
  • Ignored by pattern: .github/workflows/** (7)
    • .github/workflows/actionlint.yml
    • .github/workflows/codeql.yml
    • .github/workflows/gitleaks.yml
    • .github/workflows/markdownlint.yml
    • .github/workflows/pr_conflict_notify.yml
    • .github/workflows/stale.yml
    • .github/workflows/trivy.yml
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@coderabbitai

coderabbitai Bot commented May 21, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 74343548-5ab9-4364-ac0b-8d44606bd912

📥 Commits

Reviewing files that changed from the base of the PR and between 8c2a1b0 and 0f37d78.

📒 Files selected for processing (1)
  • .husky/pre-commit

📝 Walkthrough

Walkthrough

リポジトリのレビュー方針(CodeRabbit)、PR テンプレート、複数の GitHub Actions ワークフロー追加・更新、Husky フック、および lint/format/devDependencies を一括で整備する変更です。

Changes

リポジトリ設定・CI 整備

Layer / File(s) Summary
CodeRabbit レビュー設定
.coderabbit.yaml
language を 'ja-JP' に変更、reviews.profile を 'assertive' に切替。reviews.instructions と path_instructions を追加し、path_filters の全体指定を削除して除外パターンを整理。
PR テンプレート再構成
.github/PULL_REQUEST_TEMPLATE.md
PR テンプレートを再構成し「関連 Issue / 設計ドキュメント」「セルフチェック」「デプロイ時の注意」などのセクションを追加・更新。セルフチェックに npm run lint と npm run format:check を明記。
既存ワークフロー更新と新規ワークフロー追加
.github/workflows/*
actionlint/codeql/gitleaks/markdownlint の uses やステップを更新。pr_conflict_notify(PR 競合検出・通知)、stale(古い PR 自動ラベル/クローズ)、trivy(FS スキャン・SARIF アップロード)を追加。
Husky git フック設定
.husky/commit-msg, .husky/pre-commit
commit-msg で npx commitlint --edit 実行、pre-commit で gitleaks(存在時)を用いた秘密スキャン、npm run format:check、npm run lint を実行。
コード品質設定・依存追加
.markdownlint-cli2.jsonc, .prettierrc, package.json, style.css
markdownlint の ignores とルール説明を整理、Prettier 設定を追加、@commitlint/cli と @commitlint/config-conventional を devDependencies に追加。CSS の引用符スタイルを統一。

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed プルリクエストのタイトルは「ci: 🎡 CI/CD、自動化、セキュリティおよび品質チェック設定の統一」であり、ファイル変更の主要な内容(CI/CD パイプライン、セキュリティスキャン、自動化ツール、品質チェック設定の統一)を的確に要約しています。
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feature/ci-cd-and-security-alignment

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

このプルリクエストは、CodeRabbitの設定変更、プルリクエストテンプレートの更新、Huskyによるコミットフック(commitlint、lint-staged、gitleaks)の導入、およびPrettierとmarkdownlintの設定追加を行っています。レビューでは、追加された設定やスクリプトがプロジェクトの実態(vanilla JS、単一パッケージ構成、npm使用)と乖離しており、backend/frontendディレクトリやBun、Hono、Reactなどの存在しない環境を前提としている点が複数指摘されました。また、commitlintの依存関係への追加漏れや、markdownlint設定におけるパス指定の重複についても改善が求められています。

Comment thread .husky/commit-msg
Comment thread .husky/pre-commit Outdated
Comment thread .coderabbit.yaml Outdated
Comment thread .github/PULL_REQUEST_TEMPLATE.md Outdated
Comment thread .markdownlint-cli2.jsonc Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/codeql.yml:
- Around line 5-10: Prettier is failing due to array spacing in the workflow
YAML; update the array notation for the branches keys and any other arrays
(e.g., the top-level branches, pull_request.branches and schedule entries) to
match the project's Prettier style (remove or add spaces around bracketed arrays
so they match other files), then run prettier --check to confirm the file (keys:
branches and pull_request.branches and schedule) now passes.

In @.github/workflows/pr_conflict_notify.yml:
- Around line 3-12: Add a top-level concurrency stanza to the workflow to
prevent simultaneous runs from schedule/push/workflow_dispatch colliding;
specifically, add a concurrency block (e.g., group: "pr-conflict-notify" and
cancel-in-progress: true) at the root of the workflow so runs share the same
concurrency group and in-progress runs are cancelled when a new run starts,
referencing the existing triggers (schedule, push, workflow_dispatch) so this
behaviour applies to those events.
- Around line 13-16: The workflow's top-level permissions are too broad—replace
the global pull-requests: write with pull-requests: read and add issues: write
only to the job(s) that post/update/delete comments; specifically, change the
top-level permissions block to minimal read-only (contents: read, pull-requests:
read) and then add issues: write to the job(s) that call
listComments/createComment/updateComment/deleteComment so only those jobs get
comment-writing rights; update any job-level permissions blocks accordingly to
keep least privilege.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 856c666f-1d86-4ca4-a4ed-2c5245a25319

📥 Commits

Reviewing files that changed from the base of the PR and between a9d43d7 and f0c4504.

📒 Files selected for processing (13)
  • .coderabbit.yaml
  • .github/PULL_REQUEST_TEMPLATE.md
  • .github/workflows/actionlint.yml
  • .github/workflows/codeql.yml
  • .github/workflows/gitleaks.yml
  • .github/workflows/markdownlint.yml
  • .github/workflows/pr_conflict_notify.yml
  • .github/workflows/stale.yml
  • .github/workflows/trivy.yml
  • .husky/commit-msg
  • .husky/pre-commit
  • .markdownlint-cli2.jsonc
  • .prettierrc

Comment thread .github/workflows/codeql.yml Outdated
Comment thread .github/workflows/pr_conflict_notify.yml
Comment thread .github/workflows/pr_conflict_notify.yml
@genzouw
genzouw enabled auto-merge (squash) May 21, 2026 08:18
genzouw added 7 commits May 21, 2026 17:19
.husky/commit-msg で実行される `npx commitlint` 用に、@commitlint/cli と
@commitlint/config-conventional をプロジェクトの devDependencies に追加した。
これにより npx が都度ダウンロードを試みることがなくなり、commit-msg フックの
実行が安定する。

レビューコメント: #55 (comment)
レビュアー: gemini-code-assist
優先度: high
本プロジェクトは vanilla JS の単一パッケージ構成のため、以下を修正した:

- 未インストールの lint-staged 呼び出しを削除
- 存在しない backend/ frontend/ ディレクトリ向けの typecheck/test 実行ブロックを削除
- ルートで定義済みの npm run format:check と npm run lint を実行するよう変更

これにより pre-commit フックが現状の package.json と整合して動作する。

レビューコメント: #55 (comment)
レビュアー: gemini-code-assist
優先度: high
本プロジェクトは vanilla JS (ES modules) の単一構成であり、Hono / Better Auth /
Drizzle / React / backend / frontend / db といったディレクトリや技術スタックは
存在しない。CodeRabbit が誤った前提でレビューしないよう、該当する
path_instructions を削除し、代わりに js/ 配下に対するクライアントコード向け
レビュー指示を追加した。

レビューコメント: #55 (comment)
レビュアー: gemini-code-assist
優先度: medium
本プロジェクトは npm を使用する単一パッケージ構成のため、bun および
backend/frontend ディレクトリを前提とした項目を実態に合わせて修正した:

- bun --cwd backend/frontend run lint → npm run lint
- typecheck 行は本プロジェクトに該当スクリプトが無いため format:check に置換
- DB マイグレーション項目は本プロジェクトに DB が無いため削除

レビューコメント: #55 (comment)
レビュアー: gemini-code-assist
優先度: medium
**/node_modules/** はルートを含むあらゆる階層の node_modules にマッチするため、
ルート専用の node_modules/** は冗長だった。重複を解消するため削除した。

レビューコメント: #55 (comment)
レビュアー: gemini-code-assist
優先度: low
prettier --check で失敗していた配列のブラケット内スペースを除去した。
- branches: [ "main" ] → branches: [main]
- language: [ 'javascript-typescript' ] → language: ['javascript-typescript']
併せて Prettier の自動整形により、quote / インデント / step ハイフン位置が
プロジェクト標準に揃った。

レビューコメント: #55 (comment)
レビュアー: coderabbitai
優先度: low
- schedule / push / workflow_dispatch の同時実行による PR コメント更新の競合を
  防ぐため、workflow レベルに concurrency stanza を追加した。
- 本ワークフローは Issues API (createComment / updateComment / deleteComment)
  でコメントを操作しているため、workflow レベルでは pull-requests: read のみと
  し、job レベルに issues: write を付与する最小権限構成に変更した。

レビューコメント: #55 (comment)
レビュアー: coderabbitai
優先度: medium

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

♻️ Duplicate comments (1)
.github/workflows/pr_conflict_notify.yml (1)

13-15: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

concurrency.group は固定値にしてください。

${{ github.ref }} だと別ブランチからの workflow_dispatch が main の定期実行/Push 実行と並走できます。この workflow は全 open PR のコメントを横断更新するので、ref 単位ではまだ競合が残ります。

🔧 提案差分
 concurrency:
-  group: pr-conflict-notify-${{ github.ref }}
+  group: pr-conflict-notify
   cancel-in-progress: true
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/pr_conflict_notify.yml around lines 13 - 15,
concurrency.group currently uses a dynamic key (pr-conflict-notify-${{
github.ref }}), which allows runs from different refs to run concurrently;
change it to a fixed value such as "pr-conflict-notify" so all invocations
serialize across branches; keep cancel-in-progress: true and leave the group
name as the unique identifier "pr-conflict-notify" referenced in this workflow
to ensure only one instance runs at a time (covers workflow_dispatch and
scheduled/push runs).
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.husky/pre-commit:
- Around line 9-15: The pre-commit hook (.husky/pre-commit) does not propagate
failures from the invoked commands so a failing npm run format:check can be
ignored; fix by making the hook fail-fast (e.g., add set -e at the top of the
script or append || exit 1 to each command) so that npm run format:check and npm
run lint failures immediately stop the hook; update the script around the npm
run format:check and npm run lint invocations to ensure errors are propagated.

---

Duplicate comments:
In @.github/workflows/pr_conflict_notify.yml:
- Around line 13-15: concurrency.group currently uses a dynamic key
(pr-conflict-notify-${{ github.ref }}), which allows runs from different refs to
run concurrently; change it to a fixed value such as "pr-conflict-notify" so all
invocations serialize across branches; keep cancel-in-progress: true and leave
the group name as the unique identifier "pr-conflict-notify" referenced in this
workflow to ensure only one instance runs at a time (covers workflow_dispatch
and scheduled/push runs).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 7d29664f-cf2d-465c-b3b2-4e3fa8bf5c57

📥 Commits

Reviewing files that changed from the base of the PR and between f0c4504 and 61fc25b.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json, !**/package-lock.json
📒 Files selected for processing (7)
  • .coderabbit.yaml
  • .github/PULL_REQUEST_TEMPLATE.md
  • .github/workflows/codeql.yml
  • .github/workflows/pr_conflict_notify.yml
  • .husky/pre-commit
  • .markdownlint-cli2.jsonc
  • package.json
💤 Files with no reviewable changes (1)
  • .markdownlint-cli2.jsonc

Comment thread .husky/pre-commit Outdated
genzouw added 2 commits May 21, 2026 17:28
CSS 属性セレクターのクォートをシングルクォートに統一し、
Prettier の format:check を通過するよう修正。
.husky/pre-commit 内の npm run format:check および npm run lint 実行時に、失敗時に即座にコミットを中断するよう、"|| exit 1" を追加しました。

レビューコメント: #55 (comment)
レビュアー: coderabbitai
優先度: high
@genzouw
genzouw merged commit 06f5f08 into main May 21, 2026
11 checks passed
@genzouw
genzouw deleted the feature/ci-cd-and-security-alignment branch May 21, 2026 08:33
genzouw added a commit that referenced this pull request May 29, 2026
## Summary

- 過去 8 連続 `startup_failure` の markdownlint workflow を、PR #44 と同じ npm
経由実行へ戻して復旧する
- `DavidAnson/markdownlint-cli2-action` を撤去し、`allowed_actions`
(`patterns_allowed`) への依存をワークフロー側から排除する
- 経緯と意図を workflow 本文にコメントで残し、再々度のリグレッションを抑止する

## 失敗 Run

https://github.com/genzouw/kakezan-manabo/actions/runs/26388299802
(`startup_failure`、ジョブ 0 件)

5/21 (PR #55) で action 利用へ戻して以降、`gh run list --workflow
markdownlint.yml` の通り直近 8 回連続で `startup_failure`。

## 原因

`DavidAnson/markdownlint-cli2-action` は third-party の Marketplace
action。
本リポジトリの `allowed_actions` は `selected` + `github_owned_allowed=true` +
`verified_allowed=true` で運用しており、`patterns_allowed` に登録されていない third-party
action は SHA pin していても起動拒否 (`startup_failure`) となる。

PR #44 ではまさにこの事象を解消するため npm 経由実行へ切り替えたが、PR #55 で action 利用へ意図せず差し戻されていた。

`genzouw/genzouw.com` 側の terraform (commit `f5af9f3`、2026-05-26) で
`DavidAnson/markdownlint-cli2-action@*` を `patterns_allowed` に追加して
GitHub 側の許可は復旧済みだが、許可リストへの依存自体が壊れやすい構造のため、ワークフロー側でも依存を取り除く。

## 変更内容

- `actions/setup-node@v6.4.0` で Node.js `20.19` をセットアップ (他 workflow と統一)
- `npm install -g --no-fund --no-audit --ignore-scripts
markdownlint-cli2@0.22.1` でインストール
  - `--ignore-scripts`: postinstall 経由の任意コード実行を防止
- `markdownlint-cli2 --config .markdownlint-cli2.jsonc "**/*.md"` を直接実行
- `continue-on-error: true` は既存方針 (MD040/MD031 整理後に外す) に従い据え置き
- 経緯と意図を workflow に日本語コメントで明記

## Terraform 側について

`genzouw.com` の `actions_patterns_allowed` で
`DavidAnson/markdownlint-cli2-action@*` は既に許可されている状態。本 PR では terraform
は変更しない。

将来このパターンを掃除する場合、本 workflow に依存が無いことを確認してから削除可能。

## Test plan

- [ ] 本 PR の `pull_request` イベントで markdownlint workflow が
`startup_failure` せず起動する
- [ ] `markdownlint-cli2` が実行され、レポートが出力される (継続失敗時も `continue-on-error`
で全体は通る)
- [ ] `actionlint` が通る
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants