From eb42844308564270701fd5a1d7c384652419f791 Mon Sep 17 00:00:00 2001 From: Toshiaki Wakabayashi Date: Wed, 20 May 2026 11:18:45 +0900 Subject: [PATCH 1/6] =?UTF-8?q?ci:=20=F0=9F=A4=96=20=E5=93=81=E8=B3=AA?= =?UTF-8?q?=E5=90=91=E4=B8=8A=E3=83=AF=E3=83=BC=E3=82=AF=E3=83=95=E3=83=AD?= =?UTF-8?q?=E3=83=BC=E3=82=92=E5=B0=8E=E5=85=A5?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/actionlint.yml | 43 ++++++++++++++++++++++ .github/workflows/codeql.yml | 47 ++++++++++++++++++++++++ .github/workflows/gitleaks.yml | 57 ++++++++++++++++++++++++++++++ .github/workflows/markdownlint.yml | 40 +++++++++++++++++++++ .markdownlint-cli2.jsonc | 35 ++++++++++++++++++ 5 files changed, 222 insertions(+) create mode 100644 .github/workflows/actionlint.yml create mode 100644 .github/workflows/codeql.yml create mode 100644 .github/workflows/gitleaks.yml create mode 100644 .github/workflows/markdownlint.yml create mode 100644 .markdownlint-cli2.jsonc diff --git a/.github/workflows/actionlint.yml b/.github/workflows/actionlint.yml new file mode 100644 index 00000000..ccf65428 --- /dev/null +++ b/.github/workflows/actionlint.yml @@ -0,0 +1,43 @@ +name: actionlint + +on: + push: + branches: [main] + paths: + - '.github/workflows/**' + - '.github/actionlint*' + pull_request: + branches: [main] + paths: + - '.github/workflows/**' + - '.github/actionlint*' + +concurrency: + group: actionlint-${{ github.ref }} + cancel-in-progress: true + +permissions: + contents: read + +jobs: + actionlint: + name: actionlint + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6 + + - name: Download actionlint + id: actionlint + run: | + set -euo pipefail + VERSION=1.7.7 + TARBALL="actionlint_${VERSION}_linux_amd64.tar.gz" + curl -fsSL -o "/tmp/${TARBALL}" "https://github.com/rhysd/actionlint/releases/download/v${VERSION}/${TARBALL}" + curl -fsSL -o /tmp/checksums.txt "https://github.com/rhysd/actionlint/releases/download/v${VERSION}/actionlint_${VERSION}_checksums.txt" + cd /tmp && grep "${TARBALL}" checksums.txt | sha256sum -c - + tar -xzf "/tmp/${TARBALL}" -C /tmp actionlint + echo "executable=/tmp/actionlint" >> "$GITHUB_OUTPUT" + + - name: Run actionlint + run: | + "${{ steps.actionlint.outputs.executable }}" -color diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml new file mode 100644 index 00000000..edaf4859 --- /dev/null +++ b/.github/workflows/codeql.yml @@ -0,0 +1,47 @@ +name: CodeQL + +on: + push: + branches: [main] + pull_request: + branches: [main] + schedule: + # 毎週月曜 03:00 JST (= 日曜 18:00 UTC) に main を再スキャン + - cron: '0 18 * * 0' + +concurrency: + group: codeql-${{ github.ref }} + cancel-in-progress: true + +permissions: + contents: read + security-events: write + actions: read + +jobs: + analyze: + name: Analyze (${{ matrix.language }}) + runs-on: ubuntu-latest + strategy: + fail-fast: false + matrix: + # frontend は tsx、backend は ts。両方とも 'javascript-typescript' でまとめてスキャン。 + language: ['javascript-typescript'] + steps: + - name: Checkout + uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6 + with: + persist-credentials: false + + - name: Initialize CodeQL + uses: github/codeql-action/init@78ed0c7291d93e40c51b085850dc669a4c3ab73b # v3 + with: + languages: ${{ matrix.language }} + # security-extended は誤検知が増えるため、まずは security-and-quality で運用。 + # ノイズが多い場合は 'security' に下げる。 + queries: security-and-quality + + - name: Perform CodeQL Analysis + uses: github/codeql-action/analyze@78ed0c7291d93e40c51b085850dc669a4c3ab73b # v3 + with: + category: '/language:${{ matrix.language }}' diff --git a/.github/workflows/gitleaks.yml b/.github/workflows/gitleaks.yml new file mode 100644 index 00000000..bda3c0de --- /dev/null +++ b/.github/workflows/gitleaks.yml @@ -0,0 +1,57 @@ +name: Gitleaks + +on: + push: + branches: [main] + pull_request: + branches: [main] + schedule: + # 毎週月曜 05:00 JST (= 日曜 20:00 UTC) に履歴全体を再スキャン + - cron: '0 20 * * 0' + workflow_dispatch: + +concurrency: + group: gitleaks-${{ github.ref }} + cancel-in-progress: true + +permissions: + contents: read + security-events: write + +jobs: + gitleaks: + name: Scan for leaked secrets + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6 + with: + # 履歴全体をスキャンするためフルクローン + fetch-depth: 0 + persist-credentials: false + + - name: Install gitleaks + run: | + set -euo pipefail + GITLEAKS_VERSION=8.21.2 + curl -fsSLO "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" + tar -xzf "gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" gitleaks + sudo mv gitleaks /usr/local/bin/gitleaks + gitleaks version + + - name: Run gitleaks + run: | + gitleaks detect \ + --source . \ + --redact \ + --verbose \ + --no-banner \ + --exit-code 1 \ + --report-format sarif \ + --report-path gitleaks.sarif + + - name: Upload SARIF + if: always() + uses: github/codeql-action/upload-sarif@78ed0c7291d93e40c51b085850dc669a4c3ab73b # v3 + with: + sarif_file: gitleaks.sarif + category: gitleaks diff --git a/.github/workflows/markdownlint.yml b/.github/workflows/markdownlint.yml new file mode 100644 index 00000000..c9c42b83 --- /dev/null +++ b/.github/workflows/markdownlint.yml @@ -0,0 +1,40 @@ +name: markdownlint + +on: + push: + branches: [main] + paths: + - '**/*.md' + - '.markdownlint-cli2.jsonc' + - '.github/workflows/markdownlint.yml' + pull_request: + branches: [main] + paths: + - '**/*.md' + - '.markdownlint-cli2.jsonc' + - '.github/workflows/markdownlint.yml' + +concurrency: + group: markdownlint-${{ github.ref }} + cancel-in-progress: true + +permissions: + contents: read + +jobs: + markdownlint: + name: markdownlint-cli2 + runs-on: ubuntu-latest + # 既存ドキュメントの MD040/MD031 違反を片付けるまでは赤検知にしない。 + # 整備完了後に continue-on-error を外して赤検知に切り替える。 + continue-on-error: true + steps: + - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6 + with: + persist-credentials: false + + - name: Run markdownlint-cli2 + uses: DavidAnson/markdownlint-cli2-action@992badcdf24e3b8eb7e87ff9287fe931bcb00c6e # v20 + with: + config: '.markdownlint-cli2.jsonc' + globs: '**/*.md' diff --git a/.markdownlint-cli2.jsonc b/.markdownlint-cli2.jsonc new file mode 100644 index 00000000..074b6c39 --- /dev/null +++ b/.markdownlint-cli2.jsonc @@ -0,0 +1,35 @@ +{ + // markdownlint-cli2 設定 + // https://github.com/DavidAnson/markdownlint-cli2 + "config": { + "default": true, + // 行長制限: コード/表/長文を伴うドキュメントが多いので無効化 + "MD013": false, + // インライン HTML: README や PR テンプレで やテーブル装飾を使うので許可 + "MD033": false, + // 単一の H1 を強制: 既存ドキュメントが満たさないものがあるため無効化 + "MD025": false, + // 重複ヘッダ: docs で「概要」が複数出るので緩める + "MD024": { "siblings_only": true }, + // 最初の行が H1 でなくてもよい (PR テンプレなど) + "MD041": false, + // 強調を見出しに使ってよい + "MD036": false, + // bare URL を許可 (GitHub flavored Markdown で自動リンク化される) + "MD034": false, + // テーブル列スタイル: 重要度が低いため無効化 + "MD060": false, + // blockquote 内の空行: 引用節を見やすくするため許可 + "MD028": false, + }, + "globs": ["**/*.md"], + "ignores": [ + "node_modules/**", + "**/node_modules/**", + ".claude/**", + "dist/**", + "**/dist/**", + "build/**", + "**/build/**", + ], +} From cdbe7e548681b4af36b13fe199a3fb95e228a740 Mon Sep 17 00:00:00 2001 From: Toshiaki Wakabayashi Date: Wed, 20 May 2026 12:21:52 +0900 Subject: [PATCH 2/6] =?UTF-8?q?fix:=20=F0=9F=90=9B=20[Code=20Review]=20act?= =?UTF-8?q?ionlint.yml=20=E3=81=AB=20persist-credentials:=20false=20?= =?UTF-8?q?=E3=82=92=E8=BF=BD=E5=8A=A0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit actions/checkout ステップに persist-credentials: false を明示し、 Git 認証情報が不要なワークフローで権限最小化の原則を適用。 レビューコメント: https://github.com/genzouw/monopo/pull/94#discussion_r3270872152 レビュアー: coderabbitai 優先度: high --- .github/workflows/actionlint.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/actionlint.yml b/.github/workflows/actionlint.yml index ccf65428..c5e6c149 100644 --- a/.github/workflows/actionlint.yml +++ b/.github/workflows/actionlint.yml @@ -25,6 +25,8 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6 + with: + persist-credentials: false - name: Download actionlint id: actionlint From 5b822d0ae6d3720b6ed2622b316bb85fb3217f3b Mon Sep 17 00:00:00 2001 From: Toshiaki Wakabayashi Date: Wed, 20 May 2026 12:22:08 +0900 Subject: [PATCH 3/6] =?UTF-8?q?fix:=20=F0=9F=90=9B=20[Code=20Review]=20git?= =?UTF-8?q?leaks=20=E3=83=90=E3=82=A4=E3=83=8A=E3=83=AA=E3=81=AE=E3=83=81?= =?UTF-8?q?=E3=82=A7=E3=83=83=E3=82=AF=E3=82=B5=E3=83=A0=E6=A4=9C=E8=A8=BC?= =?UTF-8?q?=E3=82=92=E8=BF=BD=E5=8A=A0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ダウンロードした gitleaks tarball を展開・実行する前に SHA-256 チェックサムによる整合性検証を追加し、 サプライチェーン攻撃リスクを低減。 レビューコメント: https://github.com/genzouw/monopo/pull/94#discussion_r3270872156 レビュアー: coderabbitai 優先度: high --- .github/workflows/gitleaks.yml | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/.github/workflows/gitleaks.yml b/.github/workflows/gitleaks.yml index bda3c0de..196bc24e 100644 --- a/.github/workflows/gitleaks.yml +++ b/.github/workflows/gitleaks.yml @@ -33,8 +33,12 @@ jobs: run: | set -euo pipefail GITLEAKS_VERSION=8.21.2 - curl -fsSLO "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" - tar -xzf "gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" gitleaks + TARBALL="gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" + CHECKSUMS="gitleaks_${GITLEAKS_VERSION}_checksums.txt" + curl -fsSLO "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/${TARBALL}" + curl -fsSLO "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/${CHECKSUMS}" + grep -F " ${TARBALL}" "${CHECKSUMS}" | sha256sum -c - + tar -xzf "${TARBALL}" gitleaks sudo mv gitleaks /usr/local/bin/gitleaks gitleaks version From 81da09ff49e0e899f911c75c1e1089c0591f029b Mon Sep 17 00:00:00 2001 From: Toshiaki Wakabayashi Date: Wed, 20 May 2026 12:22:20 +0900 Subject: [PATCH 4/6] =?UTF-8?q?fix:=20=F0=9F=90=9B=20[Code=20Review]=20mar?= =?UTF-8?q?kdownlint=20MD060=20=E3=82=92=20MD055=20=E3=81=AB=E4=BF=AE?= =?UTF-8?q?=E6=AD=A3?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit MD060 は markdownlint に存在しないルール ID。 意図した「テーブルパイプスタイル」設定は MD055 (Table pipe style) が正しい。 レビューコメント: https://github.com/genzouw/monopo/pull/94#discussion_r3270865902 レビュアー: gemini-code-assist 優先度: low --- .markdownlint-cli2.jsonc | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.markdownlint-cli2.jsonc b/.markdownlint-cli2.jsonc index 074b6c39..d3df7133 100644 --- a/.markdownlint-cli2.jsonc +++ b/.markdownlint-cli2.jsonc @@ -17,8 +17,8 @@ "MD036": false, // bare URL を許可 (GitHub flavored Markdown で自動リンク化される) "MD034": false, - // テーブル列スタイル: 重要度が低いため無効化 - "MD060": false, + // テーブルパイプスタイル: 重要度が低いため無効化 + "MD055": false, // blockquote 内の空行: 引用節を見やすくするため許可 "MD028": false, }, From 47a22f21a2329d3c9fc17ce073f59f7b085b286e Mon Sep 17 00:00:00 2001 From: Toshiaki Wakabayashi Date: Wed, 20 May 2026 12:22:34 +0900 Subject: [PATCH 5/6] =?UTF-8?q?fix:=20=F0=9F=90=9B=20[Code=20Review]=20mar?= =?UTF-8?q?kdownlint=20ignores=20=E3=81=8B=E3=82=89=E5=86=97=E9=95=B7?= =?UTF-8?q?=E3=81=AA=E3=83=91=E3=82=BF=E3=83=BC=E3=83=B3=E3=82=92=E5=89=8A?= =?UTF-8?q?=E9=99=A4?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit **/node_modules/** は node_modules/** を含むため、 ルート固定の冗長なエントリ (node_modules/**, dist/**, build/**) を削除。 レビューコメント: https://github.com/genzouw/monopo/pull/94#discussion_r3270865906 レビュアー: gemini-code-assist 優先度: low --- .markdownlint-cli2.jsonc | 10 +--------- 1 file changed, 1 insertion(+), 9 deletions(-) diff --git a/.markdownlint-cli2.jsonc b/.markdownlint-cli2.jsonc index d3df7133..d2644d52 100644 --- a/.markdownlint-cli2.jsonc +++ b/.markdownlint-cli2.jsonc @@ -23,13 +23,5 @@ "MD028": false, }, "globs": ["**/*.md"], - "ignores": [ - "node_modules/**", - "**/node_modules/**", - ".claude/**", - "dist/**", - "**/dist/**", - "build/**", - "**/build/**", - ], + "ignores": ["**/node_modules/**", ".claude/**", "**/dist/**", "**/build/**"], } From 58e4f860cadbae4a3c672d4a0d75282c2fa50fee Mon Sep 17 00:00:00 2001 From: Toshiaki Wakabayashi Date: Wed, 20 May 2026 12:25:30 +0900 Subject: [PATCH 6/6] =?UTF-8?q?fix:=20=E3=82=AB=E3=82=B9=E3=82=BF=E3=83=A0?= =?UTF-8?q?=20CodeQL=20=E3=83=AF=E3=83=BC=E3=82=AF=E3=83=95=E3=83=AD?= =?UTF-8?q?=E3=83=BC=E3=82=92=E5=89=8A=E9=99=A4=E3=81=97=E3=81=A6=E3=83=87?= =?UTF-8?q?=E3=83=95=E3=82=A9=E3=83=AB=E3=83=88=E8=A8=AD=E5=AE=9A=E3=81=A8?= =?UTF-8?q?=E3=81=AE=E7=AB=B6=E5=90=88=E3=82=92=E8=A7=A3=E6=B6=88?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit リポジトリの Default Setup (CodeQL 自動スキャン) が既に有効なため、 カスタムの codeql.yml を追加すると 「advanced configurations cannot be processed when the default setup is enabled」 エラーが発生していた。Default Setup によるスキャンは維持されるため機能への影響はない。 --- .github/workflows/codeql.yml | 47 ------------------------------------ 1 file changed, 47 deletions(-) delete mode 100644 .github/workflows/codeql.yml diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml deleted file mode 100644 index edaf4859..00000000 --- a/.github/workflows/codeql.yml +++ /dev/null @@ -1,47 +0,0 @@ -name: CodeQL - -on: - push: - branches: [main] - pull_request: - branches: [main] - schedule: - # 毎週月曜 03:00 JST (= 日曜 18:00 UTC) に main を再スキャン - - cron: '0 18 * * 0' - -concurrency: - group: codeql-${{ github.ref }} - cancel-in-progress: true - -permissions: - contents: read - security-events: write - actions: read - -jobs: - analyze: - name: Analyze (${{ matrix.language }}) - runs-on: ubuntu-latest - strategy: - fail-fast: false - matrix: - # frontend は tsx、backend は ts。両方とも 'javascript-typescript' でまとめてスキャン。 - language: ['javascript-typescript'] - steps: - - name: Checkout - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6 - with: - persist-credentials: false - - - name: Initialize CodeQL - uses: github/codeql-action/init@78ed0c7291d93e40c51b085850dc669a4c3ab73b # v3 - with: - languages: ${{ matrix.language }} - # security-extended は誤検知が増えるため、まずは security-and-quality で運用。 - # ノイズが多い場合は 'security' に下げる。 - queries: security-and-quality - - - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@78ed0c7291d93e40c51b085850dc669a4c3ab73b # v3 - with: - category: '/language:${{ matrix.language }}'