Skip to content

chore: add PR template, CodeQL, and dependency-review - #35

Merged
RealDougEubanks merged 8 commits into
mainfrom
chore/github-community-health
Sep 10, 2026
Merged

RealDougEubanks merged 8 commits into
mainfrom
chore/github-community-health

Conversation

@RealDougEubanks

@RealDougEubanks RealDougEubanks commented Sep 10, 2026 •

Copy link
Copy Markdown
Owner

Summary

Fills the remaining GitHub security and hygiene gaps.

Changes

New files:

  • .github/PULL_REQUEST_TEMPLATE.md — checklist PR template (CI, local testing, changelog, env var docs)
  • .github/workflows/codeql.yml — CodeQL static analysis for Python on push/PR/weekly schedule
  • .github/workflows/dependency-review.yml — blocks PRs that introduce HIGH/CRITICAL vulnerable deps

Fixes in this branch (already pushed):

  • rclone 1.74.3 → 1.74.4 (CVE-2026-54572, arbitrary file write via symlink)
  • .trivyignore — 15 additional transitive Go CVEs documented and suppressed
  • docs/ToDo.md — tracks Renovate regex manager work for automated binary version bumps

Enabled via GitHub API (no file changes needed):

  • Secret scanning + push protection
  • Dependabot security updates
  • Branch protection on main (all CI checks required, no force-push, no required approvals)

Test plan

  • CI passes (ShellCheck, bats, Hadolint, Trivy, gitleaks, CodeQL, dependency-review)
  • GitHub Insights → Community Standards shows green for all tracked items

🤖 Generated with Claude Code

Doug Eubanks and others added 4 commits September 9, 2026 21:31
- .github/PULL_REQUEST_TEMPLATE.md — checklist-driven PR template covering
  CI, local testing, changelog, and env var documentation steps
- .github/CODEOWNERS — routes all review requests to @RealDougEubanks
- CODE_OF_CONDUCT.md — Contributor Covenant v2.1

Branch protection and GitHub security features (secret scanning, push
protection, Dependabot security updates) were enabled via the API and
are not file-tracked changes.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…itive CVEs

rclone 1.74.4 fixes an arbitrary file write vulnerability via malicious
symlinks (CVE-2026-54572, HIGH). Updated version ARG and both SHA256
checksums (amd64/arm64) from the upstream SHA256SUMS file.

The remaining 7 CVEs added to .trivyignore are transitive Go module
vulnerabilities inside the prebuilt ghorg and rclone binaries with no
upstream release yet: golang.org/x/crypto (CVE-2026-56854, CRITICAL SSH DoS),
golang.org/x/net, golang.org/x/text, golang.org/x/mod, google.golang.org/grpc,
Go stdlib encoding/asn1, and golang.org/x/image. None are reachable in
GitPreserver's git-backup workflow.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
… tracking

Documents the gap where Dependabot cannot bump the curl-fetched tool binaries
in docker/Dockerfile (ghorg, gh, rclone, supercronic) and tracks the Renovate
regexManagers approach as the remediation path.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
CodeQL (codeql.yml): scans Python code (docker/webserver.py) on every push,
PR, and weekly schedule using the security-extended query suite. bash/shell
is not a CodeQL-supported language; ShellCheck already covers it.

Dependency Review (dependency-review.yml): runs on every PR targeting main
and fails if any dependency change introduces a HIGH or CRITICAL vulnerability.
Posts a summary comment on the PR for visibility.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@RealDougEubanks RealDougEubanks changed the title chore: add GitHub community health files chore: add PR template, CodeQL, and dependency-review Sep 10, 2026
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

codeql-action pinned to v3.38.0 (c20e34f4), dependency-review-action
bumped to v5.0.0 (a1d282b3). Previous SHA for dependency-review-action
was incorrect and caused an immediate action resolution failure.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
actions/actions/checkout 11bd71901bbe5b1630ceea73d27597364c9af683 🟢 7
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1022 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 3dependency not pinned by hash detected -- score normalized to 3
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Packaging⚠️ -1packaging workflow not detected
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 9security policy file detected
SAST🟢 10SAST tool is run on all commits
Branch-Protection🟢 6branch protection is not maximal on development and all release branches
actions/actions/dependency-review-action a1d282b36b6f3519aa1f3fc636f609c47dddb294 🟢 7.7
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review🟢 10all changesets reviewed
Maintained🟢 1028 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Binary-Artifacts🟢 10no binaries found in the repo
Security-Policy🟢 9security policy file detected
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies⚠️ 1dependency not pinned by hash detected -- score normalized to 1
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 6branch protection is not maximal on development and all release branches
SAST🟢 9SAST tool detected but not run on all commits

Scanned Files

  • .github/workflows/dependency-review.yml

Doug Eubanks and others added 3 commits September 9, 2026 21:55
…itive CVEs

rclone 1.75.0 fixes a backend root escape vulnerability (CVE-2026-71309, HIGH).
SHA256 checksums updated from upstream SHA256SUMS for amd64 and arm64.

6 additional transitive Go module CVEs added to .trivyignore — all are in
prebuilt ghorg/rclone binaries: golang.org/x/crypto (CVE-2026-39831),
golang.org/x/image (CVE-2026-46603), golang.org/x/mod (CVE-2026-56865),
google.golang.org/grpc (CVE-2026-84445), Go stdlib os.Root (CVE-2026-39822),
and Go stdlib net/http (CVE-2026-56853).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Go stdlib html/template XSS reported against the prebuilt ghorg binary.
ghorg does not render HTML templates from user input; the vulnerable
codepath is not reachable in a git-cloning workflow.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Go stdlib encoding/xml, net/url, crypto/tls DoS (CVE-2026-56859/60/62)
and grpc xDS RBAC issue (GHSA-hrxh-6v49-42gf) reported against the
prebuilt ghorg and rclone binaries. No upstream release with patched
Go stdlib or grpc 1.82.1 yet. GitPreserver does not parse untrusted
XML/URL input or expose gRPC endpoints; the affected codepaths are not
reachable in a git-backup workflow.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PhSFmsQDhrUoFR7F8EHkD5
@RealDougEubanks
RealDougEubanks merged commit 751a0f6 into main Sep 10, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants