Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
38 commits
Select commit Hold shift + click to select a range
9be79d9
feat(hooks): surface scanner findings in CI job summary + fix Checkov…
osterman Jun 15, 2026
77297c1
docs(roadmap): link scanner CI-summary milestone to PR #2617
osterman Jun 15, 2026
0cc205b
docs(roadmap): classify Infracost as a cost tool, not a security scanner
osterman Jun 15, 2026
c18ea52
feat(hooks): native CI annotations + SARIF Code Scanning upload for s…
osterman Jun 19, 2026
f6e8f16
docs(roadmap): link scanner CI annotations/results milestone to PR #2631
osterman Jun 19, 2026
32f8e60
docs(hooks): clarify GitHub Advanced Security is a paid GitHub add-on…
osterman Jun 19, 2026
5db20e8
chore: update ci annotations and actions
osterman Jun 19, 2026
86197e6
test: add native CI e2e fixture
osterman Jun 19, 2026
0e894b6
feat(hooks): surface scanner findings in CI job summary + fix Checkov…
osterman Jun 15, 2026
693683f
docs(roadmap): link scanner CI-summary milestone to PR #2617
osterman Jun 15, 2026
39cbc31
docs(roadmap): classify Infracost as a cost tool, not a security scanner
osterman Jun 15, 2026
2ab39f7
feat(hooks): native CI annotations + SARIF Code Scanning upload for s…
osterman Jun 19, 2026
0094e45
docs(roadmap): link scanner CI annotations/results milestone to PR #2631
osterman Jun 19, 2026
e256f7d
docs(hooks): clarify GitHub Advanced Security is a paid GitHub add-on…
osterman Jun 19, 2026
35a0d04
chore: update ci annotations and actions
osterman Jun 19, 2026
cd2c067
test: add native CI e2e fixture
osterman Jun 19, 2026
73cb30a
Normalize AWS auth endpoint config
osterman Jun 19, 2026
e1d6502
Merge branch 'osterman/scanner-ci-annotations-results' of https://git…
osterman Jun 19, 2026
72b942a
Fix screengrab build command list
osterman Jun 19, 2026
9e68d71
Fix CI annotations and validation failures
osterman Jun 19, 2026
3adfafd
Update quick-start acceptance snapshots
osterman Jun 19, 2026
9748333
Normalize SARIF paths for scanner hooks
osterman Jun 20, 2026
975b7ed
Fix native scanner CI annotations
osterman Jun 20, 2026
069b688
Scope scanner SARIF category to tool name and event-scoped preflight
osterman Jun 20, 2026
4cc5c41
Scope Native CI to scanner-related path changes
osterman Jun 21, 2026
ab68a24
Reduce native CI scanner findings to one per scanner
osterman Jun 21, 2026
c6988ff
Fix doubled SARIF paths for workdir-relative scanner output
osterman Jun 21, 2026
fcc017f
Fix native CI apply by keeping scanner targets Floci-applyable
osterman Jun 21, 2026
9c195ff
Exclude no-color.org from link check (CI timeouts)
osterman Jun 21, 2026
c77e335
Test scanner inline-ignore directives in native CI fixture
osterman Jun 21, 2026
9bbd482
Route KMS to Floci in native CI fixture provider config
osterman Jun 21, 2026
da4dabd
Merge remote-tracking branch 'origin/main' into osterman/scanner-ci-a…
osterman Jun 21, 2026
a037a43
Merge remote-tracking branch 'origin/main' into osterman/scanner-ci-a…
osterman Jun 22, 2026
603b36e
fix: address code-review findings on scanner CI branch
osterman Jun 22, 2026
9d4a07a
test(ci): cover CI-reporting helpers to clear 80% patch gate
osterman Jun 22, 2026
4c8f5a4
Merge remote-tracking branch 'origin/main' into osterman/scanner-ci-a…
osterman Jun 22, 2026
d261c78
Merge remote-tracking branch 'origin/main' into osterman/scanner-ci-a…
osterman Jun 24, 2026
4798f81
Merge branch 'main' into osterman/scanner-ci-annotations-results
aknysh Jun 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/actions/go-version-check/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -72,7 +72,7 @@ runs:

- name: Comment on PR
if: steps.compare.outputs.changed == 'true'
uses: actions/github-script@v7
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
with:
github-token: ${{ inputs.token }}
script: |
Expand Down
4 changes: 2 additions & 2 deletions .github/actions/verify-sha-pinning/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ runs:
steps:
- name: Verify SHA pins against upstream tags
id: verify
uses: actions/github-script@v7
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
env:
WORKFLOW_DIR: ${{ inputs.workflow-dir }}
with:
Expand Down Expand Up @@ -273,7 +273,7 @@ runs:

- name: Post or update PR comment
if: always() && github.event_name == 'pull_request'
uses: actions/github-script@v7
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
env:
RESULTS_JSON: ${{ steps.verify.outputs.results_json }}
VERIFIED_COUNT: ${{ steps.verify.outputs.verified_count }}
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/algolia.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -36,12 +36,12 @@ jobs:
persist-credentials: false

- name: Setup Node
uses: actions/setup-node@v4
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version-file: "website/.nvmrc"

- name: Setup pnpm
uses: pnpm/action-setup@v4
uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v4.4.0
with:
version: 9

Expand Down Expand Up @@ -78,12 +78,12 @@ jobs:
persist-credentials: false

- name: Setup Node
uses: actions/setup-node@v4
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version-file: "website/.nvmrc"

- name: Setup pnpm
uses: pnpm/action-setup@v4
uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v4.4.0
with:
version: 9

Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/atmos-pro.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ jobs:
with:
persist-credentials: false
# Install Go and toolchain dependencies
- uses: actions/setup-go@f111f3307d8850f501ac008e886eec1fd1932a34 # v5.3.0
- uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version-file: go.mod
- run: go mod tidy
Expand All @@ -40,7 +40,7 @@ jobs:
# gofumpt
- name: Get changed Go files
id: changed-files
uses: tj-actions/changed-files@a284dc1814e3fd07f2e34267fc8f81227ed29fb8 # v45.0.6
uses: tj-actions/changed-files@9426d40962ed5378910ee2e21d5f8c6fcbf2dd96 # v47.0.6
with:
use_rest_api: "true"
files: |
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -94,7 +94,7 @@ jobs:
# Without this step, the action may fail intermittently with
# "could not load export data" errors due to cache corruption
- name: Set up Go
uses: actions/setup-go@v5
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version-file: go.mod
cache: true
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/dependency-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,12 +24,12 @@ jobs:
persist-credentials: false

- name: Set up Go
uses: actions/setup-go@v5
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version-file: go.mod

- name: Dependency Review
uses: actions/dependency-review-action@v4
uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0
with:
# Disable OpenSSF scorecard to reduce summary size (prevents 1024k limit errors)
show-openssf-scorecard: false
Expand Down
169 changes: 169 additions & 0 deletions .github/workflows/native-ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,169 @@
name: Native CI

on:
pull_request:
types: [opened, synchronize, reopened]
# Only run when something this E2E actually exercises changes, so unrelated
# PRs aren't spammed with scanner SARIF/code-scanning annotations.
paths:
# The E2E fixture + its validation test-case.
- "tests/fixtures/scenarios/native-ci-e2e/**"
- "tests/test-cases/native-ci-e2e.yaml"
# The workflow itself.
- ".github/workflows/native-ci.yml"
# The feature this E2E exercises, so scanner/CI source changes still run it.
- "pkg/ci/**"
- "pkg/hooks/**"
- "actions/cache/**"
workflow_dispatch:

permissions:
contents: read
pull-requests: write
security-events: write
statuses: write

env:
ATMOS_NATIVE_CI_WORKDIR: tests/fixtures/scenarios/native-ci-e2e
ATMOS_VERSION_CHECK_ENABLED: "false"
NATIVE_CI_TRIVY_VERSION: "0.70.0"
NATIVE_CI_KICS_VERSION: "2.1.20"

jobs:
terraform-plan:
name: "[native ci] terraform plan"
runs-on: ubuntu-latest
timeout-minutes: 20

services:
floci:
image: floci/floci@sha256:c88ec20bf221630dd195d38a14eeb0ac52ddfa72c37ebb3c8aa17f63ae27c5f2 # 1.5.23
ports:
- 4566:4566

steps:
- name: Check out code
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false

- name: Set up Go
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
with:
go-version-file: "go.mod"

- name: Build Atmos
run: |
make build-linux
echo "${{ github.workspace }}/build" >> "$GITHUB_PATH"

- name: Restore Atmos native CI cache
uses: ./actions/cache
env:
ATMOS_CHDIR: ${{ env.ATMOS_NATIVE_CI_WORKDIR }}

- name: Validate native CI fixture
working-directory: ${{ env.ATMOS_NATIVE_CI_WORKDIR }}
run: atmos validate stacks

- name: Mirror Terraform providers
working-directory: ${{ env.ATMOS_NATIVE_CI_WORKDIR }}
run: atmos terraform cache mirror bucket -s test --platform=linux_amd64 --format=json

- name: Install scanner tools for native CI fixture
run: |
scanner_bin="$RUNNER_TEMP/native-ci-scanners/bin"
scanner_assets="$RUNNER_TEMP/native-ci-scanners/assets"
mkdir -p "$scanner_bin" "$scanner_assets"

# Download and verify the Trivy binary against its published checksum
# before extracting, so a tampered or corrupted archive never executes.
curl -fsSL \
-o "$RUNNER_TEMP/trivy.tar.gz" \
"https://github.com/aquasecurity/trivy/releases/download/v${NATIVE_CI_TRIVY_VERSION}/trivy_${NATIVE_CI_TRIVY_VERSION}_Linux-64bit.tar.gz"
curl -fsSL \
-o "$RUNNER_TEMP/trivy_checksums.txt" \
"https://github.com/aquasecurity/trivy/releases/download/v${NATIVE_CI_TRIVY_VERSION}/trivy_${NATIVE_CI_TRIVY_VERSION}_checksums.txt"
trivy_sha="$(grep " trivy_${NATIVE_CI_TRIVY_VERSION}_Linux-64bit.tar.gz$" "$RUNNER_TEMP/trivy_checksums.txt" | awk '{print $1}')"
echo "${trivy_sha} $RUNNER_TEMP/trivy.tar.gz" | sha256sum -c -
tar -xzf "$RUNNER_TEMP/trivy.tar.gz" -C "$scanner_bin" trivy

# Download and verify the KICS binary against its published checksum
# before extracting.
curl -fsSL \
-o "$RUNNER_TEMP/kics.tar.gz" \
"https://github.com/Checkmarx/kics/releases/download/v${NATIVE_CI_KICS_VERSION}/kics_${NATIVE_CI_KICS_VERSION}_linux_amd64.tar.gz"
curl -fsSL \
-o "$RUNNER_TEMP/kics_checksums.txt" \
"https://github.com/Checkmarx/kics/releases/download/v${NATIVE_CI_KICS_VERSION}/checksums.txt"
kics_sha="$(grep " kics_${NATIVE_CI_KICS_VERSION}_linux_amd64.tar.gz$" "$RUNNER_TEMP/kics_checksums.txt" | awk '{print $1}')"
echo "${kics_sha} $RUNNER_TEMP/kics.tar.gz" | sha256sum -c -
tar -xzf "$RUNNER_TEMP/kics.tar.gz" -C "$scanner_bin" kics

# The KICS query assets (extracted-info.zip) have no published checksum,
# so they cannot be verified the same way. They are data, not an executable.
curl -fsSL \
-o "$RUNNER_TEMP/kics-extracted-info.zip" \
"https://github.com/Checkmarx/kics/releases/download/v${NATIVE_CI_KICS_VERSION}/extracted-info.zip"
unzip -q "$RUNNER_TEMP/kics-extracted-info.zip" -d "$scanner_assets/kics"

chmod +x "$scanner_bin/trivy" "$scanner_bin/kics"
echo "$scanner_bin" >> "$GITHUB_PATH"
echo "KICS_QUERIES_PATH=$scanner_assets/kics/assets/queries" >> "$GITHUB_ENV"

- name: Terraform plan
id: terraform-plan
working-directory: ${{ env.ATMOS_NATIVE_CI_WORKDIR }}
env:
ATMOS_CI_GITHUB_TOKEN: ${{ github.token }}
GITHUB_TOKEN: ${{ github.token }}
run: atmos terraform plan bucket -s test

terraform-apply:
name: "[native ci] terraform apply"
needs: terraform-plan
runs-on: ubuntu-latest
timeout-minutes: 20

services:
floci:
image: floci/floci@sha256:c88ec20bf221630dd195d38a14eeb0ac52ddfa72c37ebb3c8aa17f63ae27c5f2 # 1.5.23
ports:
- 4566:4566

steps:
- name: Check out code
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false

- name: Set up Go
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
with:
go-version-file: "go.mod"

- name: Build Atmos
run: |
make build-linux
echo "${{ github.workspace }}/build" >> "$GITHUB_PATH"

- name: Restore Atmos native CI cache
uses: ./actions/cache
env:
ATMOS_CHDIR: ${{ env.ATMOS_NATIVE_CI_WORKDIR }}

- name: Validate native CI fixture
working-directory: ${{ env.ATMOS_NATIVE_CI_WORKDIR }}
run: atmos validate stacks

- name: Mirror Terraform providers
working-directory: ${{ env.ATMOS_NATIVE_CI_WORKDIR }}
run: atmos terraform cache mirror bucket -s test --platform=linux_amd64 --format=json

- name: Terraform apply
id: terraform-apply
working-directory: ${{ env.ATMOS_NATIVE_CI_WORKDIR }}
env:
ATMOS_CI_GITHUB_TOKEN: ${{ github.token }}
GITHUB_TOKEN: ${{ github.token }}
run: atmos terraform apply bucket -s test -auto-approve
4 changes: 2 additions & 2 deletions .github/workflows/pre-commit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ jobs:
fetch-depth: 0

- name: Set up Go
uses: actions/setup-go@v5
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version-file: go.mod
cache: true
Expand All @@ -59,7 +59,7 @@ jobs:
go mod download

- name: Set up Python
uses: actions/setup-python@v5
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
with:
python-version: ${{ env.PYTHON_VERSION }}

Expand Down
13 changes: 8 additions & 5 deletions .github/workflows/screengrabs.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -73,9 +73,10 @@ jobs:
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

- uses: hashicorp/setup-terraform@v3
with:
terraform_wrapper: false
- name: Add Terraform from Atmos toolchain to PATH
run: |
atmos toolchain install hashicorp/terraform
atmos toolchain env --format=github

- name: Run make build-all install
run: |
Expand All @@ -85,14 +86,16 @@ jobs:
env:
ATMOS_PAGER: "false"

- uses: actions/create-github-app-token@v1
- uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
id: github-app
with:
app-id: ${{ vars.BOT_GITHUB_APP_ID }}
private-key: ${{ secrets.BOT_GITHUB_APP_PRIVATE_KEY }}
permission-contents: write
permission-pull-requests: write

Comment thread
coderabbitai[bot] marked this conversation as resolved.
- name: Create or update PR
uses: peter-evans/create-pull-request@v7
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
with:
token: ${{ steps.github-app.outputs.token }}
branch: "chore/update-build-screengrabs-for-${{ needs.prepare.outputs.version }}"
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/setup-go-cache-warmup.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ jobs:
persist-credentials: false

- name: Set up Go
uses: actions/setup-go@v5
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version-file: "go.mod"
id: go
Expand Down
Loading
Loading