Skip to content

Commit 696bbfa

Browse files
Align PMG integration with the agreed standard
Brings this repo onto the same integration used in ai-playbook and i18nify, with the enforcement fix from blade. - Setup step renamed to "Setup PMG proxy" and given `id: pmg-setup`, so the enforce step can tell whether setup actually ran. - Enforce step runs `--fail-on-violation` only when setup succeeded. With a bare `if: always()`, any failure before the PMG step makes GitHub skip setup while still running enforce, which then dies with `pmg: command not found` (exit 127) and buries the real error. - Removed additions that are not part of the reference integration: `permissions:` blocks, workflow comments, pinned action SHAs and non-standard step names. - Added pmg-test.yml, byte-identical to the copy in ai-playbook and i18nify, which demonstrates the proxy blocking a known-malicious package and syncing the event to SafeDep Cloud. The workflow files are now the master versions plus the two PMG steps and nothing else: 75 lines added, none removed or modified. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent caa8e8a commit 696bbfa

7 files changed

Lines changed: 101 additions & 32 deletions

File tree

‎.github/workflows/crud_app.yaml‎

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,15 +8,14 @@ jobs:
88
irc:
99
runs-on: ubuntu-latest
1010
name: Build CRUD demo app image
11-
permissions:
12-
contents: read
1311
steps:
1412
- name: checkout
1513
id: checkout
1614
uses: actions/checkout@v2
1715
with:
1816
submodules: true
19-
- name: Start PMG proxy
17+
- name: Setup PMG proxy
18+
id: pmg-setup
2019
uses: safedep/pmg@v1
2120
with:
2221
server-mode: true
@@ -46,4 +45,9 @@ jobs:
4645
file: ./example/apps/webapp/Dockerfile
4746
- name: Enforce PMG policy
4847
if: always()
49-
run: pmg proxy stop --fail-on-violation
48+
run: |
49+
if [ "${{ steps.pmg-setup.outcome }}" = "success" ]; then
50+
pmg proxy stop --fail-on-violation
51+
else
52+
pmg proxy stop || true
53+
fi

‎.github/workflows/ingressroute_configurator.yaml‎

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,15 +8,14 @@ jobs:
88
irc:
99
runs-on: ubuntu-latest
1010
name: Build Ingressroute configurator image
11-
permissions:
12-
contents: read
1311
steps:
1412
- name: checkout
1513
id: checkout
1614
uses: actions/checkout@v2
1715
with:
1816
submodules: true
19-
- name: Start PMG proxy
17+
- name: Setup PMG proxy
18+
id: pmg-setup
2019
uses: safedep/pmg@v1
2120
with:
2221
server-mode: true
@@ -46,4 +45,9 @@ jobs:
4645
file: ./hooks/ingressroute_configurator/Dockerfile
4746
- name: Enforce PMG policy
4847
if: always()
49-
run: pmg proxy stop --fail-on-violation
48+
run: |
49+
if [ "${{ steps.pmg-setup.outcome }}" = "success" ]; then
50+
pmg proxy stop --fail-on-violation
51+
else
52+
pmg proxy stop || true
53+
fi

‎.github/workflows/pmg-test.yml‎

Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
name: PMG Proxy Test
2+
3+
on:
4+
workflow_dispatch:
5+
pull_request:
6+
push:
7+
8+
jobs:
9+
test-pmg-allows-clean-install:
10+
name: PMG - Clean package should not be blocked
11+
runs-on: ubuntu-latest
12+
steps:
13+
- name: Setup PMG proxy
14+
uses: safedep/pmg@v1
15+
with:
16+
server-mode: true
17+
api-key: ${{ secrets.PMG_PUBLIC_REPOS_TOKEN }}
18+
tenant-id: ${{ secrets.PMG_TENANT_ID }}
19+
20+
- name: Install npm via nvm
21+
run: |
22+
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.7/install.sh | bash
23+
export NVM_DIR="$HOME/.nvm"
24+
[ -s "$NVM_DIR/nvm.sh" ] && \. "$NVM_DIR/nvm.sh"
25+
nvm install 20
26+
echo "$NVM_DIR/versions/node/$(nvm version 20)/bin" >> $GITHUB_PATH
27+
28+
- name: Install clean package (should succeed)
29+
run: npm install lodash
30+
31+
- name: Enforce PMG policy
32+
if: always()
33+
run: pmg proxy stop --fail-on-violation
34+
35+
test-pmg-blocks-malicious-package:
36+
name: PMG - Malicious package should be blocked
37+
runs-on: ubuntu-latest
38+
steps:
39+
- name: Setup PMG proxy
40+
uses: safedep/pmg@v1
41+
with:
42+
server-mode: true
43+
api-key: ${{ secrets.PMG_PUBLIC_REPOS_TOKEN }}
44+
tenant-id: ${{ secrets.PMG_TENANT_ID }}
45+
46+
- name: Install npm via nvm
47+
run: |
48+
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.7/install.sh | bash
49+
export NVM_DIR="$HOME/.nvm"
50+
[ -s "$NVM_DIR/nvm.sh" ] && \. "$NVM_DIR/nvm.sh"
51+
nvm install 20
52+
echo "$NVM_DIR/versions/node/$(nvm version 20)/bin" >> $GITHUB_PATH
53+
54+
- name: Install flagged test package (PMG should block this)
55+
continue-on-error: true
56+
run: npm install --no-cache --prefer-online safedep-test-pkg@0.1.3
57+
58+
- name: Enforce PMG policy (expect failure — violation recorded)
59+
if: always()
60+
run: pmg proxy stop --fail-on-violation

‎.github/workflows/secret_cloner.yaml‎

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,15 +8,14 @@ jobs:
88
secc:
99
runs-on: ubuntu-latest
1010
name: Build SQS configurator image
11-
permissions:
12-
contents: read
1311
steps:
1412
- name: checkout
1513
id: checkout
1614
uses: actions/checkout@v2
1715
with:
1816
submodules: true
19-
- name: Start PMG proxy
17+
- name: Setup PMG proxy
18+
id: pmg-setup
2019
uses: safedep/pmg@v1
2120
with:
2221
server-mode: true
@@ -46,4 +45,9 @@ jobs:
4645
file: ./hooks/secret_cloner/Dockerfile
4746
- name: Enforce PMG policy
4847
if: always()
49-
run: pmg proxy stop --fail-on-violation
48+
run: |
49+
if [ "${{ steps.pmg-setup.outcome }}" = "success" ]; then
50+
pmg proxy stop --fail-on-violation
51+
else
52+
pmg proxy stop || true
53+
fi

‎.github/workflows/semgrep.yaml‎

Lines changed: 1 addition & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -7,23 +7,12 @@ jobs:
77
semgrep:
88
name: Scan
99
runs-on: ubuntu-latest
10-
permissions:
11-
contents: read
1210
steps:
1311
- uses: razorpay/checkout-action@30aedaf6f35b3b7756b8095789c1e18674bcf2f6
14-
- name: Start PMG proxy
15-
uses: safedep/pmg@v1
16-
with:
17-
server-mode: true
18-
api-key: ${{ secrets.PMG_PUBLIC_REPOS_TOKEN }}
19-
tenant-id: ${{ secrets.PMG_TENANT_ID }}
2012
- uses: returntocorp/semgrep-action@v1
2113
with:
2214
auditOn: push
2315
publishToken: ${{ secrets.SEMGREP_APP_TOKEN }}
2416
publishDeployment: 339
2517
env:
26-
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
27-
- name: Enforce PMG policy
28-
if: always()
29-
run: pmg proxy stop --fail-on-violation
18+
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

‎.github/workflows/sqs_app.yaml‎

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,15 +8,14 @@ jobs:
88
irc:
99
runs-on: ubuntu-latest
1010
name: Build SQS demo app image
11-
permissions:
12-
contents: read
1311
steps:
1412
- name: checkout
1513
id: checkout
1614
uses: actions/checkout@v2
1715
with:
1816
submodules: true
19-
- name: Start PMG proxy
17+
- name: Setup PMG proxy
18+
id: pmg-setup
2019
uses: safedep/pmg@v1
2120
with:
2221
server-mode: true
@@ -46,4 +45,9 @@ jobs:
4645
file: ./example/apps/sqs/Dockerfile
4746
- name: Enforce PMG policy
4847
if: always()
49-
run: pmg proxy stop --fail-on-violation
48+
run: |
49+
if [ "${{ steps.pmg-setup.outcome }}" = "success" ]; then
50+
pmg proxy stop --fail-on-violation
51+
else
52+
pmg proxy stop || true
53+
fi

‎.github/workflows/sqs_configurator.yaml‎

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,15 +8,14 @@ jobs:
88
sqsc:
99
runs-on: ubuntu-latest
1010
name: Build SQS configurator image
11-
permissions:
12-
contents: read
1311
steps:
1412
- name: checkout
1513
id: checkout
1614
uses: actions/checkout@v2
1715
with:
1816
submodules: true
19-
- name: Start PMG proxy
17+
- name: Setup PMG proxy
18+
id: pmg-setup
2019
uses: safedep/pmg@v1
2120
with:
2221
server-mode: true
@@ -46,4 +45,9 @@ jobs:
4645
file: ./hooks/sqs_configurator/Dockerfile
4746
- name: Enforce PMG policy
4847
if: always()
49-
run: pmg proxy stop --fail-on-violation
48+
run: |
49+
if [ "${{ steps.pmg-setup.outcome }}" = "success" ]; then
50+
pmg proxy stop --fail-on-violation
51+
else
52+
pmg proxy stop || true
53+
fi

0 commit comments

Comments
 (0)