-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathaction.yml
More file actions
110 lines (99 loc) · 3.28 KB
/
Copy pathaction.yml
File metadata and controls
110 lines (99 loc) · 3.28 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
name: 'OpSentry Security Scan'
description: 'Scan PRs for security vulnerabilities, code quality issues, and guardrail compliance'
author: 'OpSight Intelligence'
branding:
icon: 'shield'
color: 'blue'
inputs:
scan-type:
description: 'Scan type: security, code-health, governance, all'
required: false
default: 'all'
config-path:
description: 'Path to guardrails.yaml config file'
required: false
default: ''
scan-mode:
description: 'Scan mode: changed (PR files only) or full (all files)'
required: false
default: 'changed'
fail-on:
description: 'Fail the check on: critical, high, medium, low, none'
required: false
default: 'high'
auto-fix:
description: 'Auto-fix safe issues and commit to PR branch'
required: false
default: 'true'
post-comment:
description: 'Post scan results as a PR comment'
required: false
default: 'true'
llm-provider:
description: 'LLM provider for docstring generation: bedrock, anthropic, openai, local, none'
required: false
default: 'none'
outputs:
findings-count:
description: 'Total number of findings'
critical-count:
description: 'Number of critical findings'
high-count:
description: 'Number of high findings'
report-path:
description: 'Path to the JSON report file'
runs:
using: 'composite'
steps:
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: '3.11'
- name: Install dependencies
shell: bash
run: pip install pyyaml jinja2
- name: Checkout OpSentry
uses: actions/checkout@v4
with:
repository: opsight-intelligence/opsentry
path: .opsentry
- name: Run security audit
if: inputs.scan-type == 'all' || inputs.scan-type == 'security'
shell: bash
env:
SCAN_MODE: ${{ inputs.scan-mode }}
SCAN_ROOT: ${{ github.workspace }}
BASE_BRANCH: ${{ github.base_ref }}
run: python3 .opsentry/ai-ci-agents/scripts/security_audit.py
- name: Run code health
if: inputs.scan-type == 'all' || inputs.scan-type == 'code-health'
shell: bash
env:
SCAN_MODE: ${{ inputs.scan-mode }}
SCAN_ROOT: ${{ github.workspace }}
BASE_BRANCH: ${{ github.base_ref }}
USE_LLM: ${{ inputs.llm-provider != 'none' && 'true' || 'false' }}
LLM_PROVIDER: ${{ inputs.llm-provider }}
run: python3 .opsentry/ai-ci-agents/scripts/code_health.py
- name: Run governance check
if: inputs.scan-type == 'all' || inputs.scan-type == 'governance'
shell: bash
env:
SCAN_MODE: ${{ inputs.scan-mode }}
SCAN_ROOT: ${{ github.workspace }}
run: python3 .opsentry/ai-ci-agents/scripts/governance_check.py
- name: Auto-fix
if: inputs.auto-fix == 'true'
shell: bash
env:
SCAN_ROOT: ${{ github.workspace }}
AUTO_COMMIT: 'true'
run: python3 .opsentry/ai-ci-agents/scripts/auto_fix.py
- name: Post PR comment
if: inputs.post-comment == 'true' && github.event_name == 'pull_request'
shell: bash
env:
GITHUB_TOKEN: ${{ github.token }}
GITHUB_REPOSITORY: ${{ github.repository }}
PR_NUMBER: ${{ github.event.pull_request.number }}
run: python3 .opsentry/ai-ci-agents/scripts/report_to_pr.py