chore: add ReversingLabs malware scan workflow - #1412
Closed
nirmal-joishi-auth0 wants to merge 1 commit into
Closed
nirmal-joishi-auth0 wants to merge 1 commit into
nirmal-joishi-auth0 wants to merge 1 commit into
Conversation
Author
|
The previous remediation PR for this workflow was closed. This is an organization-enforced, mandatory security-hardening workflow, so we've opened a new PR to replace the discarded one. Please review the changes, update them if needed, and merge once all checks are green. |
Author
|
@auth0/project-dx-sdks-engineer-codeowner please review the files in the PR and merge the PR if all is green. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
✏️ Changes
This pull request adds a security hardening workflow. No functional changes are introduced.
ReversingLabs Malware Scan
This PR adds
.github/workflows/rl.yml. It is a reusable workflow (workflow_call) that wraps the okta-approvedauth0/devsecops-tooling/.github/actions/rl-scanaction — it does not run on its own.Steps to wire it up
rl.ymlwith all steps required to produce your artifact at the path you pass asartifact-path— this includes toolchain setup (e.g.actions/setup-node,setup-go,setup-dotnet), dependency installation, compilation, and packaging (e.g.tar,zip,docker save).artifact-pathmust be a concrete file path — the action's internal[ -f ]check does not expand globs or accept directories. A missing or incorrect path fails the job.Required org secrets
RLSECURE_LICENSE,RLSECURE_SITE_KEYSIGNAL_HANDLER_TOKEN,SIGNAL_HANDLER_DOMAINPRODSEC_TOOLS_ARN,PRODSEC_TOOLS_USER,PRODSEC_TOOLS_TOKENPRODSEC_PYTHON_TOOLS_REPO🔮 Type of Change
🔗 References
This change applies a standard automated security-scanning workflow as part of routine repository hardening.
📖 Documentation
No user-facing changes have been introduced.
🎯 Testing
This change adds a CI workflow only; validated by the workflow running on this PR.
🚀 Deployment
🔥 Rollback
Reverting this PR removes the added workflow file — no further action required.