Skip to content

chore: add ReversingLabs malware scan workflow - #1412

Closed
nirmal-joishi-auth0 wants to merge 1 commit into
auth0:masterfrom
nirmal-joishi-auth0:security/add-malwarescan
Closed

nirmal-joishi-auth0 wants to merge 1 commit into
auth0:masterfrom
nirmal-joishi-auth0:security/add-malwarescan

Conversation

@nirmal-joishi-auth0

Copy link
Copy Markdown

✏️ Changes

This pull request adds a security hardening workflow. No functional changes are introduced.

ReversingLabs Malware Scan

This PR adds .github/workflows/rl.yml. It is a reusable workflow (workflow_call) that wraps the okta-approved auth0/devsecops-tooling/.github/actions/rl-scan action — it does not run on its own.

⚠️ Before merging, complete the two steps below.

Steps to wire it up

  1. Replace the placeholder build step in rl.yml with all steps required to produce your artifact at the path you pass as artifact-path — this includes toolchain setup (e.g. actions/setup-node, setup-go, setup-dotnet), dependency installation, compilation, and packaging (e.g. tar, zip, docker save).
  2. Add a caller in your release or CI workflow, for example:
    jobs:
      rl-scan:
        uses: ./.github/workflows/rl.yml
        with:
          artifact-name: my-artifact
          artifact-path: dist/my-artifact.tgz   # concrete file path — no globs or directories
          version: ${{ github.event.release.tag_name }}
        secrets: inherit
    artifact-path must be a concrete file path — the action's internal [ -f ] check does not expand globs or accept directories. A missing or incorrect path fails the job.

Required org secrets

  • RLSECURE_LICENSE, RLSECURE_SITE_KEY
  • SIGNAL_HANDLER_TOKEN, SIGNAL_HANDLER_DOMAIN
  • PRODSEC_TOOLS_ARN, PRODSEC_TOOLS_USER, PRODSEC_TOOLS_TOKEN
  • PRODSEC_PYTHON_TOOLS_REPO

🔮 Type of Change

  • Standard

🔗 References

This change applies a standard automated security-scanning workflow as part of routine repository hardening.

  • I explained why this change is needed.

📖 Documentation

No user-facing changes have been introduced.

  • I reflected this change in the (internal and/or user-facing) documentation, or added an explanation for why no documentation update is needed.

🎯 Testing

This change adds a CI workflow only; validated by the workflow running on this PR.

  • This change has integration, unit, or performance test coverage, or I explained why not.

🚀 Deployment

  • This change can support multiple releases of the code serving traffic at the same time.

🔥 Rollback

Reverting this PR removes the added workflow file — no further action required.

  • I explained what the rollback for this change will look like.

@nirmal-joishi-auth0

Copy link
Copy Markdown
Author

The previous remediation PR for this workflow was closed. This is an organization-enforced, mandatory security-hardening workflow, so we've opened a new PR to replace the discarded one. Please review the changes, update them if needed, and merge once all checks are green.

@nirmal-joishi-auth0
nirmal-joishi-auth0 requested a review from a team as a code owner September 28, 2026 06:18
@nirmal-joishi-auth0

Copy link
Copy Markdown
Author

@auth0/project-dx-sdks-engineer-codeowner please review the files in the PR and merge the PR if all is green.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant