Skip to content
sogeorPublic

About

Reusable GitHub Actions workflows and composite actions for the sogeor DevSecOps platform: pinned, least-privilege CI building blocks.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

workflows

Reusable GitHub Actions workflows and composite actions for the sogeor platform.

validate self-test OpenSSF Scorecard License

Overview

  • One place for CI logic shared by every repository of the sogeor organization.
  • Secure by default: minimal permissions, persist-credentials: false, actions pinned by full SHA, tool downloads verified by SHA-256, inputs passed to shell only through env:.
  • Exact versions: callers pin a release by full commit SHA with the tag in a comment; Renovate updates it.
  • Tested: self-test calls every workflow on this repository.
  • Workflows: docs (markdownlint, lychee, MkDocs), security-lite (gitleaks, Trivy, Semgrep, Checkov), scorecard (OpenSSF Scorecard), packer-build, tofu-gitlab-state (GitLab-managed state, plan comments, Conftest), mirror-to-gitlab.
  • Actions: export-env, setup-mesh (WireGuard), setup-tofu-http-backend, pr-comment.
  • Infrastructure credentials stay in the caller's GitHub Environment, usable only from the default branch.
flowchart LR
  subgraph callers[Caller repositories]
    I[images]
    M[management]
    O[other repositories]
  end
  W[sogeor/workflows<br/>reusable workflows<br/>composite actions]
  I & M & O -->|uses: ...@sha # vX.Y.Z| W
  W --> GH[GitHub-hosted runners]
Loading

Quick start

jobs:
  docs:
    uses: sogeor/workflows/.github/workflows/docs.yml@<full-sha> # vX.Y.Z

More examples: Usage; first release v0.1.0.

Documentation

Page What is inside
Overview Purpose, contents, place in the platform
Getting started Calling a workflow from your repository
Repository setup GitHub settings for this repository and for callers
Configuration Every input, secret and output
Usage Typical calls
Operations Releases, updates, rollback
Architecture Structure, interface contract, versioning
Security Guarantees, limits, assurance case
Troubleshooting Symptoms, causes and fixes
Reference All workflows and actions
Decisions Architecture decision records

Preview locally: pip install --require-hashes -r .github/requirements-docs.txt && mkdocs serve.

Versions

Component Version
Runner image ubuntu-24.04
actions/checkout v7.0.1
actions/upload-artifact v7.0.2
github/codeql-action v4.38.3
ossf/scorecard-action v2.4.4
DavidAnson/markdownlint-cli2-action v24.2.0
lycheeverse/lychee-action v2.9.0
actionlint 1.7.12
gitleaks 8.30.1
Trivy 0.75.0
Semgrep (image) 1.180.0-nonroot
Checkov (image) 3.3.26
OpenTofu 1.13.1
tflint 0.64.0
conftest 0.71.1
Packer (default) 1.16.1
hashicorp/setup-packer v3.4.0
zizmor 1.30.1
yamllint 1.38.0
mkdocs-material 9.7.7

Contributing

See CONTRIBUTING.md, GOVERNANCE.md and CODE_OF_CONDUCT.md.

Security

Report vulnerabilities privately as described in SECURITY.md.

License

Apache-2.0

About

Reusable GitHub Actions workflows and composite actions for the sogeor DevSecOps platform: pinned, least-privilege CI building blocks.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Used by

Contributors

Languages