Reusable GitHub Actions workflows and composite actions for the sogeor platform.
- One place for CI logic shared by every repository of the sogeor organization.
- Secure by default: minimal
permissions,persist-credentials: false, actions pinned by full SHA, tool downloads verified by SHA-256, inputs passed to shell only throughenv:. - Exact versions: callers pin a release by full commit SHA with the tag in a comment; Renovate updates it.
- Tested:
self-testcalls every workflow on this repository. - Workflows:
docs(markdownlint, lychee, MkDocs),security-lite(gitleaks, Trivy, Semgrep, Checkov),scorecard(OpenSSF Scorecard),packer-build,tofu-gitlab-state(GitLab-managed state, plan comments, Conftest),mirror-to-gitlab. - Actions:
export-env,setup-mesh(WireGuard),setup-tofu-http-backend,pr-comment. - Infrastructure credentials stay in the caller's GitHub Environment, usable only from the default branch.
flowchart LR
subgraph callers[Caller repositories]
I[images]
M[management]
O[other repositories]
end
W[sogeor/workflows<br/>reusable workflows<br/>composite actions]
I & M & O -->|uses: ...@sha # vX.Y.Z| W
W --> GH[GitHub-hosted runners]
jobs:
docs:
uses: sogeor/workflows/.github/workflows/docs.yml@<full-sha> # vX.Y.ZMore examples: Usage; first release v0.1.0.
| Page | What is inside |
|---|---|
| Overview | Purpose, contents, place in the platform |
| Getting started | Calling a workflow from your repository |
| Repository setup | GitHub settings for this repository and for callers |
| Configuration | Every input, secret and output |
| Usage | Typical calls |
| Operations | Releases, updates, rollback |
| Architecture | Structure, interface contract, versioning |
| Security | Guarantees, limits, assurance case |
| Troubleshooting | Symptoms, causes and fixes |
| Reference | All workflows and actions |
| Decisions | Architecture decision records |
Preview locally: pip install --require-hashes -r .github/requirements-docs.txt && mkdocs serve.
| Component | Version |
|---|---|
| Runner image | ubuntu-24.04 |
| actions/checkout | v7.0.1 |
| actions/upload-artifact | v7.0.2 |
| github/codeql-action | v4.38.3 |
| ossf/scorecard-action | v2.4.4 |
| DavidAnson/markdownlint-cli2-action | v24.2.0 |
| lycheeverse/lychee-action | v2.9.0 |
| actionlint | 1.7.12 |
| gitleaks | 8.30.1 |
| Trivy | 0.75.0 |
| Semgrep (image) | 1.180.0-nonroot |
| Checkov (image) | 3.3.26 |
| OpenTofu | 1.13.1 |
| tflint | 0.64.0 |
| conftest | 0.71.1 |
| Packer (default) | 1.16.1 |
| hashicorp/setup-packer | v3.4.0 |
| zizmor | 1.30.1 |
| yamllint | 1.38.0 |
| mkdocs-material | 9.7.7 |
See CONTRIBUTING.md, GOVERNANCE.md and CODE_OF_CONDUCT.md.
Report vulnerabilities privately as described in SECURITY.md.