-
Notifications
You must be signed in to change notification settings - Fork 8
Expand file tree
/
Copy path.plumber.yaml
More file actions
152 lines (152 loc) · 4.25 KB
/
Copy path.plumber.yaml
File metadata and controls
152 lines (152 loc) · 4.25 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
# Plumber configuration for the sdk-java repository.
# Based on Plumber's built-in defaults (github provider only); every control
# is listed explicitly so none is silently disabled. The only customization is
# the branch protection policy below.
version: "2.0"
github:
controls:
containerImageMustNotUseForbiddenTags:
enabled: true
tags:
- latest
- dev
- development
- staging
- main
- master
containerImagesMustBePinnedByDigest: true
branchMustBeProtected:
enabled: true
namePatterns:
- main
- master
- release/*
- production
- dev
defaultMustBeProtected: true
allowForcePush: false
# This project does not use a CODEOWNERS-based review process, so
# code owner approval is not part of its branch protection policy.
codeOwnerApprovalRequired: false
externalRefsMustNotCollide:
enabled: true
pipelineMustNotEnableDebugTrace:
enabled: true
forbiddenVariables:
- ACTIONS_STEP_DEBUG
- ACTIONS_RUNNER_DEBUG
securityJobsMustNotBeWeakened:
enabled: true
securityJobPatterns:
- '*codeql*'
- '*dependency-review*'
- '*trufflehog*'
- '*gitleaks*'
- '*osv-scanner*'
- '*-sast'
- '*-sast-*'
- '*-scan'
- '*scan*'
- '*-security'
- '*-security-*'
- '*-audit'
- '*-audit-*'
allowFailureMustBeFalse:
enabled: true
rulesMustNotBeRedefined:
enabled: true
whenMustNotBeManual:
enabled: true
pipelineMustNotExecuteUnverifiedScripts:
enabled: true
pipelineMustNotUseDockerInDocker:
enabled: true
detectInsecureDaemon: true
actionsMustBePinnedByCommitSha:
enabled: true
trustedOwners:
- actions
- github
githubActionMustComeFromAuthorizedSources:
enabled: true
trustGithubOfficialActions: true
trustSameOrgActions: true
trustedGithubActions:
- getplumber/plumber
workflowMustNotInjectUserInputInScripts:
enabled: true
workflowMustNotWriteUntrustedContentToGitHubEnv:
enabled: true
workflowMustNotUseDangerousTriggers:
enabled: true
pullRequestTargetMustNotCheckoutHead:
enabled: true
workflowsMustDeclarePermissions:
enabled: true
reusableWorkflowsMustNotInheritSecrets:
enabled: true
workflowMustNotExportEntireSecretsContext:
enabled: true
workflowMustNotGrantPermissionsWriteAll:
enabled: true
actionsMustNotBeArchived:
enabled: true
actionRefsMustExistUpstream:
enabled: true
actionsMustNotCarryKnownCVEs:
enabled: true
actionsMustNotExecuteMutableRemoteCode:
enabled: true
releaseWorkflowsMustNotRestoreUntrustedCache:
enabled: true
publishActions:
- gradle/publish-plugin
cacheActions:
- action: actions/cache
mode: always
- action: actions/cache/restore
mode: always
- action: Swatinem/rust-cache
mode: always
- action: actions/setup-go
mode: default
disableInput: cache
disableValue: false
- action: gradle/actions/setup-gradle
mode: default
disableInput: cache-disabled
disableValue: true
- action: actions/setup-node
mode: opt-in
enableInput: cache
- action: actions/setup-python
mode: opt-in
enableInput: cache
- action: actions/setup-java
mode: opt-in
enableInput: cache
- action: pnpm/action-setup
mode: opt-in
enableInput: cache
- action: docker/build-push-action
mode: opt-in
enableInput: cache-from
enableContains: type=gha
publishScriptPatterns:
- (?i)(npm|pnpm|yarn|bun)\s+publish
- (?i)cargo\s+publish
- (?i)twine\s+upload
- (?i)poetry\s+publish
- (?i)gh\s+release\s+create
- (?i)goreleaser\s+release
- (?i)semantic-release
- (?i)gradlew?\b[^\n]*\bpublish
- (?i)\bmvnw?\b[^\n]*\bdeploy\b
- (?i)dotnet\s+nuget\s+push
- (?i)gem\s+push
- (?i)docker\s+push
publishScriptExcludePatterns:
- (?i)--dry-run
- (?i)publishToMavenLocal
workflowMustIncludeRequiredActions:
enabled: false