Repository navigation
chore(security): add ReversingLabs malware scan workflow - #420
nirmal-joishi-a0 wants to merge 1 commit into
Conversation
|
The previous remediation PR for this workflow was closed. This is an organization-enforced, mandatory security-hardening workflow, so we've opened a new PR to replace the discarded one. Please review the changes and update them if needed. Note: this workflow is untested in this repo — confirm it triggers and passes before merging; do not merge on a green result alone. To permanently decline this workflow, closing this PR is not enough (a fresh replacement will be opened): close it AND add one of these labels — |
|
@auth0/project-dx-sdks-engineer-codeowner please review the files in the PR. This automated security-hardening workflow is untested in this repo — before merging, confirm it triggers and passes (and is not silently ignoring failures); do not merge on a green result alone. |
|
An internal service ticket has been filed for the owning team to review and merge this PR. |
3cf6111 to
8f86d04
Compare
✏️ Changes
This pull request adds a security hardening workflow. No functional changes are introduced.
ReversingLabs Malware Scan
This PR adds
.github/workflows/rl.yml. It is a reusable workflow (workflow_call) that wraps the okta-approvedauth0/devsecops-tooling/.github/actions/rl-scanaction.Steps to wire it up
rl.ymlwith all steps that produce your artifact at theartifact-pathyou pass — toolchain setup, dependency install, compile, and package.artifact-pathmust be a concrete file — the action's[ -f ]check rejects globs/directories and a missing path fails the job.Required org secrets — all 8 must be present
The
rl-scanaction declares all 8 as required inputs — if any is missing or empty the scan job fails. Confirm each is available to this repo (set at theauth0/org level) before merging:RLSECURE_LICENSE,RLSECURE_SITE_KEY— ReversingLabs license + site keySIGNAL_HANDLER_TOKEN,SIGNAL_HANDLER_DOMAIN— scan telemetry auth + endpointPRODSEC_TOOLS_ARN— AWS IAM role assumed via OIDC (see below)PRODSEC_TOOLS_USER,PRODSEC_TOOLS_TOKEN,PRODSEC_PYTHON_TOOLS_REPO— private ProdSec Python index creds + URLAWS OIDC trust — required, not just a secret
The action authenticates to AWS by assuming
PRODSEC_TOOLS_ARNvia GitHub OIDC (no static keys), so two things must be in place:id-token: write(mints the OIDC token) andcontents: read. Removingid-token: writebreaks the AWS step.Configure AWS credentialsfails even with every secret set — an infra change the repo/org owner must arrange before merging.🟠 Declining this workflow
This is an organization-enforced security-hardening workflow, so closing this PR is not enough — the tool treats a plain close as a discard and opens a fresh replacement PR on its next run.
To permanently decline this category, a maintainer must close this PR and add one of these labels to it:
remediation: not-requiredremediation: not-applicableApplying a label requires write, triage, or admin access, so the label is a trusted maintainer signal. Once a closed PR carries one of these labels, the tool respects the decline and will not reopen a replacement.
🔮 Type of Change
🔗 References
This change applies a standard automated security-scanning workflow as part of routine repository hardening.
📖 Documentation
No user-facing changes have been introduced.
🎯 Testing
remediation: not-applicable.🚀 Deployment
🔥 Rollback
Reverting this PR removes the added workflow file — no further action required.
Supersedes #418, a previous remediation PR for this workflow that was closed. This workflow is organization-enforced, so a fresh PR was opened to replace it.