This page lists the workflows in this repository and their caller-facing contracts.
Callers of the project-routing workflows use these credentials to dispatch the internal implementations:
PROJECT_ROUTER_BOT_APP_ID(Actions variable, org-level)PROJECT_ROUTER_BOT_PRIVATE_KEY(Actions secret, org-level)
Important
For public caller repositories that run these workflows automatically on issue or pull request creation events, those events must be limited to trusted actors. In practice, require collaborator-only issue or pull request creation, or an equivalent repository control. Configure this in the caller repository at https://github.com/<owner>/<repo>/settings under Settings > General > Features, then use Issues > Issue permissions or Pull requests > Pull request permissions as appropriate.
Project-handling credentials are used internally and are not required from callers. The project workflows verify that the requested organization matches this repository owner and that the submitted issue or pull request node ID resolves back to the repository named in the request. See GitHub Apps reference.
Workflow file: .github/workflows/add-issue-to-projects.yml
workflow_call
implementation_ref: optional override. Branch or tag ref to use when dispatching.github/workflows/add-issue-to-projects-impl.yml.repository: required. Source repository name.issue_node_id: required. Node ID of the issue to add.project_field_values: required. JSON array of project mappings.organization: optional compatibility field; if provided it is forwarded to the implementation workflow.
- Validates the dispatch credentials and required dispatch inputs.
- Mints a dispatch token with
actions: writeondatasciencecampus/github-actions. - Dispatches
.github/workflows/add-issue-to-projects-impl.ymlwith the supplied inputs.
- This is the public reusable workflow for the issue flow.
- If
implementation_refis omitted, the workflow readsconfigs/implementation-ref.jsonfrom the invoked workflow revision, turnsimplementation_versioninto av...tag, and dispatches that release-managed ref. - Use
implementation_refonly to override that release-managed dispatch target with a specific branch or tag. - It is most useful for workflows in this repository, or same-organization callers that intentionally provide the dispatch secret to the public reusable workflow.
.github/workflows/test-add-issue-to-projects-reusable.ymlmanually exercises this reusable workflow withworkflow_dispatchinputs.- The same test workflow also runs automatically on
issues.openedin this repository. - For automatic runs, it derives
project_field_valuesfrom the repository Actions variablePROJECT_NUMBER.
Workflow file: .github/workflows/add-issue-to-projects-impl.yml
workflow_dispatch via POST /repos/datasciencecampus/github-actions/actions/workflows/add-issue-to-projects-impl.yml/dispatches
issue_node_id: required. Node ID of the issue to add.project_field_values: required. JSON array of project mappings.repository: required. Source repository name.organization: optional compatibility field; if provided it must match the owner of this repository.
Each entry must have project. field and value are optional — if omitted the issue is added with no field update.
[{"project": 1234}]
[{"project": 1234, "field": "Status", "value": "Backlog"}]- Validates credentials.
- Verifies that the submitted issue node ID belongs to the named source repository.
- Parses and validates all mapping entries.
- For each entry: adds the issue to the project if not already present.
- If
fieldis specified: sets the field value on the project item.
contents: read
Workflow file: .github/workflows/add-pr-to-projects.yml
workflow_call
implementation_ref: optional override. Branch or tag ref to use when dispatching.github/workflows/add-pr-to-projects-impl.yml.repository: required. Source repository name.pull_request_node_id: required. Node ID of the pull request to add.project_field_values: required. JSON array of project mappings.organization: optional compatibility field; if provided it is forwarded to the implementation workflow.
- Validates the dispatch credentials and required dispatch inputs.
- Mints a dispatch token with
actions: writeondatasciencecampus/github-actions. - Dispatches
.github/workflows/add-pr-to-projects-impl.ymlwith the supplied inputs.
- This is the public reusable workflow for the pull request flow.
- If
implementation_refis omitted, the workflow readsconfigs/implementation-ref.jsonfrom the invoked workflow revision, turnsimplementation_versioninto av...tag, and dispatches that release-managed ref. - Use
implementation_refonly to override that release-managed dispatch target with a specific branch or tag.
.github/workflows/test-add-pr-to-projects-reusable.ymlmanually exercises this reusable workflow withworkflow_dispatchinputs.- The same test workflow also runs automatically on
pull_request.openedandpull_request.reopenedin this repository. - For automatic runs, it derives
project_field_valuesfrom the repository Actions variablePROJECT_NUMBER, usingStatus = Reviewas the default field mapping.
Workflow file: .github/workflows/add-pr-to-projects-impl.yml
workflow_dispatch via POST /repos/datasciencecampus/github-actions/actions/workflows/add-pr-to-projects-impl.yml/dispatches
pull_request_node_id: required. Node ID of the pull request to add.project_field_values: required. JSON array of project mappings.repository: required. Source repository name.organization: optional compatibility field; if provided it must match the owner of this repository.
Each entry must have project, field, and value.
[{ "project": 1234, "field": "Status", "value": "Review" }]- Validates credentials.
- Verifies that the submitted pull request node ID belongs to the named source repository.
- Parses and validates all mapping entries (project, field, and value required).
- For each entry: adds the pull request to the project if not already present.
- Sets the configured field value on the project item.
contents: readpull-requests: read
Workflow file: .github/workflows/security-analysis.yml
Orchestrates GitHub Actions security analysis with zizmor and infrastructure security scanning with checkov.
pushtomainpull_requestagainstmainworkflow_call(for reuse in other repositories)
zizmor-config: optional string. Path to zizmor config file in the caller's checkout. Defaults to./configs/zizmor.yaml.zizmor-persona: optional string. Persona for zizmor analysis:regular,pedantic, orauditor. Defaults toauditor.checkov-config: optional string. Path to checkov config file in the caller's checkout. Defaults to./configs/checkov.yml.advanced-security: optional boolean. Upload SARIF results to GitHub Advanced Security. Tri-state behavior:- Omitted (default): Auto-detect based on repository privacy (true for public, false for private)
true: Always uploadfalse: Never upload
- Runs
zizmorto scan GitHub Actions workflows for security misconfigurations. - Runs
checkovto scan infrastructure-as-code and configuration files. - Both tools run in parallel and upload SARIF results to GitHub Advanced Security (when enabled).
- Reads config files from the caller's checkout at the configured paths.
- Default triggers: On this repository's
pushandpull_requestevents formain, the config files in this repository are used (zizmor persona:auditor, both tools enabled). Callers usingworkflow_callmust provide the config files in their own checkout or set the config path inputs. - Customization: Callers can override config paths, persona, and advanced-security via
workflow_callinputs. - Tri-state logic:
advanced-securityinput is tri-state (omit = auto-detect, true = enable, false = disable). This logic is computed by the orchestrator and passed to child workflows. - Concurrency: Managed at the orchestrator level to prevent duplicate runs.
- Child workflows:
zizmor.ymlandcheckov.ymlexposeworkflow_calland can be called directly, but callers should usesecurity-analysis.ymlto run both tools with the shared trigger, concurrency, and SARIF policy.
Workflow file: .github/workflows/terraform-quality.yml
workflow_call only.
terraform-dirs: optional JSON array of repository-relative directories to validate. Defaults to the four standard environment directories. Input validation rejects non-arrays, non-string entries, empty paths, absolute paths, and paths containing...terraform-version: optional string. Terraform version to install. Defaults to1.14.3.run-fmt: optional boolean. Run the Terraform formatting check. Defaults totrue.run-validate: optional boolean. Runterraform init -backend=falseandterraform validatefor each configured directory. Defaults totrue.run-tflint: optional boolean. Run TFLint. Defaults totrue.continue_on_error: optional boolean intended for negative testing. Defaults tofalse; when enabled, failures in the validation checks do not fail the workflow.
- Validates the
terraform-dirsinput before running checks. - Runs
terraform fmt -check -recursive terraformwhen formatting is enabled. - Runs
terraform init -backend=falseandterraform validatefor each configured directory when validation is enabled. - Runs TFLint recursively under
terraform/when enabled, usingconfigs/.tflint.hclfrom the caller's checkout.
terraform-dirscontrols onlyterraform validate; formatting and TFLint scan the entireterraform/directory.- The caller must provide
configs/.tflint.hclwhen TFLint is enabled. - The workflow exposes a
validation-passedoutput indicating whetherterraform-dirsinput validation succeeded.
contents: read
Workflow file: .github/workflows/zizmor.yml
GitHub Actions workflow security scanning using zizmor.
workflow_call only (called by security-analysis.yml)
config-path: optional string. Path to zizmor config file. Defaults to./configs/zizmor.yaml.persona: optional string. Analysis persona:regular,pedantic, orauditor. Defaults toauditor.advanced-security: optional boolean. Upload SARIF results to GitHub Advanced Security. Defaults tofalse. Callers should pass the tri-state value computed by the orchestrator.
- This is an internal workflow; call via
security-analysis.ymlinstead. - Tri-state logic (auto-detect based on repository privacy) is implemented in
security-analysis.yml.
- Checks out the repository.
- Runs zizmor with the specified config and persona.
- Uploads SARIF results (when advanced-security is enabled).
actions: readcontents: readsecurity-events: write
Workflow file: .github/workflows/checkov.yml
Infrastructure-as-code and configuration security scanning using checkov.
workflow_call only (called by security-analysis.yml)
config-path: optional string. Path to checkov config file. Defaults to./configs/checkov.yml.advanced-security: optional boolean. Upload SARIF results to GitHub Advanced Security. Defaults tofalse. Callers should pass the tri-state value computed by the orchestrator.
- Checks out the repository.
- Runs checkov with the specified config file.
- Outputs results as CLI and SARIF formats.
- Uploads SARIF results (when advanced-security is enabled).
- This is an internal workflow; call via
security-analysis.ymlinstead. - Tri-state logic (auto-detect based on repository privacy) is implemented in
security-analysis.yml.
contents: readsecurity-events: write