Latest commit

History

27 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Studyportals

About Studyportals

Studyportals is the global study choice platform. Since its inception, it was founded to solve student problems, with a strong belief in the value of international experiences – both for individual students and society at large.

Come work for us

.github Repository

This repository contains GitHub Actions workflows that automate key tasks related to security, code quality, and repository maintenance for the Studyportals organization. The workflows include:

  • CodeQL Analysis: Automatic security and code quality scanning using CodeQL.
  • Dependency Scanning: Monitoring project dependencies for vulnerabilities.
  • Goldeneye A CI/CD pipeline generator.
  • Linting: Ensuring code quality by running linters for various languages.
  • Stale Bot: Automatically managing stale issues and pull requests.

Workflows

1. CodeQL Analysis

The CodeQL Analysis workflow automatically scans the codebase for security vulnerabilities and code quality issues using GitHub's CodeQL. It is triggered on push and pull_request events, and can also be scheduled for regular analysis.

  • Trigger:push, pull_request, and scheduled runs (e.g., every Monday at 7 AM).
  • Languages analyzed: JavaScript, TypeScript, Python, and others.
  • Custom queries: Configurable CodeQL queries for additional security checks.

Configuration: The workflow uses a reusable GitHub Actions setup to run CodeQL analysis. You can customize the analysis by specifying the languages you want to analyze. Additional configuration options can be defined in the codeql-config.yml file, placed in the .github/workflows/ directory of the repository.

2. Dependency Scanning

The Dependency Scanning workflow ensures that the project's dependencies are free of known vulnerabilities.

  • Trigger:push and pull_request events.
  • Action: Automatically checks for outdated dependencies or vulnerabilities in the dependency tree.

3. Goldeneye

The Goldeneye workflow is a CI/CD pipeline generator that automates the creation of pipelines.

Trigger: push, pull_request, and manual triggers.

Action: Automatically creates CI/CD pipelines for deployment or testing.

Configuration: Customize the goldeneye.json configuration in the workflow file for service names, AWS accounts, and regions.

3. Linting

The Linting workflow ensures the code adheres to predefined coding standards and best practices. It runs linters for various languages like PHP,JavaScript, TypeScript, Python, etc., based on the project's needs.

  • Trigger:push, pull_request, and manual triggers.
  • Tools used: ESLint for JavaScript/TypeScript, Flake8 for Python, and more.
  • Action: Linting is automatically run whenever code is pushed to the repository or when a pull request is made.

4. Stale Bot

The Stale Bot workflow helps keep the repository clean by automatically marking issues and pull requests as stale if they have not had activity for a specified period. This helps the team focus on active issues and PRs.

  • Trigger: On a schedule (e.g., daily or weekly).
  • Action: Automatically marks issues or PRs as "stale" if no activity has occurred in the last 30 days.
  • Configuration: Can be customized to change the inactivity period, labels, and more.

Setup Instructions

This repository is intended to be used as part of a larger project. To use the workflows in your own project:

  1. Create the .github directory into your repository.
  2. Customize any workflows based on your specific needs (e.g., language versions, linting rules, etc.) See Portal repository for examples.
    • You can copy the workflow files from this repository to your own repository.
    • Make sure to adjust any paths or configurations as necessary.
  3. Modify any settings in the workflows to match the project requirements (e.g., configuring the dependency scanning tool to scan your specific dependency manager)
  4. Push the changes to your repository, and the workflows will automatically run based on their triggers.
  5. Make the GitHub checks required if needed.

Workflow Overview

Workflow NameTrigger EventsDescription
CodeQL Analysispush, pull_request, scheduleScans the code for security vulnerabilities and code quality issues.
Dependency Scanningpush, pull_requestScans dependencies for known vulnerabilities.
Goldeneyepush, pull_request, manualCreates CI/CD piplines
Lintingpush, pull_request, manualRuns linters for various languages to ensure code quality.
Stale BotScheduled (e.g., daily, weekly)Marks issues/PRs as stale if there has been no activity.

Customizing Workflows

CodeQL Analysis

You can customize which languages are analyzed by modifying the languages input in the workflow file. You can also customize the CodeQL queries being run.

NOTE: When adding the CodeQL workflow to a repository for the first time, the workflow might not report results. You may see the following message in the checks

To resolve this issue, run the following commands in Git Bash or WSL terminal:

gh api -H "Accept: application/vnd.github+json" ./repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses --paginate | jq '.[]|select(.category=="/language:actions") | .id '| sed 's/\r//'| xargs -I {} gh api --method DELETE -H "Accept: application/vnd.github+json" -H "X-GitHub-Api-Version: 2022-11-28" /repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses/{}?confirm_delete
gh api -H "Accept: application/vnd.github+json" ./repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses --paginate | jq '.[]|select(.category=="/language:javascript-typescript") | .id '| sed 's/\r//'| xargs -I {} gh api --method DELETE -H "Accept: application/vnd.github+json" -H "X-GitHub-Api-Version: 2022-11-28" /repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses/{}?confirm_delete

Make sure to replace <OrganisationName> and <RepositoryName> with the actual names , and adjust the category value to match the one displayed in your repository's checks.

Important Notes:

  • The CodeQL Analysis workflow itself will typically show as successful, even if vulnerabilities are detected.
  • A separate line item—Code scanning results / CodeQL—will display the actual results of the CodeQL scan.
  • By default, this check will only report a failure if high or critical severity issues are found.
  • You can customize this behavior to fail the check on any level of issue, including medium, low severity or warnings.
  • CodeQL errors and warnings are displayed directly on the pull request, along with GitHub Copilot suggestions to help fix the issue.

Goldeneye

You can customize which aws accounts, regions service names in the goldeneye.json input in the workflow file. Check the specific configuration in the workflow file.

Dependency Scanning

You can enable or configure the dependency scanning to use different tools like npm audit, yarn audit, or any other security tools. Check the specific configuration in the workflow file.

Linting

You can add more linters, configure existing ones, or change the linter rules by modifying the .github/workflows/lint.yml file.

Stale Bot

You can modify the settings in the stale bot workflow to change how often the bot runs and which labels it should apply when marking issues or PRs as stale. The bot's inactivity timeout can also be adjusted.

PULL_REQUEST_TEMPLATE.md

The repository also includes a PULL_REQUEST_TEMPLATE.md file that can be used to standardize pull requests across repositories within the organization. This template ensures that pull requests are well-structured and provide all necessary information for reviewers.

  • Purpose: The template helps contributors provide details such as the problem being solved, the approach taken, and any additional information that may be relevant.

  • Customization: You can modify the template to suit your team's specific needs, such as including sections for testing instructions, related issues, or feature documentation.

This template ensures that every pull request provides clarity on what changes are being made and why, helping maintain consistency and improving communication across your team.

GitHub Copilot Instructions

This repository defines the organization-wide GitHub Copilot review configuration, ensuring that all AI-assisted code reviews across Studyportals repositories are consistent, secure, and aligned with company-wide engineering standards.

The configuration draws from the Knowledge Vault – Good Practices and Quality Standards, and enforces guidelines in the following areas:

  • Code Quality and Security — Enforces standards for readability, maintainability, and secure coding.
  • Dependency and IAM Audits — Validates dependency health and adherence to least-privilege principles.
  • Secure Coding Practices — Covers PHP, TypeScript, AWS SDK/CDK, and cloud infrastructure.
  • Testing and Validation — Ensures adequate test coverage, reliability, and adherence to company testing standards.
  • Architecture and Conventions — Promotes consistent naming, documentation, and structural design patterns across all projects.

By defining these standards centrally, Copilot provides reviewers and contributors with automated, organization-aligned feedback, helping to maintain high code quality and security across all repositories.

Note:

  • By default, Copilot reviews only pull requests marked as “Ready for Review.”
  • To enable Copilot reviews for draft pull requests, configure it in the rulesets of the repository’s Copilot settings under “Review draft pull requests.”
  • Copilot reviews each pull request only once, unless explicitly configured to re-review after every push.
  • If a repository is configured to automatically request a Copilot review for all new pull requests, the premium review usage is applied to the quota of the pull request author.
  • If the pull request is created by GitHub Actions or a bot, the usage is applied to the user who triggered the workflow (if identifiable) or to the designated billing owner.
  • When your monthly quota of premium Copilot review requests is reached, further automated reviews will be unavailable until the quota resets — unless your plan is upgraded or additional premium requests are enabled.

Contributing

Feel free to fork this repository, modify the workflows, and submit pull requests. If you want to improve or add additional workflows, such as testing, deployment, or notifications, feel free to open an issue or PR.

NOTE: You can find examples of the custom workflow in the Portal repository under the .github/workflows directory.

About

Studyportals public organization repository

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Latest commit

History

27 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Studyportals

About Studyportals

Studyportals is the global study choice platform. Since its inception, it was founded to solve student problems, with a strong belief in the value of international experiences – both for individual students and society at large.

Come work for us

.github Repository

This repository contains GitHub Actions workflows that automate key tasks related to security, code quality, and repository maintenance for the Studyportals organization. The workflows include:

  • CodeQL Analysis: Automatic security and code quality scanning using CodeQL.
  • Dependency Scanning: Monitoring project dependencies for vulnerabilities.
  • Goldeneye A CI/CD pipeline generator.
  • Linting: Ensuring code quality by running linters for various languages.
  • Stale Bot: Automatically managing stale issues and pull requests.

Workflows

1. CodeQL Analysis

The CodeQL Analysis workflow automatically scans the codebase for security vulnerabilities and code quality issues using GitHub's CodeQL. It is triggered on push and pull_request events, and can also be scheduled for regular analysis.

  • Trigger:push, pull_request, and scheduled runs (e.g., every Monday at 7 AM).
  • Languages analyzed: JavaScript, TypeScript, Python, and others.
  • Custom queries: Configurable CodeQL queries for additional security checks.

Configuration: The workflow uses a reusable GitHub Actions setup to run CodeQL analysis. You can customize the analysis by specifying the languages you want to analyze. Additional configuration options can be defined in the codeql-config.yml file, placed in the .github/workflows/ directory of the repository.

2. Dependency Scanning

The Dependency Scanning workflow ensures that the project's dependencies are free of known vulnerabilities.

  • Trigger:push and pull_request events.
  • Action: Automatically checks for outdated dependencies or vulnerabilities in the dependency tree.

3. Goldeneye

The Goldeneye workflow is a CI/CD pipeline generator that automates the creation of pipelines.

Trigger: push, pull_request, and manual triggers.

Action: Automatically creates CI/CD pipelines for deployment or testing.

Configuration: Customize the goldeneye.json configuration in the workflow file for service names, AWS accounts, and regions.

3. Linting

The Linting workflow ensures the code adheres to predefined coding standards and best practices. It runs linters for various languages like PHP,JavaScript, TypeScript, Python, etc., based on the project's needs.

  • Trigger:push, pull_request, and manual triggers.
  • Tools used: ESLint for JavaScript/TypeScript, Flake8 for Python, and more.
  • Action: Linting is automatically run whenever code is pushed to the repository or when a pull request is made.

4. Stale Bot

The Stale Bot workflow helps keep the repository clean by automatically marking issues and pull requests as stale if they have not had activity for a specified period. This helps the team focus on active issues and PRs.

  • Trigger: On a schedule (e.g., daily or weekly).
  • Action: Automatically marks issues or PRs as "stale" if no activity has occurred in the last 30 days.
  • Configuration: Can be customized to change the inactivity period, labels, and more.

Setup Instructions

This repository is intended to be used as part of a larger project. To use the workflows in your own project:

  1. Create the .github directory into your repository.
  2. Customize any workflows based on your specific needs (e.g., language versions, linting rules, etc.) See Portal repository for examples.
    • You can copy the workflow files from this repository to your own repository.
    • Make sure to adjust any paths or configurations as necessary.
  3. Modify any settings in the workflows to match the project requirements (e.g., configuring the dependency scanning tool to scan your specific dependency manager)
  4. Push the changes to your repository, and the workflows will automatically run based on their triggers.
  5. Make the GitHub checks required if needed.

Workflow Overview

Workflow NameTrigger EventsDescription
CodeQL Analysispush, pull_request, scheduleScans the code for security vulnerabilities and code quality issues.
Dependency Scanningpush, pull_requestScans dependencies for known vulnerabilities.
Goldeneyepush, pull_request, manualCreates CI/CD piplines
Lintingpush, pull_request, manualRuns linters for various languages to ensure code quality.
Stale BotScheduled (e.g., daily, weekly)Marks issues/PRs as stale if there has been no activity.

Customizing Workflows

CodeQL Analysis

You can customize which languages are analyzed by modifying the languages input in the workflow file. You can also customize the CodeQL queries being run.

NOTE: When adding the CodeQL workflow to a repository for the first time, the workflow might not report results. You may see the following message in the checks

To resolve this issue, run the following commands in Git Bash or WSL terminal:

gh api -H "Accept: application/vnd.github+json" ./repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses --paginate | jq '.[]|select(.category=="/language:actions") | .id '| sed 's/\r//'| xargs -I {} gh api --method DELETE -H "Accept: application/vnd.github+json" -H "X-GitHub-Api-Version: 2022-11-28" /repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses/{}?confirm_delete
gh api -H "Accept: application/vnd.github+json" ./repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses --paginate | jq '.[]|select(.category=="/language:javascript-typescript") | .id '| sed 's/\r//'| xargs -I {} gh api --method DELETE -H "Accept: application/vnd.github+json" -H "X-GitHub-Api-Version: 2022-11-28" /repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses/{}?confirm_delete

Make sure to replace <OrganisationName> and <RepositoryName> with the actual names , and adjust the category value to match the one displayed in your repository's checks.

Important Notes:

  • The CodeQL Analysis workflow itself will typically show as successful, even if vulnerabilities are detected.
  • A separate line item—Code scanning results / CodeQL—will display the actual results of the CodeQL scan.
  • By default, this check will only report a failure if high or critical severity issues are found.
  • You can customize this behavior to fail the check on any level of issue, including medium, low severity or warnings.
  • CodeQL errors and warnings are displayed directly on the pull request, along with GitHub Copilot suggestions to help fix the issue.

Goldeneye

You can customize which aws accounts, regions service names in the goldeneye.json input in the workflow file. Check the specific configuration in the workflow file.

Dependency Scanning

You can enable or configure the dependency scanning to use different tools like npm audit, yarn audit, or any other security tools. Check the specific configuration in the workflow file.

Linting

You can add more linters, configure existing ones, or change the linter rules by modifying the .github/workflows/lint.yml file.

Stale Bot

You can modify the settings in the stale bot workflow to change how often the bot runs and which labels it should apply when marking issues or PRs as stale. The bot's inactivity timeout can also be adjusted.

PULL_REQUEST_TEMPLATE.md

The repository also includes a PULL_REQUEST_TEMPLATE.md file that can be used to standardize pull requests across repositories within the organization. This template ensures that pull requests are well-structured and provide all necessary information for reviewers.

  • Purpose: The template helps contributors provide details such as the problem being solved, the approach taken, and any additional information that may be relevant.

  • Customization: You can modify the template to suit your team's specific needs, such as including sections for testing instructions, related issues, or feature documentation.

This template ensures that every pull request provides clarity on what changes are being made and why, helping maintain consistency and improving communication across your team.

GitHub Copilot Instructions

This repository defines the organization-wide GitHub Copilot review configuration, ensuring that all AI-assisted code reviews across Studyportals repositories are consistent, secure, and aligned with company-wide engineering standards.

The configuration draws from the Knowledge Vault – Good Practices and Quality Standards, and enforces guidelines in the following areas:

  • Code Quality and Security — Enforces standards for readability, maintainability, and secure coding.
  • Dependency and IAM Audits — Validates dependency health and adherence to least-privilege principles.
  • Secure Coding Practices — Covers PHP, TypeScript, AWS SDK/CDK, and cloud infrastructure.
  • Testing and Validation — Ensures adequate test coverage, reliability, and adherence to company testing standards.
  • Architecture and Conventions — Promotes consistent naming, documentation, and structural design patterns across all projects.

By defining these standards centrally, Copilot provides reviewers and contributors with automated, organization-aligned feedback, helping to maintain high code quality and security across all repositories.

Note:

  • By default, Copilot reviews only pull requests marked as “Ready for Review.”
  • To enable Copilot reviews for draft pull requests, configure it in the rulesets of the repository’s Copilot settings under “Review draft pull requests.”
  • Copilot reviews each pull request only once, unless explicitly configured to re-review after every push.
  • If a repository is configured to automatically request a Copilot review for all new pull requests, the premium review usage is applied to the quota of the pull request author.
  • If the pull request is created by GitHub Actions or a bot, the usage is applied to the user who triggered the workflow (if identifiable) or to the designated billing owner.
  • When your monthly quota of premium Copilot review requests is reached, further automated reviews will be unavailable until the quota resets — unless your plan is upgraded or additional premium requests are enabled.

Contributing

Feel free to fork this repository, modify the workflows, and submit pull requests. If you want to improve or add additional workflows, such as testing, deployment, or notifications, feel free to open an issue or PR.

NOTE: You can find examples of the custom workflow in the Portal repository under the .github/workflows directory.

About

Studyportals public organization repository

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

27 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Studyportals

About Studyportals

Studyportals is the global study choice platform. Since its inception, it was founded to solve student problems, with a strong belief in the value of international experiences – both for individual students and society at large.

Come work for us

.github Repository

This repository contains GitHub Actions workflows that automate key tasks related to security, code quality, and repository maintenance for the Studyportals organization. The workflows include:

  • CodeQL Analysis: Automatic security and code quality scanning using CodeQL.
  • Dependency Scanning: Monitoring project dependencies for vulnerabilities.
  • Goldeneye A CI/CD pipeline generator.
  • Linting: Ensuring code quality by running linters for various languages.
  • Stale Bot: Automatically managing stale issues and pull requests.

Workflows

1. CodeQL Analysis

The CodeQL Analysis workflow automatically scans the codebase for security vulnerabilities and code quality issues using GitHub's CodeQL. It is triggered on push and pull_request events, and can also be scheduled for regular analysis.

  • Trigger:push, pull_request, and scheduled runs (e.g., every Monday at 7 AM).
  • Languages analyzed: JavaScript, TypeScript, Python, and others.
  • Custom queries: Configurable CodeQL queries for additional security checks.

Configuration: The workflow uses a reusable GitHub Actions setup to run CodeQL analysis. You can customize the analysis by specifying the languages you want to analyze. Additional configuration options can be defined in the codeql-config.yml file, placed in the .github/workflows/ directory of the repository.

2. Dependency Scanning

The Dependency Scanning workflow ensures that the project's dependencies are free of known vulnerabilities.

  • Trigger:push and pull_request events.
  • Action: Automatically checks for outdated dependencies or vulnerabilities in the dependency tree.

3. Goldeneye

The Goldeneye workflow is a CI/CD pipeline generator that automates the creation of pipelines.

Trigger: push, pull_request, and manual triggers.

Action: Automatically creates CI/CD pipelines for deployment or testing.

Configuration: Customize the goldeneye.json configuration in the workflow file for service names, AWS accounts, and regions.

3. Linting

The Linting workflow ensures the code adheres to predefined coding standards and best practices. It runs linters for various languages like PHP,JavaScript, TypeScript, Python, etc., based on the project's needs.

  • Trigger:push, pull_request, and manual triggers.
  • Tools used: ESLint for JavaScript/TypeScript, Flake8 for Python, and more.
  • Action: Linting is automatically run whenever code is pushed to the repository or when a pull request is made.

4. Stale Bot

The Stale Bot workflow helps keep the repository clean by automatically marking issues and pull requests as stale if they have not had activity for a specified period. This helps the team focus on active issues and PRs.

  • Trigger: On a schedule (e.g., daily or weekly).
  • Action: Automatically marks issues or PRs as "stale" if no activity has occurred in the last 30 days.
  • Configuration: Can be customized to change the inactivity period, labels, and more.

Setup Instructions

This repository is intended to be used as part of a larger project. To use the workflows in your own project:

  1. Create the .github directory into your repository.
  2. Customize any workflows based on your specific needs (e.g., language versions, linting rules, etc.) See Portal repository for examples.
    • You can copy the workflow files from this repository to your own repository.
    • Make sure to adjust any paths or configurations as necessary.
  3. Modify any settings in the workflows to match the project requirements (e.g., configuring the dependency scanning tool to scan your specific dependency manager)
  4. Push the changes to your repository, and the workflows will automatically run based on their triggers.
  5. Make the GitHub checks required if needed.

Workflow Overview

Workflow NameTrigger EventsDescription
CodeQL Analysispush, pull_request, scheduleScans the code for security vulnerabilities and code quality issues.
Dependency Scanningpush, pull_requestScans dependencies for known vulnerabilities.
Goldeneyepush, pull_request, manualCreates CI/CD piplines
Lintingpush, pull_request, manualRuns linters for various languages to ensure code quality.
Stale BotScheduled (e.g., daily, weekly)Marks issues/PRs as stale if there has been no activity.

Customizing Workflows

CodeQL Analysis

You can customize which languages are analyzed by modifying the languages input in the workflow file. You can also customize the CodeQL queries being run.

NOTE: When adding the CodeQL workflow to a repository for the first time, the workflow might not report results. You may see the following message in the checks

To resolve this issue, run the following commands in Git Bash or WSL terminal:

gh api -H "Accept: application/vnd.github+json" ./repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses --paginate | jq '.[]|select(.category=="/language:actions") | .id '| sed 's/\r//'| xargs -I {} gh api --method DELETE -H "Accept: application/vnd.github+json" -H "X-GitHub-Api-Version: 2022-11-28" /repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses/{}?confirm_delete
gh api -H "Accept: application/vnd.github+json" ./repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses --paginate | jq '.[]|select(.category=="/language:javascript-typescript") | .id '| sed 's/\r//'| xargs -I {} gh api --method DELETE -H "Accept: application/vnd.github+json" -H "X-GitHub-Api-Version: 2022-11-28" /repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses/{}?confirm_delete

Make sure to replace <OrganisationName> and <RepositoryName> with the actual names , and adjust the category value to match the one displayed in your repository's checks.

Important Notes:

  • The CodeQL Analysis workflow itself will typically show as successful, even if vulnerabilities are detected.
  • A separate line item—Code scanning results / CodeQL—will display the actual results of the CodeQL scan.
  • By default, this check will only report a failure if high or critical severity issues are found.
  • You can customize this behavior to fail the check on any level of issue, including medium, low severity or warnings.
  • CodeQL errors and warnings are displayed directly on the pull request, along with GitHub Copilot suggestions to help fix the issue.

Goldeneye

You can customize which aws accounts, regions service names in the goldeneye.json input in the workflow file. Check the specific configuration in the workflow file.

Dependency Scanning

You can enable or configure the dependency scanning to use different tools like npm audit, yarn audit, or any other security tools. Check the specific configuration in the workflow file.

Linting

You can add more linters, configure existing ones, or change the linter rules by modifying the .github/workflows/lint.yml file.

Stale Bot

You can modify the settings in the stale bot workflow to change how often the bot runs and which labels it should apply when marking issues or PRs as stale. The bot's inactivity timeout can also be adjusted.

PULL_REQUEST_TEMPLATE.md

The repository also includes a PULL_REQUEST_TEMPLATE.md file that can be used to standardize pull requests across repositories within the organization. This template ensures that pull requests are well-structured and provide all necessary information for reviewers.

  • Purpose: The template helps contributors provide details such as the problem being solved, the approach taken, and any additional information that may be relevant.

  • Customization: You can modify the template to suit your team's specific needs, such as including sections for testing instructions, related issues, or feature documentation.

This template ensures that every pull request provides clarity on what changes are being made and why, helping maintain consistency and improving communication across your team.

GitHub Copilot Instructions

This repository defines the organization-wide GitHub Copilot review configuration, ensuring that all AI-assisted code reviews across Studyportals repositories are consistent, secure, and aligned with company-wide engineering standards.

The configuration draws from the Knowledge Vault – Good Practices and Quality Standards, and enforces guidelines in the following areas:

  • Code Quality and Security — Enforces standards for readability, maintainability, and secure coding.
  • Dependency and IAM Audits — Validates dependency health and adherence to least-privilege principles.
  • Secure Coding Practices — Covers PHP, TypeScript, AWS SDK/CDK, and cloud infrastructure.
  • Testing and Validation — Ensures adequate test coverage, reliability, and adherence to company testing standards.
  • Architecture and Conventions — Promotes consistent naming, documentation, and structural design patterns across all projects.

By defining these standards centrally, Copilot provides reviewers and contributors with automated, organization-aligned feedback, helping to maintain high code quality and security across all repositories.

Note:

  • By default, Copilot reviews only pull requests marked as “Ready for Review.”
  • To enable Copilot reviews for draft pull requests, configure it in the rulesets of the repository’s Copilot settings under “Review draft pull requests.”
  • Copilot reviews each pull request only once, unless explicitly configured to re-review after every push.
  • If a repository is configured to automatically request a Copilot review for all new pull requests, the premium review usage is applied to the quota of the pull request author.
  • If the pull request is created by GitHub Actions or a bot, the usage is applied to the user who triggered the workflow (if identifiable) or to the designated billing owner.
  • When your monthly quota of premium Copilot review requests is reached, further automated reviews will be unavailable until the quota resets — unless your plan is upgraded or additional premium requests are enabled.

Contributing

Feel free to fork this repository, modify the workflows, and submit pull requests. If you want to improve or add additional workflows, such as testing, deployment, or notifications, feel free to open an issue or PR.

NOTE: You can find examples of the custom workflow in the Portal repository under the .github/workflows directory.

About

Studyportals public organization repository

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

27 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Studyportals

About Studyportals

Studyportals is the global study choice platform. Since its inception, it was founded to solve student problems, with a strong belief in the value of international experiences – both for individual students and society at large.

Come work for us

.github Repository

This repository contains GitHub Actions workflows that automate key tasks related to security, code quality, and repository maintenance for the Studyportals organization. The workflows include:

  • CodeQL Analysis: Automatic security and code quality scanning using CodeQL.
  • Dependency Scanning: Monitoring project dependencies for vulnerabilities.
  • Goldeneye A CI/CD pipeline generator.
  • Linting: Ensuring code quality by running linters for various languages.
  • Stale Bot: Automatically managing stale issues and pull requests.

Workflows

1. CodeQL Analysis

The CodeQL Analysis workflow automatically scans the codebase for security vulnerabilities and code quality issues using GitHub's CodeQL. It is triggered on push and pull_request events, and can also be scheduled for regular analysis.

  • Trigger:push, pull_request, and scheduled runs (e.g., every Monday at 7 AM).
  • Languages analyzed: JavaScript, TypeScript, Python, and others.
  • Custom queries: Configurable CodeQL queries for additional security checks.

Configuration: The workflow uses a reusable GitHub Actions setup to run CodeQL analysis. You can customize the analysis by specifying the languages you want to analyze. Additional configuration options can be defined in the codeql-config.yml file, placed in the .github/workflows/ directory of the repository.

2. Dependency Scanning

The Dependency Scanning workflow ensures that the project's dependencies are free of known vulnerabilities.

  • Trigger:push and pull_request events.
  • Action: Automatically checks for outdated dependencies or vulnerabilities in the dependency tree.

3. Goldeneye

The Goldeneye workflow is a CI/CD pipeline generator that automates the creation of pipelines.

Trigger: push, pull_request, and manual triggers.

Action: Automatically creates CI/CD pipelines for deployment or testing.

Configuration: Customize the goldeneye.json configuration in the workflow file for service names, AWS accounts, and regions.

3. Linting

The Linting workflow ensures the code adheres to predefined coding standards and best practices. It runs linters for various languages like PHP,JavaScript, TypeScript, Python, etc., based on the project's needs.

  • Trigger:push, pull_request, and manual triggers.
  • Tools used: ESLint for JavaScript/TypeScript, Flake8 for Python, and more.
  • Action: Linting is automatically run whenever code is pushed to the repository or when a pull request is made.

4. Stale Bot

The Stale Bot workflow helps keep the repository clean by automatically marking issues and pull requests as stale if they have not had activity for a specified period. This helps the team focus on active issues and PRs.

  • Trigger: On a schedule (e.g., daily or weekly).
  • Action: Automatically marks issues or PRs as "stale" if no activity has occurred in the last 30 days.
  • Configuration: Can be customized to change the inactivity period, labels, and more.

Setup Instructions

This repository is intended to be used as part of a larger project. To use the workflows in your own project:

  1. Create the .github directory into your repository.
  2. Customize any workflows based on your specific needs (e.g., language versions, linting rules, etc.) See Portal repository for examples.
    • You can copy the workflow files from this repository to your own repository.
    • Make sure to adjust any paths or configurations as necessary.
  3. Modify any settings in the workflows to match the project requirements (e.g., configuring the dependency scanning tool to scan your specific dependency manager)
  4. Push the changes to your repository, and the workflows will automatically run based on their triggers.
  5. Make the GitHub checks required if needed.

Workflow Overview

Workflow NameTrigger EventsDescription
CodeQL Analysispush, pull_request, scheduleScans the code for security vulnerabilities and code quality issues.
Dependency Scanningpush, pull_requestScans dependencies for known vulnerabilities.
Goldeneyepush, pull_request, manualCreates CI/CD piplines
Lintingpush, pull_request, manualRuns linters for various languages to ensure code quality.
Stale BotScheduled (e.g., daily, weekly)Marks issues/PRs as stale if there has been no activity.

Customizing Workflows

CodeQL Analysis

You can customize which languages are analyzed by modifying the languages input in the workflow file. You can also customize the CodeQL queries being run.

NOTE: When adding the CodeQL workflow to a repository for the first time, the workflow might not report results. You may see the following message in the checks

To resolve this issue, run the following commands in Git Bash or WSL terminal:

gh api -H "Accept: application/vnd.github+json" ./repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses --paginate | jq '.[]|select(.category=="/language:actions") | .id '| sed 's/\r//'| xargs -I {} gh api --method DELETE -H "Accept: application/vnd.github+json" -H "X-GitHub-Api-Version: 2022-11-28" /repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses/{}?confirm_delete
gh api -H "Accept: application/vnd.github+json" ./repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses --paginate | jq '.[]|select(.category=="/language:javascript-typescript") | .id '| sed 's/\r//'| xargs -I {} gh api --method DELETE -H "Accept: application/vnd.github+json" -H "X-GitHub-Api-Version: 2022-11-28" /repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses/{}?confirm_delete

Make sure to replace <OrganisationName> and <RepositoryName> with the actual names , and adjust the category value to match the one displayed in your repository's checks.

Important Notes:

  • The CodeQL Analysis workflow itself will typically show as successful, even if vulnerabilities are detected.
  • A separate line item—Code scanning results / CodeQL—will display the actual results of the CodeQL scan.
  • By default, this check will only report a failure if high or critical severity issues are found.
  • You can customize this behavior to fail the check on any level of issue, including medium, low severity or warnings.
  • CodeQL errors and warnings are displayed directly on the pull request, along with GitHub Copilot suggestions to help fix the issue.

Goldeneye

You can customize which aws accounts, regions service names in the goldeneye.json input in the workflow file. Check the specific configuration in the workflow file.

Dependency Scanning

You can enable or configure the dependency scanning to use different tools like npm audit, yarn audit, or any other security tools. Check the specific configuration in the workflow file.

Linting

You can add more linters, configure existing ones, or change the linter rules by modifying the .github/workflows/lint.yml file.

Stale Bot

You can modify the settings in the stale bot workflow to change how often the bot runs and which labels it should apply when marking issues or PRs as stale. The bot's inactivity timeout can also be adjusted.

PULL_REQUEST_TEMPLATE.md

The repository also includes a PULL_REQUEST_TEMPLATE.md file that can be used to standardize pull requests across repositories within the organization. This template ensures that pull requests are well-structured and provide all necessary information for reviewers.

  • Purpose: The template helps contributors provide details such as the problem being solved, the approach taken, and any additional information that may be relevant.

  • Customization: You can modify the template to suit your team's specific needs, such as including sections for testing instructions, related issues, or feature documentation.

This template ensures that every pull request provides clarity on what changes are being made and why, helping maintain consistency and improving communication across your team.

GitHub Copilot Instructions

This repository defines the organization-wide GitHub Copilot review configuration, ensuring that all AI-assisted code reviews across Studyportals repositories are consistent, secure, and aligned with company-wide engineering standards.

The configuration draws from the Knowledge Vault – Good Practices and Quality Standards, and enforces guidelines in the following areas:

  • Code Quality and Security — Enforces standards for readability, maintainability, and secure coding.
  • Dependency and IAM Audits — Validates dependency health and adherence to least-privilege principles.
  • Secure Coding Practices — Covers PHP, TypeScript, AWS SDK/CDK, and cloud infrastructure.
  • Testing and Validation — Ensures adequate test coverage, reliability, and adherence to company testing standards.
  • Architecture and Conventions — Promotes consistent naming, documentation, and structural design patterns across all projects.

By defining these standards centrally, Copilot provides reviewers and contributors with automated, organization-aligned feedback, helping to maintain high code quality and security across all repositories.

Note:

  • By default, Copilot reviews only pull requests marked as “Ready for Review.”
  • To enable Copilot reviews for draft pull requests, configure it in the rulesets of the repository’s Copilot settings under “Review draft pull requests.”
  • Copilot reviews each pull request only once, unless explicitly configured to re-review after every push.
  • If a repository is configured to automatically request a Copilot review for all new pull requests, the premium review usage is applied to the quota of the pull request author.
  • If the pull request is created by GitHub Actions or a bot, the usage is applied to the user who triggered the workflow (if identifiable) or to the designated billing owner.
  • When your monthly quota of premium Copilot review requests is reached, further automated reviews will be unavailable until the quota resets — unless your plan is upgraded or additional premium requests are enabled.

Contributing

Feel free to fork this repository, modify the workflows, and submit pull requests. If you want to improve or add additional workflows, such as testing, deployment, or notifications, feel free to open an issue or PR.

NOTE: You can find examples of the custom workflow in the Portal repository under the .github/workflows directory.

About

Studyportals public organization repository

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Latest commit

History

27 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Studyportals

About Studyportals

Studyportals is the global study choice platform. Since its inception, it was founded to solve student problems, with a strong belief in the value of international experiences – both for individual students and society at large.

Come work for us

.github Repository

This repository contains GitHub Actions workflows that automate key tasks related to security, code quality, and repository maintenance for the Studyportals organization. The workflows include:

  • CodeQL Analysis: Automatic security and code quality scanning using CodeQL.
  • Dependency Scanning: Monitoring project dependencies for vulnerabilities.
  • Goldeneye A CI/CD pipeline generator.
  • Linting: Ensuring code quality by running linters for various languages.
  • Stale Bot: Automatically managing stale issues and pull requests.

Workflows

1. CodeQL Analysis

The CodeQL Analysis workflow automatically scans the codebase for security vulnerabilities and code quality issues using GitHub's CodeQL. It is triggered on push and pull_request events, and can also be scheduled for regular analysis.

  • Trigger:push, pull_request, and scheduled runs (e.g., every Monday at 7 AM).
  • Languages analyzed: JavaScript, TypeScript, Python, and others.
  • Custom queries: Configurable CodeQL queries for additional security checks.

Configuration: The workflow uses a reusable GitHub Actions setup to run CodeQL analysis. You can customize the analysis by specifying the languages you want to analyze. Additional configuration options can be defined in the codeql-config.yml file, placed in the .github/workflows/ directory of the repository.

2. Dependency Scanning

The Dependency Scanning workflow ensures that the project's dependencies are free of known vulnerabilities.

  • Trigger:push and pull_request events.
  • Action: Automatically checks for outdated dependencies or vulnerabilities in the dependency tree.

3. Goldeneye

The Goldeneye workflow is a CI/CD pipeline generator that automates the creation of pipelines.

Trigger: push, pull_request, and manual triggers.

Action: Automatically creates CI/CD pipelines for deployment or testing.

Configuration: Customize the goldeneye.json configuration in the workflow file for service names, AWS accounts, and regions.

3. Linting

The Linting workflow ensures the code adheres to predefined coding standards and best practices. It runs linters for various languages like PHP,JavaScript, TypeScript, Python, etc., based on the project's needs.

  • Trigger:push, pull_request, and manual triggers.
  • Tools used: ESLint for JavaScript/TypeScript, Flake8 for Python, and more.
  • Action: Linting is automatically run whenever code is pushed to the repository or when a pull request is made.

4. Stale Bot

The Stale Bot workflow helps keep the repository clean by automatically marking issues and pull requests as stale if they have not had activity for a specified period. This helps the team focus on active issues and PRs.

  • Trigger: On a schedule (e.g., daily or weekly).
  • Action: Automatically marks issues or PRs as "stale" if no activity has occurred in the last 30 days.
  • Configuration: Can be customized to change the inactivity period, labels, and more.

Setup Instructions

This repository is intended to be used as part of a larger project. To use the workflows in your own project:

  1. Create the .github directory into your repository.
  2. Customize any workflows based on your specific needs (e.g., language versions, linting rules, etc.) See Portal repository for examples.
    • You can copy the workflow files from this repository to your own repository.
    • Make sure to adjust any paths or configurations as necessary.
  3. Modify any settings in the workflows to match the project requirements (e.g., configuring the dependency scanning tool to scan your specific dependency manager)
  4. Push the changes to your repository, and the workflows will automatically run based on their triggers.
  5. Make the GitHub checks required if needed.

Workflow Overview

Workflow NameTrigger EventsDescription
CodeQL Analysispush, pull_request, scheduleScans the code for security vulnerabilities and code quality issues.
Dependency Scanningpush, pull_requestScans dependencies for known vulnerabilities.
Goldeneyepush, pull_request, manualCreates CI/CD piplines
Lintingpush, pull_request, manualRuns linters for various languages to ensure code quality.
Stale BotScheduled (e.g., daily, weekly)Marks issues/PRs as stale if there has been no activity.

Customizing Workflows

CodeQL Analysis

You can customize which languages are analyzed by modifying the languages input in the workflow file. You can also customize the CodeQL queries being run.

NOTE: When adding the CodeQL workflow to a repository for the first time, the workflow might not report results. You may see the following message in the checks

To resolve this issue, run the following commands in Git Bash or WSL terminal:

gh api -H "Accept: application/vnd.github+json" ./repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses --paginate | jq '.[]|select(.category=="/language:actions") | .id '| sed 's/\r//'| xargs -I {} gh api --method DELETE -H "Accept: application/vnd.github+json" -H "X-GitHub-Api-Version: 2022-11-28" /repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses/{}?confirm_delete
gh api -H "Accept: application/vnd.github+json" ./repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses --paginate | jq '.[]|select(.category=="/language:javascript-typescript") | .id '| sed 's/\r//'| xargs -I {} gh api --method DELETE -H "Accept: application/vnd.github+json" -H "X-GitHub-Api-Version: 2022-11-28" /repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses/{}?confirm_delete

Make sure to replace <OrganisationName> and <RepositoryName> with the actual names , and adjust the category value to match the one displayed in your repository's checks.

Important Notes:

  • The CodeQL Analysis workflow itself will typically show as successful, even if vulnerabilities are detected.
  • A separate line item—Code scanning results / CodeQL—will display the actual results of the CodeQL scan.
  • By default, this check will only report a failure if high or critical severity issues are found.
  • You can customize this behavior to fail the check on any level of issue, including medium, low severity or warnings.
  • CodeQL errors and warnings are displayed directly on the pull request, along with GitHub Copilot suggestions to help fix the issue.

Goldeneye

You can customize which aws accounts, regions service names in the goldeneye.json input in the workflow file. Check the specific configuration in the workflow file.

Dependency Scanning

You can enable or configure the dependency scanning to use different tools like npm audit, yarn audit, or any other security tools. Check the specific configuration in the workflow file.

Linting

You can add more linters, configure existing ones, or change the linter rules by modifying the .github/workflows/lint.yml file.

Stale Bot

You can modify the settings in the stale bot workflow to change how often the bot runs and which labels it should apply when marking issues or PRs as stale. The bot's inactivity timeout can also be adjusted.

PULL_REQUEST_TEMPLATE.md

The repository also includes a PULL_REQUEST_TEMPLATE.md file that can be used to standardize pull requests across repositories within the organization. This template ensures that pull requests are well-structured and provide all necessary information for reviewers.

  • Purpose: The template helps contributors provide details such as the problem being solved, the approach taken, and any additional information that may be relevant.

  • Customization: You can modify the template to suit your team's specific needs, such as including sections for testing instructions, related issues, or feature documentation.

This template ensures that every pull request provides clarity on what changes are being made and why, helping maintain consistency and improving communication across your team.

GitHub Copilot Instructions

This repository defines the organization-wide GitHub Copilot review configuration, ensuring that all AI-assisted code reviews across Studyportals repositories are consistent, secure, and aligned with company-wide engineering standards.

The configuration draws from the Knowledge Vault – Good Practices and Quality Standards, and enforces guidelines in the following areas:

  • Code Quality and Security — Enforces standards for readability, maintainability, and secure coding.
  • Dependency and IAM Audits — Validates dependency health and adherence to least-privilege principles.
  • Secure Coding Practices — Covers PHP, TypeScript, AWS SDK/CDK, and cloud infrastructure.
  • Testing and Validation — Ensures adequate test coverage, reliability, and adherence to company testing standards.
  • Architecture and Conventions — Promotes consistent naming, documentation, and structural design patterns across all projects.

By defining these standards centrally, Copilot provides reviewers and contributors with automated, organization-aligned feedback, helping to maintain high code quality and security across all repositories.

Note:

  • By default, Copilot reviews only pull requests marked as “Ready for Review.”
  • To enable Copilot reviews for draft pull requests, configure it in the rulesets of the repository’s Copilot settings under “Review draft pull requests.”
  • Copilot reviews each pull request only once, unless explicitly configured to re-review after every push.
  • If a repository is configured to automatically request a Copilot review for all new pull requests, the premium review usage is applied to the quota of the pull request author.
  • If the pull request is created by GitHub Actions or a bot, the usage is applied to the user who triggered the workflow (if identifiable) or to the designated billing owner.
  • When your monthly quota of premium Copilot review requests is reached, further automated reviews will be unavailable until the quota resets — unless your plan is upgraded or additional premium requests are enabled.

Contributing

Feel free to fork this repository, modify the workflows, and submit pull requests. If you want to improve or add additional workflows, such as testing, deployment, or notifications, feel free to open an issue or PR.

NOTE: You can find examples of the custom workflow in the Portal repository under the .github/workflows directory.

About

Studyportals public organization repository

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

27 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Studyportals

About Studyportals

Studyportals is the global study choice platform. Since its inception, it was founded to solve student problems, with a strong belief in the value of international experiences – both for individual students and society at large.

Come work for us

.github Repository

This repository contains GitHub Actions workflows that automate key tasks related to security, code quality, and repository maintenance for the Studyportals organization. The workflows include:

  • CodeQL Analysis: Automatic security and code quality scanning using CodeQL.
  • Dependency Scanning: Monitoring project dependencies for vulnerabilities.
  • Goldeneye A CI/CD pipeline generator.
  • Linting: Ensuring code quality by running linters for various languages.
  • Stale Bot: Automatically managing stale issues and pull requests.

Workflows

1. CodeQL Analysis

The CodeQL Analysis workflow automatically scans the codebase for security vulnerabilities and code quality issues using GitHub's CodeQL. It is triggered on push and pull_request events, and can also be scheduled for regular analysis.

  • Trigger:push, pull_request, and scheduled runs (e.g., every Monday at 7 AM).
  • Languages analyzed: JavaScript, TypeScript, Python, and others.
  • Custom queries: Configurable CodeQL queries for additional security checks.

Configuration: The workflow uses a reusable GitHub Actions setup to run CodeQL analysis. You can customize the analysis by specifying the languages you want to analyze. Additional configuration options can be defined in the codeql-config.yml file, placed in the .github/workflows/ directory of the repository.

2. Dependency Scanning

The Dependency Scanning workflow ensures that the project's dependencies are free of known vulnerabilities.

  • Trigger:push and pull_request events.
  • Action: Automatically checks for outdated dependencies or vulnerabilities in the dependency tree.

3. Goldeneye

The Goldeneye workflow is a CI/CD pipeline generator that automates the creation of pipelines.

Trigger: push, pull_request, and manual triggers.

Action: Automatically creates CI/CD pipelines for deployment or testing.

Configuration: Customize the goldeneye.json configuration in the workflow file for service names, AWS accounts, and regions.

3. Linting

The Linting workflow ensures the code adheres to predefined coding standards and best practices. It runs linters for various languages like PHP,JavaScript, TypeScript, Python, etc., based on the project's needs.

  • Trigger:push, pull_request, and manual triggers.
  • Tools used: ESLint for JavaScript/TypeScript, Flake8 for Python, and more.
  • Action: Linting is automatically run whenever code is pushed to the repository or when a pull request is made.

4. Stale Bot

The Stale Bot workflow helps keep the repository clean by automatically marking issues and pull requests as stale if they have not had activity for a specified period. This helps the team focus on active issues and PRs.

  • Trigger: On a schedule (e.g., daily or weekly).
  • Action: Automatically marks issues or PRs as "stale" if no activity has occurred in the last 30 days.
  • Configuration: Can be customized to change the inactivity period, labels, and more.

Setup Instructions

This repository is intended to be used as part of a larger project. To use the workflows in your own project:

  1. Create the .github directory into your repository.
  2. Customize any workflows based on your specific needs (e.g., language versions, linting rules, etc.) See Portal repository for examples.
    • You can copy the workflow files from this repository to your own repository.
    • Make sure to adjust any paths or configurations as necessary.
  3. Modify any settings in the workflows to match the project requirements (e.g., configuring the dependency scanning tool to scan your specific dependency manager)
  4. Push the changes to your repository, and the workflows will automatically run based on their triggers.
  5. Make the GitHub checks required if needed.

Workflow Overview

Workflow NameTrigger EventsDescription
CodeQL Analysispush, pull_request, scheduleScans the code for security vulnerabilities and code quality issues.
Dependency Scanningpush, pull_requestScans dependencies for known vulnerabilities.
Goldeneyepush, pull_request, manualCreates CI/CD piplines
Lintingpush, pull_request, manualRuns linters for various languages to ensure code quality.
Stale BotScheduled (e.g., daily, weekly)Marks issues/PRs as stale if there has been no activity.

Customizing Workflows

CodeQL Analysis

You can customize which languages are analyzed by modifying the languages input in the workflow file. You can also customize the CodeQL queries being run.

NOTE: When adding the CodeQL workflow to a repository for the first time, the workflow might not report results. You may see the following message in the checks

To resolve this issue, run the following commands in Git Bash or WSL terminal:

gh api -H "Accept: application/vnd.github+json" ./repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses --paginate | jq '.[]|select(.category=="/language:actions") | .id '| sed 's/\r//'| xargs -I {} gh api --method DELETE -H "Accept: application/vnd.github+json" -H "X-GitHub-Api-Version: 2022-11-28" /repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses/{}?confirm_delete
gh api -H "Accept: application/vnd.github+json" ./repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses --paginate | jq '.[]|select(.category=="/language:javascript-typescript") | .id '| sed 's/\r//'| xargs -I {} gh api --method DELETE -H "Accept: application/vnd.github+json" -H "X-GitHub-Api-Version: 2022-11-28" /repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses/{}?confirm_delete

Make sure to replace <OrganisationName> and <RepositoryName> with the actual names , and adjust the category value to match the one displayed in your repository's checks.

Important Notes:

  • The CodeQL Analysis workflow itself will typically show as successful, even if vulnerabilities are detected.
  • A separate line item—Code scanning results / CodeQL—will display the actual results of the CodeQL scan.
  • By default, this check will only report a failure if high or critical severity issues are found.
  • You can customize this behavior to fail the check on any level of issue, including medium, low severity or warnings.
  • CodeQL errors and warnings are displayed directly on the pull request, along with GitHub Copilot suggestions to help fix the issue.

Goldeneye

You can customize which aws accounts, regions service names in the goldeneye.json input in the workflow file. Check the specific configuration in the workflow file.

Dependency Scanning

You can enable or configure the dependency scanning to use different tools like npm audit, yarn audit, or any other security tools. Check the specific configuration in the workflow file.

Linting

You can add more linters, configure existing ones, or change the linter rules by modifying the .github/workflows/lint.yml file.

Stale Bot

You can modify the settings in the stale bot workflow to change how often the bot runs and which labels it should apply when marking issues or PRs as stale. The bot's inactivity timeout can also be adjusted.

PULL_REQUEST_TEMPLATE.md

The repository also includes a PULL_REQUEST_TEMPLATE.md file that can be used to standardize pull requests across repositories within the organization. This template ensures that pull requests are well-structured and provide all necessary information for reviewers.

  • Purpose: The template helps contributors provide details such as the problem being solved, the approach taken, and any additional information that may be relevant.

  • Customization: You can modify the template to suit your team's specific needs, such as including sections for testing instructions, related issues, or feature documentation.

This template ensures that every pull request provides clarity on what changes are being made and why, helping maintain consistency and improving communication across your team.

GitHub Copilot Instructions

This repository defines the organization-wide GitHub Copilot review configuration, ensuring that all AI-assisted code reviews across Studyportals repositories are consistent, secure, and aligned with company-wide engineering standards.

The configuration draws from the Knowledge Vault – Good Practices and Quality Standards, and enforces guidelines in the following areas:

  • Code Quality and Security — Enforces standards for readability, maintainability, and secure coding.
  • Dependency and IAM Audits — Validates dependency health and adherence to least-privilege principles.
  • Secure Coding Practices — Covers PHP, TypeScript, AWS SDK/CDK, and cloud infrastructure.
  • Testing and Validation — Ensures adequate test coverage, reliability, and adherence to company testing standards.
  • Architecture and Conventions — Promotes consistent naming, documentation, and structural design patterns across all projects.

By defining these standards centrally, Copilot provides reviewers and contributors with automated, organization-aligned feedback, helping to maintain high code quality and security across all repositories.

Note:

  • By default, Copilot reviews only pull requests marked as “Ready for Review.”
  • To enable Copilot reviews for draft pull requests, configure it in the rulesets of the repository’s Copilot settings under “Review draft pull requests.”
  • Copilot reviews each pull request only once, unless explicitly configured to re-review after every push.
  • If a repository is configured to automatically request a Copilot review for all new pull requests, the premium review usage is applied to the quota of the pull request author.
  • If the pull request is created by GitHub Actions or a bot, the usage is applied to the user who triggered the workflow (if identifiable) or to the designated billing owner.
  • When your monthly quota of premium Copilot review requests is reached, further automated reviews will be unavailable until the quota resets — unless your plan is upgraded or additional premium requests are enabled.

Contributing

Feel free to fork this repository, modify the workflows, and submit pull requests. If you want to improve or add additional workflows, such as testing, deployment, or notifications, feel free to open an issue or PR.

NOTE: You can find examples of the custom workflow in the Portal repository under the .github/workflows directory.

About

Studyportals public organization repository

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

27 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Studyportals

About Studyportals

Studyportals is the global study choice platform. Since its inception, it was founded to solve student problems, with a strong belief in the value of international experiences – both for individual students and society at large.

Come work for us

.github Repository

This repository contains GitHub Actions workflows that automate key tasks related to security, code quality, and repository maintenance for the Studyportals organization. The workflows include:

  • CodeQL Analysis: Automatic security and code quality scanning using CodeQL.
  • Dependency Scanning: Monitoring project dependencies for vulnerabilities.
  • Goldeneye A CI/CD pipeline generator.
  • Linting: Ensuring code quality by running linters for various languages.
  • Stale Bot: Automatically managing stale issues and pull requests.

Workflows

1. CodeQL Analysis

The CodeQL Analysis workflow automatically scans the codebase for security vulnerabilities and code quality issues using GitHub's CodeQL. It is triggered on push and pull_request events, and can also be scheduled for regular analysis.

  • Trigger:push, pull_request, and scheduled runs (e.g., every Monday at 7 AM).
  • Languages analyzed: JavaScript, TypeScript, Python, and others.
  • Custom queries: Configurable CodeQL queries for additional security checks.

Configuration: The workflow uses a reusable GitHub Actions setup to run CodeQL analysis. You can customize the analysis by specifying the languages you want to analyze. Additional configuration options can be defined in the codeql-config.yml file, placed in the .github/workflows/ directory of the repository.

2. Dependency Scanning

The Dependency Scanning workflow ensures that the project's dependencies are free of known vulnerabilities.

  • Trigger:push and pull_request events.
  • Action: Automatically checks for outdated dependencies or vulnerabilities in the dependency tree.

3. Goldeneye

The Goldeneye workflow is a CI/CD pipeline generator that automates the creation of pipelines.

Trigger: push, pull_request, and manual triggers.

Action: Automatically creates CI/CD pipelines for deployment or testing.

Configuration: Customize the goldeneye.json configuration in the workflow file for service names, AWS accounts, and regions.

3. Linting

The Linting workflow ensures the code adheres to predefined coding standards and best practices. It runs linters for various languages like PHP,JavaScript, TypeScript, Python, etc., based on the project's needs.

  • Trigger:push, pull_request, and manual triggers.
  • Tools used: ESLint for JavaScript/TypeScript, Flake8 for Python, and more.
  • Action: Linting is automatically run whenever code is pushed to the repository or when a pull request is made.

4. Stale Bot

The Stale Bot workflow helps keep the repository clean by automatically marking issues and pull requests as stale if they have not had activity for a specified period. This helps the team focus on active issues and PRs.

  • Trigger: On a schedule (e.g., daily or weekly).
  • Action: Automatically marks issues or PRs as "stale" if no activity has occurred in the last 30 days.
  • Configuration: Can be customized to change the inactivity period, labels, and more.

Setup Instructions

This repository is intended to be used as part of a larger project. To use the workflows in your own project:

  1. Create the .github directory into your repository.
  2. Customize any workflows based on your specific needs (e.g., language versions, linting rules, etc.) See Portal repository for examples.
    • You can copy the workflow files from this repository to your own repository.
    • Make sure to adjust any paths or configurations as necessary.
  3. Modify any settings in the workflows to match the project requirements (e.g., configuring the dependency scanning tool to scan your specific dependency manager)
  4. Push the changes to your repository, and the workflows will automatically run based on their triggers.
  5. Make the GitHub checks required if needed.

Workflow Overview

Workflow NameTrigger EventsDescription
CodeQL Analysispush, pull_request, scheduleScans the code for security vulnerabilities and code quality issues.
Dependency Scanningpush, pull_requestScans dependencies for known vulnerabilities.
Goldeneyepush, pull_request, manualCreates CI/CD piplines
Lintingpush, pull_request, manualRuns linters for various languages to ensure code quality.
Stale BotScheduled (e.g., daily, weekly)Marks issues/PRs as stale if there has been no activity.

Customizing Workflows

CodeQL Analysis

You can customize which languages are analyzed by modifying the languages input in the workflow file. You can also customize the CodeQL queries being run.

NOTE: When adding the CodeQL workflow to a repository for the first time, the workflow might not report results. You may see the following message in the checks

To resolve this issue, run the following commands in Git Bash or WSL terminal:

gh api -H "Accept: application/vnd.github+json" ./repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses --paginate | jq '.[]|select(.category=="/language:actions") | .id '| sed 's/\r//'| xargs -I {} gh api --method DELETE -H "Accept: application/vnd.github+json" -H "X-GitHub-Api-Version: 2022-11-28" /repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses/{}?confirm_delete
gh api -H "Accept: application/vnd.github+json" ./repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses --paginate | jq '.[]|select(.category=="/language:javascript-typescript") | .id '| sed 's/\r//'| xargs -I {} gh api --method DELETE -H "Accept: application/vnd.github+json" -H "X-GitHub-Api-Version: 2022-11-28" /repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses/{}?confirm_delete

Make sure to replace <OrganisationName> and <RepositoryName> with the actual names , and adjust the category value to match the one displayed in your repository's checks.

Important Notes:

  • The CodeQL Analysis workflow itself will typically show as successful, even if vulnerabilities are detected.
  • A separate line item—Code scanning results / CodeQL—will display the actual results of the CodeQL scan.
  • By default, this check will only report a failure if high or critical severity issues are found.
  • You can customize this behavior to fail the check on any level of issue, including medium, low severity or warnings.
  • CodeQL errors and warnings are displayed directly on the pull request, along with GitHub Copilot suggestions to help fix the issue.

Goldeneye

You can customize which aws accounts, regions service names in the goldeneye.json input in the workflow file. Check the specific configuration in the workflow file.

Dependency Scanning

You can enable or configure the dependency scanning to use different tools like npm audit, yarn audit, or any other security tools. Check the specific configuration in the workflow file.

Linting

You can add more linters, configure existing ones, or change the linter rules by modifying the .github/workflows/lint.yml file.

Stale Bot

You can modify the settings in the stale bot workflow to change how often the bot runs and which labels it should apply when marking issues or PRs as stale. The bot's inactivity timeout can also be adjusted.

PULL_REQUEST_TEMPLATE.md

The repository also includes a PULL_REQUEST_TEMPLATE.md file that can be used to standardize pull requests across repositories within the organization. This template ensures that pull requests are well-structured and provide all necessary information for reviewers.

  • Purpose: The template helps contributors provide details such as the problem being solved, the approach taken, and any additional information that may be relevant.

  • Customization: You can modify the template to suit your team's specific needs, such as including sections for testing instructions, related issues, or feature documentation.

This template ensures that every pull request provides clarity on what changes are being made and why, helping maintain consistency and improving communication across your team.

GitHub Copilot Instructions

This repository defines the organization-wide GitHub Copilot review configuration, ensuring that all AI-assisted code reviews across Studyportals repositories are consistent, secure, and aligned with company-wide engineering standards.

The configuration draws from the Knowledge Vault – Good Practices and Quality Standards, and enforces guidelines in the following areas:

  • Code Quality and Security — Enforces standards for readability, maintainability, and secure coding.
  • Dependency and IAM Audits — Validates dependency health and adherence to least-privilege principles.
  • Secure Coding Practices — Covers PHP, TypeScript, AWS SDK/CDK, and cloud infrastructure.
  • Testing and Validation — Ensures adequate test coverage, reliability, and adherence to company testing standards.
  • Architecture and Conventions — Promotes consistent naming, documentation, and structural design patterns across all projects.

By defining these standards centrally, Copilot provides reviewers and contributors with automated, organization-aligned feedback, helping to maintain high code quality and security across all repositories.

Note:

  • By default, Copilot reviews only pull requests marked as “Ready for Review.”
  • To enable Copilot reviews for draft pull requests, configure it in the rulesets of the repository’s Copilot settings under “Review draft pull requests.”
  • Copilot reviews each pull request only once, unless explicitly configured to re-review after every push.
  • If a repository is configured to automatically request a Copilot review for all new pull requests, the premium review usage is applied to the quota of the pull request author.
  • If the pull request is created by GitHub Actions or a bot, the usage is applied to the user who triggered the workflow (if identifiable) or to the designated billing owner.
  • When your monthly quota of premium Copilot review requests is reached, further automated reviews will be unavailable until the quota resets — unless your plan is upgraded or additional premium requests are enabled.

Contributing

Feel free to fork this repository, modify the workflows, and submit pull requests. If you want to improve or add additional workflows, such as testing, deployment, or notifications, feel free to open an issue or PR.

NOTE: You can find examples of the custom workflow in the Portal repository under the .github/workflows directory.

About

Studyportals public organization repository

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Latest commit

History

27 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Studyportals

About Studyportals

Studyportals is the global study choice platform. Since its inception, it was founded to solve student problems, with a strong belief in the value of international experiences – both for individual students and society at large.

Come work for us

.github Repository

This repository contains GitHub Actions workflows that automate key tasks related to security, code quality, and repository maintenance for the Studyportals organization. The workflows include:

  • CodeQL Analysis: Automatic security and code quality scanning using CodeQL.
  • Dependency Scanning: Monitoring project dependencies for vulnerabilities.
  • Goldeneye A CI/CD pipeline generator.
  • Linting: Ensuring code quality by running linters for various languages.
  • Stale Bot: Automatically managing stale issues and pull requests.

Workflows

1. CodeQL Analysis

The CodeQL Analysis workflow automatically scans the codebase for security vulnerabilities and code quality issues using GitHub's CodeQL. It is triggered on push and pull_request events, and can also be scheduled for regular analysis.

  • Trigger:push, pull_request, and scheduled runs (e.g., every Monday at 7 AM).
  • Languages analyzed: JavaScript, TypeScript, Python, and others.
  • Custom queries: Configurable CodeQL queries for additional security checks.

Configuration: The workflow uses a reusable GitHub Actions setup to run CodeQL analysis. You can customize the analysis by specifying the languages you want to analyze. Additional configuration options can be defined in the codeql-config.yml file, placed in the .github/workflows/ directory of the repository.

2. Dependency Scanning

The Dependency Scanning workflow ensures that the project's dependencies are free of known vulnerabilities.

  • Trigger:push and pull_request events.
  • Action: Automatically checks for outdated dependencies or vulnerabilities in the dependency tree.

3. Goldeneye

The Goldeneye workflow is a CI/CD pipeline generator that automates the creation of pipelines.

Trigger: push, pull_request, and manual triggers.

Action: Automatically creates CI/CD pipelines for deployment or testing.

Configuration: Customize the goldeneye.json configuration in the workflow file for service names, AWS accounts, and regions.

3. Linting

The Linting workflow ensures the code adheres to predefined coding standards and best practices. It runs linters for various languages like PHP,JavaScript, TypeScript, Python, etc., based on the project's needs.

  • Trigger:push, pull_request, and manual triggers.
  • Tools used: ESLint for JavaScript/TypeScript, Flake8 for Python, and more.
  • Action: Linting is automatically run whenever code is pushed to the repository or when a pull request is made.

4. Stale Bot

The Stale Bot workflow helps keep the repository clean by automatically marking issues and pull requests as stale if they have not had activity for a specified period. This helps the team focus on active issues and PRs.

  • Trigger: On a schedule (e.g., daily or weekly).
  • Action: Automatically marks issues or PRs as "stale" if no activity has occurred in the last 30 days.
  • Configuration: Can be customized to change the inactivity period, labels, and more.

Setup Instructions

This repository is intended to be used as part of a larger project. To use the workflows in your own project:

  1. Create the .github directory into your repository.
  2. Customize any workflows based on your specific needs (e.g., language versions, linting rules, etc.) See Portal repository for examples.
    • You can copy the workflow files from this repository to your own repository.
    • Make sure to adjust any paths or configurations as necessary.
  3. Modify any settings in the workflows to match the project requirements (e.g., configuring the dependency scanning tool to scan your specific dependency manager)
  4. Push the changes to your repository, and the workflows will automatically run based on their triggers.
  5. Make the GitHub checks required if needed.

Workflow Overview

Workflow NameTrigger EventsDescription
CodeQL Analysispush, pull_request, scheduleScans the code for security vulnerabilities and code quality issues.
Dependency Scanningpush, pull_requestScans dependencies for known vulnerabilities.
Goldeneyepush, pull_request, manualCreates CI/CD piplines
Lintingpush, pull_request, manualRuns linters for various languages to ensure code quality.
Stale BotScheduled (e.g., daily, weekly)Marks issues/PRs as stale if there has been no activity.

Customizing Workflows

CodeQL Analysis

You can customize which languages are analyzed by modifying the languages input in the workflow file. You can also customize the CodeQL queries being run.

NOTE: When adding the CodeQL workflow to a repository for the first time, the workflow might not report results. You may see the following message in the checks

To resolve this issue, run the following commands in Git Bash or WSL terminal:

gh api -H "Accept: application/vnd.github+json" ./repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses --paginate | jq '.[]|select(.category=="/language:actions") | .id '| sed 's/\r//'| xargs -I {} gh api --method DELETE -H "Accept: application/vnd.github+json" -H "X-GitHub-Api-Version: 2022-11-28" /repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses/{}?confirm_delete
gh api -H "Accept: application/vnd.github+json" ./repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses --paginate | jq '.[]|select(.category=="/language:javascript-typescript") | .id '| sed 's/\r//'| xargs -I {} gh api --method DELETE -H "Accept: application/vnd.github+json" -H "X-GitHub-Api-Version: 2022-11-28" /repos/<OrganisationName>/<RepositoryName>/code-scanning/analyses/{}?confirm_delete

Make sure to replace <OrganisationName> and <RepositoryName> with the actual names , and adjust the category value to match the one displayed in your repository's checks.

Important Notes:

  • The CodeQL Analysis workflow itself will typically show as successful, even if vulnerabilities are detected.
  • A separate line item—Code scanning results / CodeQL—will display the actual results of the CodeQL scan.
  • By default, this check will only report a failure if high or critical severity issues are found.
  • You can customize this behavior to fail the check on any level of issue, including medium, low severity or warnings.
  • CodeQL errors and warnings are displayed directly on the pull request, along with GitHub Copilot suggestions to help fix the issue.

Goldeneye

You can customize which aws accounts, regions service names in the goldeneye.json input in the workflow file. Check the specific configuration in the workflow file.

Dependency Scanning

You can enable or configure the dependency scanning to use different tools like npm audit, yarn audit, or any other security tools. Check the specific configuration in the workflow file.

Linting

You can add more linters, configure existing ones, or change the linter rules by modifying the .github/workflows/lint.yml file.

Stale Bot

You can modify the settings in the stale bot workflow to change how often the bot runs and which labels it should apply when marking issues or PRs as stale. The bot's inactivity timeout can also be adjusted.

PULL_REQUEST_TEMPLATE.md

The repository also includes a PULL_REQUEST_TEMPLATE.md file that can be used to standardize pull requests across repositories within the organization. This template ensures that pull requests are well-structured and provide all necessary information for reviewers.

  • Purpose: The template helps contributors provide details such as the problem being solved, the approach taken, and any additional information that may be relevant.

  • Customization: You can modify the template to suit your team's specific needs, such as including sections for testing instructions, related issues, or feature documentation.

This template ensures that every pull request provides clarity on what changes are being made and why, helping maintain consistency and improving communication across your team.

GitHub Copilot Instructions

This repository defines the organization-wide GitHub Copilot review configuration, ensuring that all AI-assisted code reviews across Studyportals repositories are consistent, secure, and aligned with company-wide engineering standards.

The configuration draws from the Knowledge Vault – Good Practices and Quality Standards, and enforces guidelines in the following areas:

  • Code Quality and Security — Enforces standards for readability, maintainability, and secure coding.
  • Dependency and IAM Audits — Validates dependency health and adherence to least-privilege principles.
  • Secure Coding Practices — Covers PHP, TypeScript, AWS SDK/CDK, and cloud infrastructure.
  • Testing and Validation — Ensures adequate test coverage, reliability, and adherence to company testing standards.
  • Architecture and Conventions — Promotes consistent naming, documentation, and structural design patterns across all projects.

By defining these standards centrally, Copilot provides reviewers and contributors with automated, organization-aligned feedback, helping to maintain high code quality and security across all repositories.

Note:

  • By default, Copilot reviews only pull requests marked as “Ready for Review.”
  • To enable Copilot reviews for draft pull requests, configure it in the rulesets of the repository’s Copilot settings under “Review draft pull requests.”
  • Copilot reviews each pull request only once, unless explicitly configured to re-review after every push.
  • If a repository is configured to automatically request a Copilot review for all new pull requests, the premium review usage is applied to the quota of the pull request author.
  • If the pull request is created by GitHub Actions or a bot, the usage is applied to the user who triggered the workflow (if identifiable) or to the designated billing owner.
  • When your monthly quota of premium Copilot review requests is reached, further automated reviews will be unavailable until the quota resets — unless your plan is upgraded or additional premium requests are enabled.

Contributing

Feel free to fork this repository, modify the workflows, and submit pull requests. If you want to improve or add additional workflows, such as testing, deployment, or notifications, feel free to open an issue or PR.

NOTE: You can find examples of the custom workflow in the Portal repository under the .github/workflows directory.

About

Studyportals public organization repository

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors