Operate

Free public security program (GitHub Actions)

anvil-agents is open source. Security evidence is as many free scanners as practical, running on public GitHub Actions minutes (no paid SaaS, no Primaris lifecycle coupling). Anyone can open the Actions tab and inspect check runs, job summaries, artifacts, and the Security tab.

Primaris only installs this operator:

.hazyforge/clusters/anvil-primaris/namespace/anvil-agents-system/

Free scanners (security.yml)

LayerPublic job nameTool (cost)
Go vulnsfree · govulncheckgovulncheck (free)
Go SASTfree · gosecgosec (free)
Go SASTfree · CodeQLGitHub CodeQL free for public repos
Lockfilesfree · OSV-ScannerGoogle OSV (free)
Owned depfree · owned-deps / anvil-hotlinegovulncheck + Trivy + OSV on pin
Repo FSfree · trivy / filesystemTrivy vuln/secret/misconfig + SBOM
PR graphfree · dependency-reviewGitHub free for public repos
Consolefree · npm audit / consolenpm audit (free)
Dockerfilesfree · hadolint / DockerfilesHadolint (free)
Helmfree · checkov / helmCheckov OSS (free)
Secretsfree · gitleaks / secretsGitleaks free for public
Workflowsfree · zizmor / workflowszizmor (free, advisory)
Images ×7free · image / <component>Trivy + Grype + CycloneDX SBOM
Trustfree · OpenSSF ScorecardScorecard free for public
Gatefree · security-gateRequires the required jobs green
UpdatesDependabotFree alerts + PRs (gomod, npm, docker, actions, helm)

Containers (breadth of tooling)

Each of the seven images gets its own named free check run:

ComponentImage
controlleranvil-agents
codexanvil-agent-run-codex
opencodeanvil-agent-run-opencode
grok-buildanvil-agent-run-grok-build
hermesanvil-agent-run-hermes
openclawanvil-agent-run-openclaw
pianvil-agent-run-pi

Per image: Trivy (HIGH/CRITICAL), Grype (high+), CycloneDX SBOM artifact.

Owned first-party pin

Runner Dockerfiles pin ANVIL_HOTLINE_VERSION. The owned-deps job requires a single pin and scans that public tag.

When it runs (all free public minutes)

  • Every PR / push to master / main
  • Weekly schedule
  • GitHub Releases
  • Manual workflow_dispatch
  • Publish workflow waits on security before GHCR push

Local optional mirrors

make security          # govulncheck + gosec
make security-trivy    # Trivy all containers
make security-all      # both

Branch protection tip

Protect master with required check: free · security-gate.

GitHub settings (once, free)

  1. Code security — enable Dependency graph, Dependabot alerts, Code scanning.
  2. No paid Advanced Security required for a public repository.