TOOL

dev-rig

Shared CI workflows and audit harness for LegionForge projects

reusable workflows and local audits for Python, static, and mixed-language repos

What it is

dev-rig is the shared CI/CD substrate used across LegionForge repos. It provides:

The goal is that every project under the LegionForge org has a clear security / quality baseline without copy-pasting workflow files between repos.

Using it in a project

# .github/workflows/ci.yml
name: CI
on: [pull_request, push]

jobs:
  lint:    { uses: LegionForge/dev-rig/.github/workflows/lint.yml@main }
  test:    { uses: LegionForge/dev-rig/.github/workflows/test.yml@main }
  sast:    { uses: LegionForge/dev-rig/.github/workflows/sast.yml@main }
  audit:   { uses: LegionForge/dev-rig/.github/workflows/audit.yml@main }
  secrets: { uses: LegionForge/dev-rig/.github/workflows/secrets.yml@main }
  sbom:    { uses: LegionForge/dev-rig/.github/workflows/sbom.yml@main }

That's the entire CI config for a Python project — every workflow is sourced from dev-rig. Updating dev-rig updates the CI across all projects that reference @main.

Local audit

LegionForge-dev-rig/scripts/audit.sh /path/to/repo

The harness is repo-shape aware. Python checks run when Python files or dependency manifests exist. Static sites still receive the applicable checks: OSV Scanner, gitleaks working-tree/history scans, ShellCheck when shell scripts exist, Semgrep packs when Docker is available, and the LegionForge risky-exec rules.

When to use it outside LegionForge

If you maintain multiple Python repos and want a consistent security baseline, dev-rig is a reasonable template. The workflows are MIT-licensed and the configuration is intentionally vanilla — they don't assume LegionForge-specific structure.

Status

Active. Public. See the GitHub repo for the latest, and the project security inventory for current coverage across repos.