Skip to content

feat(security): automated static security analysis & vulnerability sc… - #1597

Open
Joyful12-tech wants to merge 1 commit into
LabsCrypt:mainfrom
Joyful12-tech:feat/security-scanning-pipeline-1334
Open

Joyful12-tech wants to merge 1 commit into
LabsCrypt:mainfrom
Joyful12-tech:feat/security-scanning-pipeline-1334

Conversation

@Joyful12-tech

Copy link
Copy Markdown

…anning pipeline

Implements the full security scanning CI pipeline required by #1334.

Changes:

  • .github/workflows/security.yml: Complete rewrite with four jobs:

    1. dependency-check — npm audit (root, frontend, backend workspaces) + cargo audit --deny warnings on contracts/ (removes duplicate job and duplicate rust-toolchain/cargo-audit-cache steps from the original)
    2. secret-scan — gitleaks-action@v2 scanning full git history (fetch-depth 0) for accidentally committed secrets, tokens, and API keys
    3. sast — semgrep-action@v1 with p/nodejs, p/react, p/typescript, p/rust, p/owasp-top-ten, p/javascript rule sets; uploads semgrep.sarif to the GitHub Security tab via codeql-action/upload-sarif
    4. codeql-analysis — matrix over javascript and rust (typescript is not a valid standalone CodeQL language); SARIF uploaded automatically by codeql-action/analyze; queries: security-and-quality
    • All four jobs run on pull_request and on a weekly Sunday 02:00 UTC cron
    • All jobs fail-fast (no continue-on-error) so PRs are blocked on any finding
    • Least-privilege permissions; security-events:write only where SARIF is uploaded (secret-scan, sast, codeql-analysis)
  • SECURITY.md: Added 'Automated Security Scanning Pipeline' section documenting each scan, how to view SARIF results in the Security tab, how to handle dependency audit failures, how to respond to secret scan failures, how to suppress false positives responsibly, and the weekly CVE sweep cadence.

Closes #1334

Description

Type of Change

  • 🐛 Bug fix (non-breaking change which fixes an issue)
  • ✨ New feature (non-breaking change which adds functionality)
  • 💥 Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • 📚 Documentation update
  • 🔧 Refactoring (no functional changes)
  • ⚡ Performance improvement
  • 🧪 Test addition or update

Related Issues

Closes #

Changes Made

Testing

Test Coverage

  • Unit tests added/updated
  • Integration tests added/updated
  • Manual testing performed

Test Steps

Breaking Changes

Breaking Changes:

Migration Guide:

Screenshots/Demo

Checklist

  • My code follows the project's style guidelines
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • Updated Postman/Hoppscotch API collections if routes changed
  • My changes generate no new warnings
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes
  • Any dependent changes have been merged and published
  • I have checked for breaking changes and documented them if applicable
  • If this change adds or modifies a metric, I have updated the Grafana dashboard and the alert rules in backend/docs/observability/

Additional Notes

…anning pipeline

Implements the full security scanning CI pipeline required by LabsCrypt#1334.

Changes:
- .github/workflows/security.yml: Complete rewrite with four jobs:
  1. dependency-check — npm audit (root, frontend, backend workspaces) +
     cargo audit --deny warnings on contracts/ (removes duplicate job and
     duplicate rust-toolchain/cargo-audit-cache steps from the original)
  2. secret-scan — gitleaks-action@v2 scanning full git history (fetch-depth 0)
     for accidentally committed secrets, tokens, and API keys
  3. sast — semgrep-action@v1 with p/nodejs, p/react, p/typescript, p/rust,
     p/owasp-top-ten, p/javascript rule sets; uploads semgrep.sarif to the
     GitHub Security tab via codeql-action/upload-sarif
  4. codeql-analysis — matrix over javascript and rust (typescript is not a
     valid standalone CodeQL language); SARIF uploaded automatically by
     codeql-action/analyze; queries: security-and-quality
  - All four jobs run on pull_request and on a weekly Sunday 02:00 UTC cron
  - All jobs fail-fast (no continue-on-error) so PRs are blocked on any finding
  - Least-privilege permissions; security-events:write only where SARIF is
    uploaded (secret-scan, sast, codeql-analysis)

- SECURITY.md: Added 'Automated Security Scanning Pipeline' section documenting
  each scan, how to view SARIF results in the Security tab, how to handle
  dependency audit failures, how to respond to secret scan failures, how to
  suppress false positives responsibly, and the weekly CVE sweep cadence.

Closes LabsCrypt#1334
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[DevOps/Security] Automated Static Security Analysis & Vulnerability Scanning Pipeline

2 participants