-
Notifications
You must be signed in to change notification settings - Fork 0
87 lines (82 loc) · 2.95 KB
/
Copy pathsecurity.yml
File metadata and controls
87 lines (82 loc) · 2.95 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
name: Security Gate
on:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
- cron: "25 6 * * 1"
workflow_dispatch:
permissions:
contents: read
security-events: write
jobs:
dependency-review:
name: Dependency review
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/dependency-review-action@v4
with:
fail-on-severity: high
deny-licenses: GPL-3.0, AGPL-3.0
secret-scan:
name: Secret scan
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Install pinned Gitleaks CLI
env:
GITLEAKS_VERSION: "8.30.1"
run: |
set -euo pipefail
archive="gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz"
checksums="gitleaks_${GITLEAKS_VERSION}_checksums.txt"
release_url="https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}"
curl --fail --silent --show-error --location --remote-name "${release_url}/${archive}"
curl --fail --silent --show-error --location --remote-name "${release_url}/${checksums}"
grep " ${archive}$" "${checksums}" | sha256sum --check --strict
tar -xzf "${archive}" gitleaks
sudo install -m 0755 gitleaks /usr/local/bin/gitleaks
gitleaks version
- name: Scan current tree and changed commits
env:
GITLEAKS_BASE_SHA: ${{ github.event.pull_request.base.sha || github.event.before }}
GITLEAKS_HEAD_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
run: |
set -euo pipefail
scan_root="$(mktemp -d)"
trap 'rm -rf "${scan_root}"' EXIT
git archive HEAD | tar -x -C "${scan_root}"
gitleaks dir --redact --config .gitleaks.toml "${scan_root}"
if [ "${GITHUB_EVENT_NAME}" = "push" ] || [ "${GITHUB_EVENT_NAME}" = "pull_request" ]; then
if [ -z "${GITLEAKS_BASE_SHA}" ] || [[ "${GITLEAKS_BASE_SHA}" =~ ^0+$ ]]; then
log_opts="-n 1"
else
log_opts="${GITLEAKS_BASE_SHA}..${GITLEAKS_HEAD_SHA}"
fi
else
log_opts="-n 100"
fi
gitleaks git --redact --config .gitleaks.toml --log-opts="${log_opts}" .
production-audit:
name: Production dependency audit
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "24"
cache: yarn
cache-dependency-path: yarn.lock
- name: Activate package manager
run: |
corepack enable
corepack prepare yarn@1.22.22 --activate
- name: Install lockfile exactly
run: yarn install --frozen-lockfile --ignore-scripts --network-timeout 600000
- name: Audit production dependencies
run: yarn audit --groups dependencies --level high