Skip to content

ci: free security scanning to replace CodeQL - #4

Closed
prabu-openclaw wants to merge 3 commits into
mainfrom
security/free-scanner-stack
Closed

prabu-openclaw wants to merge 3 commits into
mainfrom
security/free-scanner-stack

Conversation

@prabu-openclaw

Copy link
Copy Markdown

Summary

Related issue or project item

Testing performed

Collaboration checklist

  • Added or updated tests
  • Updated documentation if needed
  • Added the appropriate labels
  • Checked the linked GitHub Project item
  • Requested review from the Partner Agents team when appropriate

CodeQL is licensed for open source only unless the org holds GitHub Code
Security ($30/active committer/month), so it cannot legally run against these
private repos - hosted or via the CLI. This adds permissively-licensed
scanners that can:

  gitleaks      secrets, full history
  bandit        python SAST, high severity + high confidence only
  semgrep OSS   multi-language SAST, ERROR severity only
  osv-scanner   dependency CVEs, advisory only

All the logic lives in scripts/security-scan.sh, which the workflow simply
calls. That means you can run the identical scan locally at any time:

    ./scripts/security-scan.sh

Local and CI results match by construction, and neither of us is blocked
waiting on the other's machine to learn whether our code is clean.

Runs on the self-hosted Macs, so it costs nothing and does not depend on the
Actions billing state. Switch to ubuntu-latest once billing is healthy.

.gitleaks.toml suppresses only shapes triaged as false positives across the
org (20 findings, 0 real secrets: Swift UserDefaults keys, golden-snapshot
fixture ids, and synthetic PEMs in tests that assert they get blocked). The
allowlist is restricted to dot-separated reverse-DNS values, so sk_live_*,
ghp_*, AKIA* and friends are still reported - verified against planted
credentials. Detection matches gitleaks' stock config on that canary.

Nothing here uploads source code.
@prabu-openclaw
prabu-openclaw requested a review from a team as a code owner August 15, 2026 18:36

Copy link
Copy Markdown
Author

This stack of pull requests is managed by Graphite. Learn more about stacking.

prabu-openclaw added 2 commits August 15, 2026 12:39
Patch-Hive already had a .github/workflows/security.yml and the first version
of this change silently overwrote it. Renaming to free-security-scan.yml so
this can never clobber a repo's own security workflow.
The bandit flags did not match the documented intent. -ll -ii means severity
and confidence MEDIUM and above, not HIGH -- so the gate failed on Psy-Fi
(High: 0, Medium: 9) and Abraxas-Orchestra (High: 0, Medium: 11), neither of
which has a single high-severity finding.

The gate now runs -lll -iii (high severity AND high confidence). Medium-and-
above still runs immediately before it as informational output, so those
findings stay visible without blocking a merge.
@scrimshawlife-ctrl

Copy link
Copy Markdown
Contributor

Closing: CI red (validate/CodeQL); free-scanner stack never landed. Prefer current org CodeQL baseline + personal tip security posture after sync. Re-open if we intentionally replace CodeQL.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants