ci(security): run gitleaks binary + audit prod deps only
The container-mode runner has no Docker socket, so the gitleaks 'docker run' step failed; download and run the binary instead. Scope npm audit to production dependencies (--omit=dev) so dev-toolchain advisories don't block merges, and match dotnet's own vulnerable-packages line to avoid severity-word false hits. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -17,9 +17,13 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
fetch-depth: 0 # full history so gitleaks scans every commit
|
fetch-depth: 0 # full history so gitleaks scans every commit
|
||||||
- name: Secret scan (gitleaks)
|
- name: Secret scan (gitleaks)
|
||||||
|
# Run the binary directly — the container-mode runner has no Docker socket,
|
||||||
|
# so `docker run` isn't available inside a job.
|
||||||
run: |
|
run: |
|
||||||
docker run --rm -v "$PWD:/repo" zricethezav/gitleaks:latest \
|
GITLEAKS_VERSION=8.18.4
|
||||||
detect --source=/repo --redact --verbose --exit-code 1
|
curl -sSL "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" -o /tmp/gitleaks.tar.gz
|
||||||
|
tar -xzf /tmp/gitleaks.tar.gz -C /tmp gitleaks
|
||||||
|
/tmp/gitleaks detect --source=. --redact --verbose --exit-code=1
|
||||||
|
|
||||||
dependencies:
|
dependencies:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
@@ -31,9 +35,11 @@ jobs:
|
|||||||
- name: Restore
|
- name: Restore
|
||||||
run: dotnet restore InboxIntel.sln
|
run: dotnet restore InboxIntel.sln
|
||||||
- name: .NET vulnerable packages (fail on any)
|
- name: .NET vulnerable packages (fail on any)
|
||||||
|
# Match dotnet's own "has the following vulnerable packages" line rather
|
||||||
|
# than raw severity words, so package/project names can't false-positive.
|
||||||
run: |
|
run: |
|
||||||
dotnet list InboxIntel.sln package --vulnerable --include-transitive 2>&1 | tee vuln.txt
|
dotnet list InboxIntel.sln package --vulnerable --include-transitive 2>&1 | tee vuln.txt
|
||||||
if grep -qiE 'Critical|High|Moderate|Low' vuln.txt; then
|
if grep -q "has the following vulnerable" vuln.txt; then
|
||||||
echo "::error::Vulnerable NuGet packages detected — see the table above."
|
echo "::error::Vulnerable NuGet packages detected — see the table above."
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
@@ -41,6 +47,8 @@ jobs:
|
|||||||
- uses: actions/setup-node@v4
|
- uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
node-version: '20'
|
node-version: '20'
|
||||||
- name: npm audit (fail on high/critical)
|
- name: npm audit (production deps, fail on high/critical)
|
||||||
|
# Only production dependencies ship to users; dev-only toolchain advisories
|
||||||
|
# (Vite/PostCSS/etc.) shouldn't block a merge.
|
||||||
working-directory: frontend
|
working-directory: frontend
|
||||||
run: npm audit --audit-level=high
|
run: npm audit --omit=dev --audit-level=high
|
||||||
|
|||||||
Reference in New Issue
Block a user