-
Notifications
You must be signed in to change notification settings - Fork 14
94 lines (87 loc) · 3.22 KB
/
Copy pathsecurity.yml
File metadata and controls
94 lines (87 loc) · 3.22 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
name: Security
# Security scanning, separate from CI so it runs in parallel and is easy to
# read. Each scanner is its own cached job. Runs on PRs, on push to master, and
# weekly (so newly-disclosed CVEs are caught even without a push).
on:
pull_request:
push:
branches: [master]
schedule:
- cron: "0 6 * * 1" # Mondays 06:00 UTC
permissions:
contents: read
concurrency:
group: security-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
govulncheck:
name: Vulnerabilities (govulncheck)
runs-on: ubuntu-latest
# Advisory to start: flags known CVEs in dependencies the code reaches.
# Flip to blocking once the baseline is confirmed clean.
continue-on-error: true
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version: "1.25"
cache: true
- name: install govulncheck
run: go install golang.org/x/vuln/cmd/govulncheck@latest
- name: govulncheck (report-only)
run: "$(go env GOPATH)/bin/govulncheck ./... || echo '::warning::govulncheck reported findings (advisory)'"
gosec:
name: SAST (gosec)
runs-on: ubuntu-latest
# Advisory to start: static security analysis (hardcoded creds, weak crypto,
# unsafe patterns). Reports without blocking until the baseline is triaged.
continue-on-error: true
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version: "1.25"
cache: true
- name: install gosec
run: go install github.com/securego/gosec/v2/cmd/gosec@latest
- name: gosec (report-only)
run: "$(go env GOPATH)/bin/gosec -exclude-generated ./... || echo '::warning::gosec reported findings (advisory)'"
codeql:
name: CodeQL (SAST)
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write
actions: read
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version: "1.25"
cache: true
- uses: github/codeql-action/init@v3
with:
languages: go
build-mode: manual
# Analyze only the shipped emulator (the root module: core + wire server).
# The opt-in contrib/ engines (contrib/realengine, contrib/dockerengine,
# contrib/server) are separate modules of local dev tooling that inherently
# perform CodeQL-flagged operations behind allowlist/containment guards the
# query engine cannot model (parameterized-only DDL identifiers, contained
# filesystem paths, first-party-argv subprocesses). Building only the root
# module keeps SAST on everything that actually ships, without the perpetual
# false positives from the guarded contrib helpers. Their own CI jobs
# build/vet/lint them.
- name: build (root module only)
run: go build ./...
- uses: github/codeql-action/analyze@v3
dependency-review:
name: Dependency Review
runs-on: ubuntu-latest
if: github.event_name == 'pull_request'
steps:
- uses: actions/checkout@v4
- name: Review dependency changes for known vulnerabilities
uses: actions/dependency-review-action@v4
with:
fail-on-severity: high