Skip to content

Add Socket Basics security scanning workflow - #5460

Open
kanwalpreetd wants to merge 1 commit into
stellar:masterfrom
kanwalpreetd:master
Open

kanwalpreetd wants to merge 1 commit into
stellar:masterfrom
kanwalpreetd:master

Conversation

@kanwalpreetd

@kanwalpreetd kanwalpreetd commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

@kanwalpreetd
kanwalpreetd force-pushed the master branch 4 times, most recently from 62a98c8 to 34c0284 Compare September 26, 2026 01:30
@kanwalpreetd
kanwalpreetd marked this pull request as ready for review September 28, 2026 12:40
Copilot AI balanced review requested due to automatic review settings September 28, 2026 12:40

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The missing-completion-marker path can report an error while still exiting successfully.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds scheduled and on-demand Socket Basics security scanning.

Changes:

  • Configures SAST, secret, and Dockerfile scanning.
  • Adds scan exclusions and rule suppressions.
  • Runs a pinned scanner image and reports findings.
File Description
.github/​workflows/​socket-basics.yml Defines the security scan workflow.
.socket-basics.json Configures scanners and exclusions.
.semgrepignore Excludes generated, vendored, and test paths.
.trivyignore Suppresses selected Dockerfile rules.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/socket-basics.yml Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The workflow can report success after scanner or upload failures, and intended golden-data exclusions do not match actual paths.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
Resolved since last review (1)

Comment thread .github/workflows/socket-basics.yml Outdated
Comment on lines +47 to +54
if grep -q "Scan completed!" /tmp/socket-basics.log; then
hc=$(grep -oE "Found [0-9]+ high/critical" /tmp/socket-basics.log \
| grep -oE "[0-9]+" | head -1)
if [ -n "$hc" ] && [ "$hc" -gt 0 ]; then
echo "::warning::Socket Basics found $hc high/critical finding(s)"
fi
exit 0
fi
Comment thread .socket-basics.json
"dockerfiles": ".devcontainer/Dockerfile,docker/Dockerfile,docker/Dockerfile.testing",
"socket_tier_1_enabled": false,
"trivy_vuln_enabled": false,
"trufflehog_exclude_dir": "build,.venv,venv,__pycache__,target,.git,__fixtures__,__mocks__,__snapshots__,__tests__,acceptance-test,acceptance-tests,acceptance_test,acceptance_tests,benches,browser-test,browser-tests,browser_test,browser_tests,e2e,e2e-test,e2e-tests,e2e_test,e2e_tests,example,examples,fixtures,functional-test,functional-tests,functional_test,functional_tests,integration-test,integration-tests,integration_test,integration_tests,integrationtest,integrationtests,mock,mock-dapp,mocks,perf-test,perf-tests,perf_test,perf_tests,performance-test,performance-tests,performance_test,performance_tests,regression-test,regression-tests,regression_test,regression_tests,smoke-test,smoke-tests,smoke_test,smoke_tests,spec,specs,test,test-data,test-fixtures,testFixtures,testdata,testfixtures,tests,unit-test,unit-tests,unit_test,unit_tests,*.test.js,*.test.jsx,*.test.ts,*.test.tsx,*.test.mjs,*.spec.js,*.spec.jsx,*.spec.ts,*.spec.tsx,*_test.go,*_test.py,*_test.rb,*_test.exs,test_*.py,*Test.java,*Tests.java,*Test.kt,*Tests.kt,*Test.scala,*Test.cs,*Tests.cs,tests.rs,test.rs,yarn.lock,package-lock.json,pnpm-lock.yaml,Cargo.lock,go.sum,poetry.lock,Gemfile.lock,composer.lock,lib,src/xdr,test-lcm,test-tx-meta-baseline,adding-tests,running-tests,serialize-tests,lib/libsodium,lib/xdrpp,lib/libmedida,lib/cereal,lib/asio,lib/fmt,lib/tracy,lib/spdlog,src/protocol-curr/xdr,src/rust/soroban/p21,src/rust/soroban/p22,src/rust/soroban/p23,src/rust/soroban/p24,src/rust/soroban/p25,src/rust/soroban/p26,src/rust/soroban/p27,src/rust/soroban/p28,lib/gperftools"
Copilot AI review requested due to automatic review settings September 29, 2026 08:53

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Trivy exclusions are ineffective, golden directories remain scanned, and abnormal container failures can be reported as successful.

Review effort: Balanced
Findings: 1 High severity · 3 Medium severity · 1 Low severity

Open (5)

Comment thread .github/workflows/socket-basics.yml Outdated
Comment thread .trivyignore
Comment on lines +12 to +27
DS-0029

# 'RUN cd ...' instead of WORKDIR
DS-0013

# Deprecated MAINTAINER instruction
DS-0022

# 'apk add' missing '--no-cache'
DS-0025

# WORKDIR path not absolute
DS-0009

# 'apt-get' missing '-y'
DS-0021
Comment thread .semgrepignore
Comment on lines +113 to +114
test-lcm/
test-tx-meta-baseline/
Copilot AI balanced review requested due to automatic review settings September 29, 2026 22:05

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Copilot AI balanced review requested due to automatic review settings September 29, 2026 22:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Secret scanning broadly excludes tracked tests, fixtures, examples, and lockfiles, creating significant detection blind spots.

Review effort: Balanced
Findings: 1 High severity · 4 Medium severity · 1 Low severity

Open (6)

Comment thread .socket-basics.json
"dockerfiles": ".devcontainer/Dockerfile,docker/Dockerfile,docker/Dockerfile.testing",
"socket_tier_1_enabled": false,
"trivy_vuln_enabled": false,
"trufflehog_exclude_dir": "build,.venv,venv,__pycache__,target,.git,__fixtures__,__mocks__,__snapshots__,__tests__,acceptance-test,acceptance-tests,acceptance_test,acceptance_tests,benches,browser-test,browser-tests,browser_test,browser_tests,e2e,e2e-test,e2e-tests,e2e_test,e2e_tests,example,examples,fixtures,functional-test,functional-tests,functional_test,functional_tests,integration-test,integration-tests,integration_test,integration_tests,integrationtest,integrationtests,mock,mock-dapp,mocks,perf-test,perf-tests,perf_test,perf_tests,performance-test,performance-tests,performance_test,performance_tests,regression-test,regression-tests,regression_test,regression_tests,smoke-test,smoke-tests,smoke_test,smoke_tests,spec,specs,test,test-data,test-fixtures,testFixtures,testdata,testfixtures,tests,unit-test,unit-tests,unit_test,unit_tests,*.test.js,*.test.jsx,*.test.ts,*.test.tsx,*.test.mjs,*.spec.js,*.spec.jsx,*.spec.ts,*.spec.tsx,*_test.go,*_test.py,*_test.rb,*_test.exs,test_*.py,*Test.java,*Tests.java,*Test.kt,*Tests.kt,*Test.scala,*Test.cs,*Tests.cs,tests.rs,test.rs,yarn.lock,package-lock.json,pnpm-lock.yaml,Cargo.lock,go.sum,poetry.lock,Gemfile.lock,composer.lock,lib,src/xdr,test-lcm,test-tx-meta-baseline,adding-tests,running-tests,serialize-tests,lib/libsodium,lib/xdrpp,lib/libmedida,lib/cereal,lib/asio,lib/fmt,lib/tracy,lib/spdlog,src/protocol-curr/xdr,src/rust/soroban/p21,src/rust/soroban/p22,src/rust/soroban/p23,src/rust/soroban/p24,src/rust/soroban/p25,src/rust/soroban/p26,src/rust/soroban/p27,src/rust/soroban/p28,lib/gperftools"
Copilot AI balanced review requested due to automatic review settings September 29, 2026 23:19

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The SAST exclusion references a nonexistent directory, leaving both generated LCM golden directories in scope.

Review effort: Balanced
Findings: 1 High severity · 3 Medium severity · 1 Low severity

Open (5)
Resolved since last review (1)

Runs SAST through OpenGrep, secret scanning through TruffleHog, and
Dockerfile misconfiguration scanning through Trivy, submitting results
to Socket.dev.

  .github/workflows/socket-basics.yml  scheduled weekly + manual dispatch
  .socket-basics.json                  scanner configuration
  .semgrepignore                       SAST path exclusions
  .trivyignore                         Dockerfile lint rules with no
                                       security dimension (only present
                                       where the repo has a Dockerfile)

Separate from socket-scan.yml, which covers dependency CVEs and Tier 1
reachability.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 00:18

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread .trivyignore
Comment on lines +12 to +27
DS-0029

# 'RUN cd ...' instead of WORKDIR
DS-0013

# Deprecated MAINTAINER instruction
DS-0022

# 'apk add' missing '--no-cache'
DS-0025

# WORKDIR path not absolute
DS-0009

# 'apt-get' missing '-y'
DS-0021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants