Add Socket Basics security scanning workflow - #5460
kanwalpreetd wants to merge 1 commit into
Conversation
62a98c8 to
34c0284
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The missing-completion-marker path can report an error while still exiting successfully.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Adds scheduled and on-demand Socket Basics security scanning.
Changes:
- Configures SAST, secret, and Dockerfile scanning.
- Adds scan exclusions and rule suppressions.
- Runs a pinned scanner image and reports findings.
| File | Description |
|---|---|
.github/workflows/socket-basics.yml |
Defines the security scan workflow. |
.socket-basics.json |
Configures scanners and exclusions. |
.semgrepignore |
Excludes generated, vendored, and test paths. |
.trivyignore |
Suppresses selected Dockerfile rules. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
34c0284 to
4fd5b64
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The workflow can report success after scanner or upload failures, and intended golden-data exclusions do not match actual paths.
Review effort: Balanced
Findings: 1
Open (2)
Resolved since last review (1)
| if grep -q "Scan completed!" /tmp/socket-basics.log; then | ||
| hc=$(grep -oE "Found [0-9]+ high/critical" /tmp/socket-basics.log \ | ||
| | grep -oE "[0-9]+" | head -1) | ||
| if [ -n "$hc" ] && [ "$hc" -gt 0 ]; then | ||
| echo "::warning::Socket Basics found $hc high/critical finding(s)" | ||
| fi | ||
| exit 0 | ||
| fi |
| "dockerfiles": ".devcontainer/Dockerfile,docker/Dockerfile,docker/Dockerfile.testing", | ||
| "socket_tier_1_enabled": false, | ||
| "trivy_vuln_enabled": false, | ||
| "trufflehog_exclude_dir": "build,.venv,venv,__pycache__,target,.git,__fixtures__,__mocks__,__snapshots__,__tests__,acceptance-test,acceptance-tests,acceptance_test,acceptance_tests,benches,browser-test,browser-tests,browser_test,browser_tests,e2e,e2e-test,e2e-tests,e2e_test,e2e_tests,example,examples,fixtures,functional-test,functional-tests,functional_test,functional_tests,integration-test,integration-tests,integration_test,integration_tests,integrationtest,integrationtests,mock,mock-dapp,mocks,perf-test,perf-tests,perf_test,perf_tests,performance-test,performance-tests,performance_test,performance_tests,regression-test,regression-tests,regression_test,regression_tests,smoke-test,smoke-tests,smoke_test,smoke_tests,spec,specs,test,test-data,test-fixtures,testFixtures,testdata,testfixtures,tests,unit-test,unit-tests,unit_test,unit_tests,*.test.js,*.test.jsx,*.test.ts,*.test.tsx,*.test.mjs,*.spec.js,*.spec.jsx,*.spec.ts,*.spec.tsx,*_test.go,*_test.py,*_test.rb,*_test.exs,test_*.py,*Test.java,*Tests.java,*Test.kt,*Tests.kt,*Test.scala,*Test.cs,*Tests.cs,tests.rs,test.rs,yarn.lock,package-lock.json,pnpm-lock.yaml,Cargo.lock,go.sum,poetry.lock,Gemfile.lock,composer.lock,lib,src/xdr,test-lcm,test-tx-meta-baseline,adding-tests,running-tests,serialize-tests,lib/libsodium,lib/xdrpp,lib/libmedida,lib/cereal,lib/asio,lib/fmt,lib/tracy,lib/spdlog,src/protocol-curr/xdr,src/rust/soroban/p21,src/rust/soroban/p22,src/rust/soroban/p23,src/rust/soroban/p24,src/rust/soroban/p25,src/rust/soroban/p26,src/rust/soroban/p27,src/rust/soroban/p28,lib/gperftools" |
4fd5b64 to
4a8aea5
Compare
4a8aea5 to
7a688f4
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Trivy exclusions are ineffective, golden directories remain scanned, and abnormal container failures can be reported as successful.
Review effort: Balanced
Findings: 1
Open (5)
Require all connector and upload success markers before reporting success Preserve abnormal Docker exit statuses · New Use full canonical Trivy rule IDs for exclusions · New Fix golden-data exclusions to match suffixed repository directories Exclude actual generated golden directories from OpenGrep scans · New
| DS-0029 | ||
|
|
||
| # 'RUN cd ...' instead of WORKDIR | ||
| DS-0013 | ||
|
|
||
| # Deprecated MAINTAINER instruction | ||
| DS-0022 | ||
|
|
||
| # 'apk add' missing '--no-cache' | ||
| DS-0025 | ||
|
|
||
| # WORKDIR path not absolute | ||
| DS-0009 | ||
|
|
||
| # 'apt-get' missing '-y' | ||
| DS-0021 |
| test-lcm/ | ||
| test-tx-meta-baseline/ |
7a688f4 to
3e1d482
Compare
3e1d482 to
80ec448
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Secret scanning broadly excludes tracked tests, fixtures, examples, and lockfiles, creating significant detection blind spots.
Review effort: Balanced
Findings: 1
Open (6)
Require all connector and upload success markers before reporting success TruffleHog exclusions create secret-scanning blind spots · New Use full canonical Trivy rule IDs for exclusions Preserve abnormal Docker exit statuses Fix golden-data exclusions to match suffixed repository directories Exclude actual generated golden directories from OpenGrep scans
| "dockerfiles": ".devcontainer/Dockerfile,docker/Dockerfile,docker/Dockerfile.testing", | ||
| "socket_tier_1_enabled": false, | ||
| "trivy_vuln_enabled": false, | ||
| "trufflehog_exclude_dir": "build,.venv,venv,__pycache__,target,.git,__fixtures__,__mocks__,__snapshots__,__tests__,acceptance-test,acceptance-tests,acceptance_test,acceptance_tests,benches,browser-test,browser-tests,browser_test,browser_tests,e2e,e2e-test,e2e-tests,e2e_test,e2e_tests,example,examples,fixtures,functional-test,functional-tests,functional_test,functional_tests,integration-test,integration-tests,integration_test,integration_tests,integrationtest,integrationtests,mock,mock-dapp,mocks,perf-test,perf-tests,perf_test,perf_tests,performance-test,performance-tests,performance_test,performance_tests,regression-test,regression-tests,regression_test,regression_tests,smoke-test,smoke-tests,smoke_test,smoke_tests,spec,specs,test,test-data,test-fixtures,testFixtures,testdata,testfixtures,tests,unit-test,unit-tests,unit_test,unit_tests,*.test.js,*.test.jsx,*.test.ts,*.test.tsx,*.test.mjs,*.spec.js,*.spec.jsx,*.spec.ts,*.spec.tsx,*_test.go,*_test.py,*_test.rb,*_test.exs,test_*.py,*Test.java,*Tests.java,*Test.kt,*Tests.kt,*Test.scala,*Test.cs,*Tests.cs,tests.rs,test.rs,yarn.lock,package-lock.json,pnpm-lock.yaml,Cargo.lock,go.sum,poetry.lock,Gemfile.lock,composer.lock,lib,src/xdr,test-lcm,test-tx-meta-baseline,adding-tests,running-tests,serialize-tests,lib/libsodium,lib/xdrpp,lib/libmedida,lib/cereal,lib/asio,lib/fmt,lib/tracy,lib/spdlog,src/protocol-curr/xdr,src/rust/soroban/p21,src/rust/soroban/p22,src/rust/soroban/p23,src/rust/soroban/p24,src/rust/soroban/p25,src/rust/soroban/p26,src/rust/soroban/p27,src/rust/soroban/p28,lib/gperftools" |
80ec448 to
27c40de
Compare
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The SAST exclusion references a nonexistent directory, leaving both generated LCM golden directories in scope.
Review effort: Balanced
Findings: 1
Open (5)
Require all connector and upload success markers before reporting success TruffleHog exclusions create secret-scanning blind spots Use full canonical Trivy rule IDs for exclusions Fix golden-data exclusions to match suffixed repository directories Exclude actual generated golden directories from OpenGrep scans
Resolved since last review (1)
Runs SAST through OpenGrep, secret scanning through TruffleHog, and
Dockerfile misconfiguration scanning through Trivy, submitting results
to Socket.dev.
.github/workflows/socket-basics.yml scheduled weekly + manual dispatch
.socket-basics.json scanner configuration
.semgrepignore SAST path exclusions
.trivyignore Dockerfile lint rules with no
security dimension (only present
where the repo has a Dockerfile)
Separate from socket-scan.yml, which covers dependency CVEs and Tier 1
reachability.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
27c40de to
f274ab2
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The Trivy exclusions use incomplete rule IDs and therefore will not suppress the intended findings.
Review effort: Balanced
Findings: 1
Open (6)
Require all connector and upload success markers before reporting success Add AVD- prefixes to Trivy ignore entries · New TruffleHog exclusions create secret-scanning blind spots Use full canonical Trivy rule IDs for exclusions Fix golden-data exclusions to match suffixed repository directories Exclude actual generated golden directories from OpenGrep scans
| DS-0029 | ||
|
|
||
| # 'RUN cd ...' instead of WORKDIR | ||
| DS-0013 | ||
|
|
||
| # Deprecated MAINTAINER instruction | ||
| DS-0022 | ||
|
|
||
| # 'apk add' missing '--no-cache' | ||
| DS-0025 | ||
|
|
||
| # WORKDIR path not absolute | ||
| DS-0009 | ||
|
|
||
| # 'apt-get' missing '-y' | ||
| DS-0021 |



More info: https://stellarorg.atlassian.net/wiki/spaces/SCRT/pages/5901680652/Socket+Basics+Integration+Guide