Skip to content

ci: migrate to reusable-security-scan - #1

Closed
vakaobr wants to merge 2 commits into
mainfrom
andersonext/dso-66-security-scan
Closed

ci: migrate to reusable-security-scan#1
vakaobr wants to merge 2 commits into
mainfrom
andersonext/dso-66-security-scan

Conversation

@vakaobr

@vakaobr vakaobr commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

Adds the standard Security Scan workflow (aminitech/.github reusable-security-scan.yaml): Semgrep SAST on every push/PR, plus an AI Security Review on PRs that consolidates the Semgrep SARIF + Trivy/Grype dependency scan + a security-persona review of the diff, posts comments + a Check Run, and gates on Critical/High.

Requires the ANTHROPIC_API_KEY org/repo Actions secret (the ai-security-review job needs it; Semgrep still runs without it).

Tracked in DSO-66.

🤖 Generated with Claude Code

@vakaobr
vakaobr force-pushed the andersonext/dso-66-security-scan branch from 2e55012 to 2c821ec Compare July 27, 2026 18:11
@vakaobr vakaobr changed the title ci: add Security Scan (semgrep + AI security review) ci: migrate to reusable-security-scan Jul 29, 2026
@vakaobr

vakaobr commented Jul 30, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #2 (pinned to reusable-security-scan v1.3.0 and merged).

@vakaobr vakaobr closed this Jul 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant