Repository navigation
63 lines (53 loc) · 1.84 KB
/
Copy pathsecurity.yml
File metadata and controls
63 lines (53 loc) · 1.84 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
name: Security
on:
pull_request:
push:
branches: [main]
schedule:
- cron: '0 7 * * 1'
workflow_dispatch:
concurrency:
group: security-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
cargo-deny:
name: Rust advisories & licenses
runs-on: ubuntu-22.04
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
# iroh terminates QUIC from the open internet; `bans` catches a duplicate crate copy.
- name: cargo-deny
uses: EmbarkStudios/cargo-deny-action@3c6349835b2b7b196a839186cb8b78e02f7b5f25 # v2.1.1
with:
manifest-path: src-tauri/Cargo.toml
command: check advisories bans licenses sources
pnpm-audit:
name: Frontend advisories
runs-on: ubuntu-22.04
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: ./.github/actions/setup-node
# `high` only: the app is static and ships no server, so request-handling advisories do not
# apply.
- name: Audit (gate)
run: pnpm audit --audit-level=high
- name: Audit (full report)
if: ${{ !cancelled() }}
run: pnpm audit || true
secrets:
name: Secret scan
runs-on: ubuntu-22.04
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Full history: gitleaks scans commits, not just the tree.
fetch-depth: 0
# The binary: gitleaks-action needs a paid licence for org-owned repos.
- name: Run gitleaks
run: |
curl -sSfL -o gitleaks.tar.gz \
https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_linux_x64.tar.gz
tar -xzf gitleaks.tar.gz gitleaks
./gitleaks git . --redact --verbose --exit-code 1 --config .gitleaks.toml