Two Dependabot PRs are stuck behind the same number. #35 raises the go directive to 1.26.0 in six modules, because golang.org/x/crypto v0.56.0 requires it -- x/crypto tracks the two most recent Go releases and 0.56 dropped 1.25. A module that says 1.26 cannot be built by the 1.25 this repository pins in two places, so that PR fails every Go job. #29 raises actions/setup-go to v7, which sets GOTOOLCHAIN=local. With that set, `go install golang.org/x/vuln/cmd/govulncheck@latest` cannot quietly fetch a newer toolchain, and stops with golang.org/x/[email protected] requires go >= 1.26.0 (running go 1.25.14) Under setup-go v5 the same install succeeded by downloading 1.26 behind our backs, which is its own reason to be on 1.26 deliberately instead. So: security-scan's go-version and all eight Dockerfiles move together, 1.25 -> 1.26. Nothing else needs to. A newer toolchain builds an older directive happily, so this stands on its own before #35 lands, and the go.mod files stay where they are here. Checked by building rather than by reading: the api and ingest images both build on golang:1.26-alpine, and api, ingest and enterprise still `go build ./...` clean against their existing 1.25 directives.
98 lines
3.8 KiB
YAML
98 lines
3.8 KiB
YAML
name: Security scan
|
|
|
|
# Closes a real gap the security audit found: license-compliance.yml
|
|
# (this repo's only other workflow) checks license text, never
|
|
# vulnerabilities -- and agent/deny.toml and search/deny.toml already
|
|
# ship an [advisories] policy that nothing in CI ever invoked. Same
|
|
# matrix-per-language shape as license-compliance.yml, extended to the
|
|
# equivalent vulnerability-scanning tool per ecosystem: cargo-deny's
|
|
# other command for Rust, govulncheck for Go, npm audit for the one
|
|
# npm package. A new dependency with a known vulnerability now fails
|
|
# the build here, not months later when someone happens to re-run this
|
|
# by hand.
|
|
|
|
on:
|
|
push:
|
|
branches: [master, main]
|
|
pull_request:
|
|
|
|
jobs:
|
|
rust-advisories:
|
|
name: Rust vulnerability check (cargo-deny)
|
|
runs-on: ubuntu-latest
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
crate_dir: [agent, search]
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: EmbarkStudios/cargo-deny-action@v2
|
|
with:
|
|
manifest-path: ${{ matrix.crate_dir }}/Cargo.toml
|
|
command: check advisories
|
|
|
|
go-vulncheck:
|
|
name: Go vulnerability check (govulncheck)
|
|
runs-on: ubuntu-latest
|
|
strategy:
|
|
# One module's findings must not cancel the other eight -- with
|
|
# fail-fast a single failure hid the whole matrix behind one log.
|
|
fail-fast: false
|
|
matrix:
|
|
# Same module list as license-compliance.yml's go-licenses job --
|
|
# see that job's own comment for why cli/hack-webhook-sink/
|
|
# hack-alert-load-test are excluded (no third-party dependencies
|
|
# at audit time).
|
|
module_dir:
|
|
- api
|
|
- ingest
|
|
- alerting
|
|
- enterprise
|
|
- deploy/operator
|
|
- terraform
|
|
- proto
|
|
- hack/benchmark-fixture
|
|
- hack/windows-fixture
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-go@v5
|
|
with:
|
|
# Deliberately NOT go-version-file. Each go.mod pins an exact
|
|
# patch, so go-version-file made CI scan against the *unpatched*
|
|
# standard library of that patch and fail on 28 stdlib CVEs --
|
|
# crypto/x509 quadratic name-constraint parsing (GO-2025-4007)
|
|
# and friends, all long since fixed. None of it was real: every
|
|
# Dockerfile builds `FROM golang:1.26-alpine`, a floating tag
|
|
# that resolves to the newest 1.26.x, so the shipped binaries
|
|
# already had the fixes. The go directive states the minimum
|
|
# language version, not the toolchain to audit with. Track the
|
|
# floating 1.26 line so this scans what production actually
|
|
# builds, and keep it in step with the Dockerfiles above all --
|
|
# a mismatch here fails every module at once.
|
|
go-version: '1.26'
|
|
- run: go install golang.org/x/vuln/cmd/govulncheck@latest
|
|
- name: Check for known vulnerabilities
|
|
working-directory: ${{ matrix.module_dir }}
|
|
run: govulncheck ./...
|
|
|
|
npm-audit:
|
|
name: npm vulnerability check (npm audit)
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: 22
|
|
- working-directory: web
|
|
run: npm ci
|
|
- name: Audit production dependencies
|
|
working-directory: web
|
|
# --omit=dev, not the deprecated --production: this deliberately
|
|
# only gates the runtime bundle a real deployment actually
|
|
# ships. The one known finding in web's full dependency tree
|
|
# today (a `cookie` advisory) lives entirely in the SvelteKit
|
|
# build toolchain, not the production bundle -- fixing it needs
|
|
# a deliberate, tested major-version bump, not an automated
|
|
# `audit fix --force`, so it's out of scope for this gate.
|
|
run: npm audit --omit=dev
|