Files
cairnobs/.github/workflows/security-scan.yml
T
dependabot[bot] 11c2e89d25 Bump the actions group across 1 directory with 3 updates
Bumps the actions group with 3 updates in the / directory: [actions/checkout](https://github.com/actions/checkout), [actions/setup-go](https://github.com/actions/setup-go) and [actions/setup-node](https://github.com/actions/setup-node).


Updates `actions/checkout` from 4 to 7
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4...v7)

Updates `actions/setup-go` from 5 to 7
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](https://github.com/actions/setup-go/compare/v5...v7)

Updates `actions/setup-node` from 4 to 7
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](https://github.com/actions/setup-node/compare/v4...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions/setup-go
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <[email protected]>
2026-09-10 16:59:19 +00:00

98 lines
3.8 KiB
YAML

name: Security scan
# Closes a real gap the security audit found: license-compliance.yml
# (this repo's only other workflow) checks license text, never
# vulnerabilities -- and agent/deny.toml and search/deny.toml already
# ship an [advisories] policy that nothing in CI ever invoked. Same
# matrix-per-language shape as license-compliance.yml, extended to the
# equivalent vulnerability-scanning tool per ecosystem: cargo-deny's
# other command for Rust, govulncheck for Go, npm audit for the one
# npm package. A new dependency with a known vulnerability now fails
# the build here, not months later when someone happens to re-run this
# by hand.
on:
push:
branches: [master, main]
pull_request:
jobs:
rust-advisories:
name: Rust vulnerability check (cargo-deny)
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
crate_dir: [agent, search]
steps:
- uses: actions/checkout@v7
- uses: EmbarkStudios/cargo-deny-action@v2
with:
manifest-path: ${{ matrix.crate_dir }}/Cargo.toml
command: check advisories
go-vulncheck:
name: Go vulnerability check (govulncheck)
runs-on: ubuntu-latest
strategy:
# One module's findings must not cancel the other eight -- with
# fail-fast a single failure hid the whole matrix behind one log.
fail-fast: false
matrix:
# Same module list as license-compliance.yml's go-licenses job --
# see that job's own comment for why cli/hack-webhook-sink/
# hack-alert-load-test are excluded (no third-party dependencies
# at audit time).
module_dir:
- api
- ingest
- alerting
- enterprise
- deploy/operator
- terraform
- proto
- hack/benchmark-fixture
- hack/windows-fixture
steps:
- uses: actions/checkout@v7
- uses: actions/setup-go@v7
with:
# Deliberately NOT go-version-file. Each go.mod pins an exact
# patch, so go-version-file made CI scan against the *unpatched*
# standard library of that patch and fail on 28 stdlib CVEs --
# crypto/x509 quadratic name-constraint parsing (GO-2025-4007)
# and friends, all long since fixed. None of it was real: every
# Dockerfile builds `FROM golang:1.26-alpine`, a floating tag
# that resolves to the newest 1.26.x, so the shipped binaries
# already had the fixes. The go directive states the minimum
# language version, not the toolchain to audit with. Track the
# floating 1.26 line so this scans what production actually
# builds, and keep it in step with the Dockerfiles above all --
# a mismatch here fails every module at once.
go-version: '1.26'
- run: go install golang.org/x/vuln/cmd/govulncheck@latest
- name: Check for known vulnerabilities
working-directory: ${{ matrix.module_dir }}
run: govulncheck ./...
npm-audit:
name: npm vulnerability check (npm audit)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version: 22
- working-directory: web
run: npm ci
- name: Audit production dependencies
working-directory: web
# --omit=dev, not the deprecated --production: this deliberately
# only gates the runtime bundle a real deployment actually
# ships. The one known finding in web's full dependency tree
# today (a `cookie` advisory) lives entirely in the SvelteKit
# build toolchain, not the production bundle -- fixing it needs
# a deliberate, tested major-version bump, not an automated
# `audit fix --force`, so it's out of scope for this gate.
run: npm audit --omit=dev