Bumps the actions group with 3 updates in the / directory: [actions/checkout](https://github.com/actions/checkout), [actions/setup-go](https://github.com/actions/setup-go) and [actions/setup-node](https://github.com/actions/setup-node). Updates `actions/checkout` from 4 to 7 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/v4...v7) Updates `actions/setup-go` from 5 to 7 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](https://github.com/actions/setup-go/compare/v5...v7) Updates `actions/setup-node` from 4 to 7 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](https://github.com/actions/setup-node/compare/v4...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/setup-go dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/setup-node dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions ... Signed-off-by: dependabot[bot] <[email protected]>
98 lines
3.8 KiB
YAML
98 lines
3.8 KiB
YAML
name: Security scan
|
|
|
|
# Closes a real gap the security audit found: license-compliance.yml
|
|
# (this repo's only other workflow) checks license text, never
|
|
# vulnerabilities -- and agent/deny.toml and search/deny.toml already
|
|
# ship an [advisories] policy that nothing in CI ever invoked. Same
|
|
# matrix-per-language shape as license-compliance.yml, extended to the
|
|
# equivalent vulnerability-scanning tool per ecosystem: cargo-deny's
|
|
# other command for Rust, govulncheck for Go, npm audit for the one
|
|
# npm package. A new dependency with a known vulnerability now fails
|
|
# the build here, not months later when someone happens to re-run this
|
|
# by hand.
|
|
|
|
on:
|
|
push:
|
|
branches: [master, main]
|
|
pull_request:
|
|
|
|
jobs:
|
|
rust-advisories:
|
|
name: Rust vulnerability check (cargo-deny)
|
|
runs-on: ubuntu-latest
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
crate_dir: [agent, search]
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: EmbarkStudios/cargo-deny-action@v2
|
|
with:
|
|
manifest-path: ${{ matrix.crate_dir }}/Cargo.toml
|
|
command: check advisories
|
|
|
|
go-vulncheck:
|
|
name: Go vulnerability check (govulncheck)
|
|
runs-on: ubuntu-latest
|
|
strategy:
|
|
# One module's findings must not cancel the other eight -- with
|
|
# fail-fast a single failure hid the whole matrix behind one log.
|
|
fail-fast: false
|
|
matrix:
|
|
# Same module list as license-compliance.yml's go-licenses job --
|
|
# see that job's own comment for why cli/hack-webhook-sink/
|
|
# hack-alert-load-test are excluded (no third-party dependencies
|
|
# at audit time).
|
|
module_dir:
|
|
- api
|
|
- ingest
|
|
- alerting
|
|
- enterprise
|
|
- deploy/operator
|
|
- terraform
|
|
- proto
|
|
- hack/benchmark-fixture
|
|
- hack/windows-fixture
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: actions/setup-go@v7
|
|
with:
|
|
# Deliberately NOT go-version-file. Each go.mod pins an exact
|
|
# patch, so go-version-file made CI scan against the *unpatched*
|
|
# standard library of that patch and fail on 28 stdlib CVEs --
|
|
# crypto/x509 quadratic name-constraint parsing (GO-2025-4007)
|
|
# and friends, all long since fixed. None of it was real: every
|
|
# Dockerfile builds `FROM golang:1.26-alpine`, a floating tag
|
|
# that resolves to the newest 1.26.x, so the shipped binaries
|
|
# already had the fixes. The go directive states the minimum
|
|
# language version, not the toolchain to audit with. Track the
|
|
# floating 1.26 line so this scans what production actually
|
|
# builds, and keep it in step with the Dockerfiles above all --
|
|
# a mismatch here fails every module at once.
|
|
go-version: '1.26'
|
|
- run: go install golang.org/x/vuln/cmd/govulncheck@latest
|
|
- name: Check for known vulnerabilities
|
|
working-directory: ${{ matrix.module_dir }}
|
|
run: govulncheck ./...
|
|
|
|
npm-audit:
|
|
name: npm vulnerability check (npm audit)
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: actions/setup-node@v7
|
|
with:
|
|
node-version: 22
|
|
- working-directory: web
|
|
run: npm ci
|
|
- name: Audit production dependencies
|
|
working-directory: web
|
|
# --omit=dev, not the deprecated --production: this deliberately
|
|
# only gates the runtime bundle a real deployment actually
|
|
# ships. The one known finding in web's full dependency tree
|
|
# today (a `cookie` advisory) lives entirely in the SvelteKit
|
|
# build toolchain, not the production bundle -- fixing it needs
|
|
# a deliberate, tested major-version bump, not an automated
|
|
# `audit fix --force`, so it's out of scope for this gate.
|
|
run: npm audit --omit=dev
|