mirror of
https://github.com/gesellix/Bose-SoundTouch.git
synced 2026-08-18 16:46:17 +00:00
Replace floating major-tag references (uses: foo/bar@vN) with the specific commit SHAs they currently resolve to, annotated with the fully-versioned tag (# vX.Y.Z) for human readability. Pinning to a SHA makes the action behaviour reproducible across runs and removes the supply-chain risk of a maintainer (or attacker) moving a tag to a new commit. One documented exception: semgrep/semgrep-action does not publish v1.x.y semver tags — v1 is their only canonical release name on that line — so it keeps a "# v1" annotation with an inline explanation. actions/dependency-review-action's previous "@v5" reference would have failed at run time: that repo only ships fully-versioned tags (v5.0.0), no moving v5 alias. Pinned to v5.0.0 explicitly. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
190 lines
5.8 KiB
YAML
190 lines
5.8 KiB
YAML
name: Security
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
pull_request:
|
|
branches: [main]
|
|
schedule:
|
|
# Run security scans daily at 2 AM UTC
|
|
- cron: '0 2 * * *'
|
|
workflow_dispatch:
|
|
|
|
jobs:
|
|
vulnerability-scan:
|
|
name: Vulnerability Scan
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Set up Go
|
|
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
|
|
with:
|
|
go-version-file: "go.mod"
|
|
|
|
- name: Install libpcap
|
|
run: sudo apt-get install -y libpcap-dev
|
|
|
|
- name: Install security scanning tools
|
|
run: |
|
|
go install golang.org/x/vuln/cmd/govulncheck@latest
|
|
go install github.com/sonatypecommunity/nancy@latest
|
|
|
|
- name: Run govulncheck (Official Go vulnerability scanner)
|
|
run: |
|
|
echo "::group::Running govulncheck"
|
|
govulncheck ./...
|
|
echo "::endgroup::"
|
|
|
|
- name: Run Nancy vulnerability scanner
|
|
run: |
|
|
echo "::group::Running Nancy dependency scanner"
|
|
go list -json -deps ./... | nancy sleuth
|
|
echo "::endgroup::"
|
|
|
|
- name: Upload vulnerability scan results
|
|
if: failure()
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: vulnerability-scan-results
|
|
path: |
|
|
vulnerability-report.json
|
|
nancy-report.json
|
|
|
|
static-analysis:
|
|
name: Static Security Analysis
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Set up Go
|
|
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
|
|
with:
|
|
go-version-file: "go.mod"
|
|
|
|
- name: Install libpcap
|
|
run: sudo apt-get install -y libpcap-dev
|
|
|
|
- name: Install static analysis tools
|
|
run: |
|
|
go install honnef.co/go/tools/cmd/staticcheck@latest
|
|
|
|
- name: Run staticcheck security analysis
|
|
run: |
|
|
echo "::group::Running staticcheck"
|
|
staticcheck ./...
|
|
echo "::endgroup::"
|
|
|
|
- name: Run Semgrep security analysis
|
|
uses: semgrep/semgrep-action@713efdd345f3035192eaa63f56867b88e63e4e5d # v1 (no v1.x.y semver tag exists)
|
|
with:
|
|
config: >-
|
|
p/security-audit
|
|
p/secrets
|
|
p/golang
|
|
generateSarif: "1"
|
|
continue-on-error: true
|
|
|
|
- name: Upload Semgrep SARIF results
|
|
if: always()
|
|
uses: github/codeql-action/upload-sarif@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4.35.4
|
|
with:
|
|
sarif_file: semgrep.sarif
|
|
continue-on-error: true
|
|
|
|
codeql-analysis:
|
|
name: CodeQL Analysis
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
actions: read
|
|
contents: read
|
|
security-events: write
|
|
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Install libpcap
|
|
run: sudo apt-get install -y libpcap-dev
|
|
|
|
- name: Initialize CodeQL
|
|
uses: github/codeql-action/init@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4.35.4
|
|
with:
|
|
languages: go
|
|
config-file: ./.github/codeql-config.yml
|
|
|
|
- name: Autobuild
|
|
uses: github/codeql-action/autobuild@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4.35.4
|
|
|
|
- name: Perform CodeQL Analysis
|
|
uses: github/codeql-action/analyze@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4.35.4
|
|
with:
|
|
category: "/language:go"
|
|
|
|
dependency-review:
|
|
name: Dependency Review
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
if: github.event_name == 'pull_request'
|
|
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Dependency Review
|
|
uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0
|
|
with:
|
|
fail-on-severity: moderate
|
|
allow-ghsas: GHSA-xxxx-xxxx-xxxx # Add specific allowlisted advisories if needed
|
|
deny-licenses: GPL-2.0, LGPL-2.0 # Add licenses to deny if needed
|
|
|
|
security-summary:
|
|
name: Security Summary
|
|
runs-on: ubuntu-latest
|
|
needs: [vulnerability-scan, static-analysis, codeql-analysis]
|
|
if: always()
|
|
permissions:
|
|
contents: read
|
|
|
|
steps:
|
|
- name: Security scan summary
|
|
run: |
|
|
echo "## Security Scan Results" >> $GITHUB_STEP_SUMMARY
|
|
echo "" >> $GITHUB_STEP_SUMMARY
|
|
|
|
if [[ "${{ needs.vulnerability-scan.result }}" == "success" ]]; then
|
|
echo "✅ **Vulnerability Scan**: PASSED" >> $GITHUB_STEP_SUMMARY
|
|
else
|
|
echo "❌ **Vulnerability Scan**: FAILED" >> $GITHUB_STEP_SUMMARY
|
|
fi
|
|
|
|
if [[ "${{ needs.static-analysis.result }}" == "success" ]]; then
|
|
echo "✅ **Static Analysis**: PASSED" >> $GITHUB_STEP_SUMMARY
|
|
else
|
|
echo "❌ **Static Analysis**: FAILED" >> $GITHUB_STEP_SUMMARY
|
|
fi
|
|
|
|
if [[ "${{ needs.codeql-analysis.result }}" == "success" ]]; then
|
|
echo "✅ **CodeQL Analysis**: PASSED" >> $GITHUB_STEP_SUMMARY
|
|
else
|
|
echo "❌ **CodeQL Analysis**: FAILED" >> $GITHUB_STEP_SUMMARY
|
|
fi
|
|
|
|
echo "" >> $GITHUB_STEP_SUMMARY
|
|
echo "For detailed results, check the individual job logs above." >> $GITHUB_STEP_SUMMARY
|
|
|
|
- name: Fail on security issues
|
|
if: needs.vulnerability-scan.result == 'failure' || needs.static-analysis.result == 'failure' || needs.codeql-analysis.result == 'failure'
|
|
run: |
|
|
echo "Security scan detected issues. Please review the results above."
|
|
exit 1
|