Skip to content
This repository was archived by the owner on Jun 22, 2026. It is now read-only.

chore(deps): Bump ws from 8.19.0 to 8.21.0 in /apps/mobile #341

chore(deps): Bump ws from 8.19.0 to 8.21.0 in /apps/mobile

chore(deps): Bump ws from 8.19.0 to 8.21.0 in /apps/mobile #341

Workflow file for this run

name: SAST
on:
workflow_dispatch:
push:
branches: [main, develop]
pull_request:
branches: [main, develop]
schedule:
- cron: '0 6 * * 1' # Weekly Monday 6am UTC
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
bandit:
name: Bandit (Python Security)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- name: Set up Python
uses: actions/setup-python@v6
with:
python-version: '3.11'
- name: Install Bandit
run: pip install bandit[toml]
- name: Run Bandit
run: bandit -r backend/app -f json -o bandit-report.json --severity-level medium
continue-on-error: true
- name: Upload Bandit Report
uses: actions/upload-artifact@v7
if: always()
with:
name: bandit-report
path: bandit-report.json
retention-days: 30
- name: Bandit (Strict - fail on high severity)
run: bandit -r backend/app --severity-level high --confidence-level high
semgrep:
name: Semgrep
runs-on: ubuntu-latest
container:
image: semgrep/semgrep
steps:
- uses: actions/checkout@v6
- name: Run Semgrep
run: semgrep scan --config=auto --config=p/security-audit --config=p/python --json --output=semgrep-report.json backend/
continue-on-error: true
- name: Upload Semgrep Report
uses: actions/upload-artifact@v7
if: always()
with:
name: semgrep-report
path: semgrep-report.json
retention-days: 30
- name: Semgrep (Strict)
run: semgrep scan --config=auto --error backend/
trivy-code:
name: Trivy (Code Scanning)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- name: Run Trivy filesystem scan
uses: aquasecurity/trivy-action@master
with:
scan-type: 'fs'
scan-ref: '.'
format: 'table'
severity: 'CRITICAL'
exit-code: '1'
- name: Trivy HIGH (informational)
uses: aquasecurity/trivy-action@master
with:
scan-type: 'fs'
scan-ref: '.'
format: 'table'
severity: 'HIGH'
exit-code: '0'
trivy-config:
name: Trivy (K8s/IaC Scanning)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- name: Scan Kubernetes manifests
uses: aquasecurity/trivy-action@master
with:
scan-type: 'config'
scan-ref: 'k8s/'
format: 'table'
severity: 'CRITICAL,HIGH'
exit-code: '0'
- name: Scan Dockerfile
uses: aquasecurity/trivy-action@master
with:
scan-type: 'config'
scan-ref: 'Dockerfile'
format: 'table'
severity: 'CRITICAL,HIGH,MEDIUM'
exit-code: '0'