Skip to content

Security Scanning

Security Scanning #4

Workflow file for this run

name: Security Scanning
on:
workflow_dispatch: # Manual only - PR scans run in ci.yml
# Removed weekly schedule - security scans run on every PR via ci.yml
permissions:
actions: read
contents: read
security-events: write
jobs:
codeql:
name: CodeQL Analysis (GitHub Actions)
runs-on: ubuntu-22.04
timeout-minutes: 10
strategy:
fail-fast: false
matrix:
language: [ 'actions' ]
steps:
- name: Checkout
uses: actions/checkout@v5
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
with:
languages: ${{ matrix.language }}
queries: security-and-quality
# For 'actions' analysis, no build step is required
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3
with:
category: "/language:${{ matrix.language }}"
dependency-check:
name: Dependency Vulnerability Scan
runs-on: ubuntu-22.04
timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@v5
- name: Set up JDK 17
uses: actions/setup-java@v5
with:
distribution: temurin
java-version: '17'
cache: 'sbt'
- name: Run dependency check
continue-on-error: true
run: |
# Check if sbt-dependency-check plugin is configured
if grep -q "sbt-dependency-check" project/plugins.sbt 2>/dev/null; then
echo "✓ sbt-dependency-check plugin found, running scan"
sbt -batch dependencyCheck
else
echo "⚠️ sbt-dependency-check plugin not configured in project/plugins.sbt"
echo "To enable: Add 'addSbtPlugin(\"net.vonbuchholtz\" % \"sbt-dependency-check\" % \"x.x.x\")'"
exit 0
fi
- name: Upload dependency check report
if: always()
uses: actions/upload-artifact@v4
with:
name: dependency-check-report
path: target/dependency-check-report.html
retention-days: 30
secret-scan:
name: Secret Scanning
runs-on: ubuntu-22.04
timeout-minutes: 10
steps:
- name: Checkout
uses: actions/checkout@v5
with:
fetch-depth: 0
- name: TruffleHog OSS
uses: trufflesecurity/trufflehog@main
with:
path: ./
base: ${{ github.event_name == 'pull_request' && github.event.pull_request.base.sha || 'HEAD~50' }}
head: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.sha || 'HEAD' }}
extra_args: --debug --only-verified