Security Scanning #4
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Security Scanning | |
| on: | |
| workflow_dispatch: # Manual only - PR scans run in ci.yml | |
| # Removed weekly schedule - security scans run on every PR via ci.yml | |
| permissions: | |
| actions: read | |
| contents: read | |
| security-events: write | |
| jobs: | |
| codeql: | |
| name: CodeQL Analysis (GitHub Actions) | |
| runs-on: ubuntu-22.04 | |
| timeout-minutes: 10 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| language: [ 'actions' ] | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v5 | |
| - name: Initialize CodeQL | |
| uses: github/codeql-action/init@v3 | |
| with: | |
| languages: ${{ matrix.language }} | |
| queries: security-and-quality | |
| # For 'actions' analysis, no build step is required | |
| - name: Perform CodeQL Analysis | |
| uses: github/codeql-action/analyze@v3 | |
| with: | |
| category: "/language:${{ matrix.language }}" | |
| dependency-check: | |
| name: Dependency Vulnerability Scan | |
| runs-on: ubuntu-22.04 | |
| timeout-minutes: 15 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v5 | |
| - name: Set up JDK 17 | |
| uses: actions/setup-java@v5 | |
| with: | |
| distribution: temurin | |
| java-version: '17' | |
| cache: 'sbt' | |
| - name: Run dependency check | |
| continue-on-error: true | |
| run: | | |
| # Check if sbt-dependency-check plugin is configured | |
| if grep -q "sbt-dependency-check" project/plugins.sbt 2>/dev/null; then | |
| echo "✓ sbt-dependency-check plugin found, running scan" | |
| sbt -batch dependencyCheck | |
| else | |
| echo "⚠️ sbt-dependency-check plugin not configured in project/plugins.sbt" | |
| echo "To enable: Add 'addSbtPlugin(\"net.vonbuchholtz\" % \"sbt-dependency-check\" % \"x.x.x\")'" | |
| exit 0 | |
| fi | |
| - name: Upload dependency check report | |
| if: always() | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: dependency-check-report | |
| path: target/dependency-check-report.html | |
| retention-days: 30 | |
| secret-scan: | |
| name: Secret Scanning | |
| runs-on: ubuntu-22.04 | |
| timeout-minutes: 10 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v5 | |
| with: | |
| fetch-depth: 0 | |
| - name: TruffleHog OSS | |
| uses: trufflesecurity/trufflehog@main | |
| with: | |
| path: ./ | |
| base: ${{ github.event_name == 'pull_request' && github.event.pull_request.base.sha || 'HEAD~50' }} | |
| head: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.sha || 'HEAD' }} | |
| extra_args: --debug --only-verified |