Add security scanning to CI pipeline

- Add pip-audit check to PR workflow (non-blocking warning)
- Add npm audit check to PR workflow (non-blocking, high severity only)
- Create scheduled weekly security audit workflow that:
  - Runs strict pip-audit and npm audit
  - Creates/updates GitHub issues when vulnerabilities found
  - Uploads audit results as artifacts
  - Supports manual trigger via workflow_dispatch
This commit is contained in:
maziggy
2026-01-26 13:20:33 +01:00
parent c7458fc73f
commit 4b2d8b51e0
2 changed files with 2 additions and 2 deletions
+1 -1
View File
@@ -146,7 +146,7 @@ jobs:
- name: Run npm audit
working-directory: frontend
run: npm audit --audit-level=moderate
run: npm audit --audit-level=high
frontend-typecheck:
name: Frontend Type Check
+1 -1
View File
@@ -130,7 +130,7 @@ jobs:
working-directory: frontend
run: |
npm audit --json > npm-audit-results.json || echo "vulnerabilities_found=true" >> $GITHUB_OUTPUT
npm audit --audit-level=moderate || true
npm audit --audit-level=high || true
- name: Upload audit results
if: always()