mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-10-08 23:21:58 +02:00
Add security scanning to CI pipeline
- Add pip-audit check to PR workflow (non-blocking warning) - Add npm audit check to PR workflow (non-blocking, high severity only) - Create scheduled weekly security audit workflow that: - Runs strict pip-audit and npm audit - Creates/updates GitHub issues when vulnerabilities found - Uploads audit results as artifacts - Supports manual trigger via workflow_dispatch
This commit is contained in:
@@ -130,7 +130,7 @@ jobs:
|
||||
working-directory: frontend
|
||||
run: |
|
||||
npm audit --json > npm-audit-results.json || echo "vulnerabilities_found=true" >> $GITHUB_OUTPUT
|
||||
npm audit --audit-level=moderate || true
|
||||
npm audit --audit-level=high || true
|
||||
|
||||
- name: Upload audit results
|
||||
if: always()
|
||||
|
||||
Reference in New Issue
Block a user