mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 03:01:21 +02:00
Add security scanning to CI pipeline
- Add pip-audit check to PR workflow (non-blocking warning) - Add npm audit check to PR workflow (non-blocking, high severity only) - Create scheduled weekly security audit workflow that: - Runs strict pip-audit and npm audit - Creates/updates GitHub issues when vulnerabilities found - Uploads audit results as artifacts - Supports manual trigger via workflow_dispatch
This commit is contained in:
@@ -146,7 +146,7 @@ jobs:
|
||||
|
||||
- name: Run npm audit
|
||||
working-directory: frontend
|
||||
run: npm audit --audit-level=moderate
|
||||
run: npm audit --audit-level=high
|
||||
|
||||
frontend-typecheck:
|
||||
name: Frontend Type Check
|
||||
|
||||
@@ -130,7 +130,7 @@ jobs:
|
||||
working-directory: frontend
|
||||
run: |
|
||||
npm audit --json > npm-audit-results.json || echo "vulnerabilities_found=true" >> $GITHUB_OUTPUT
|
||||
npm audit --audit-level=moderate || true
|
||||
npm audit --audit-level=high || true
|
||||
|
||||
- name: Upload audit results
|
||||
if: always()
|
||||
|
||||
Reference in New Issue
Block a user