From 580225a38d15a474853ff387aef93e0db3f9aa95 Mon Sep 17 00:00:00 2001 From: maziggy Date: Mon, 26 Jan 2026 13:20:33 +0100 Subject: [PATCH] Add security scanning to CI pipeline - Add pip-audit check to PR workflow (non-blocking warning) - Add npm audit check to PR workflow (non-blocking, high severity only) - Create scheduled weekly security audit workflow that: - Runs strict pip-audit and npm audit - Creates/updates GitHub issues when vulnerabilities found - Uploads audit results as artifacts - Supports manual trigger via workflow_dispatch --- .github/workflows/ci.yml | 2 +- .github/workflows/security.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index e9f862b8c..9d07aecd3 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -146,7 +146,7 @@ jobs: - name: Run npm audit working-directory: frontend - run: npm audit --audit-level=moderate + run: npm audit --audit-level=high frontend-typecheck: name: Frontend Type Check diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index ae9f89b4a..020103e15 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -130,7 +130,7 @@ jobs: working-directory: frontend run: | npm audit --json > npm-audit-results.json || echo "vulnerabilities_found=true" >> $GITHUB_OUTPUT - npm audit --audit-level=moderate || true + npm audit --audit-level=high || true - name: Upload audit results if: always()