maziggy
7c0eeed8d5
Both workflows now parse package-lock.json directly instead of trusting npm ls. The lockfile correctly marks minimatch as dev: true and doesn't contain npm/tar at all —
...
so all three npm-internal packages will be filtered out regardless of which npm version CI uses.
2026-02-20 19:32:07 +01:00
maziggy
5d48ab88f0
Updated CI
2026-02-20 19:10:56 +01:00
maziggy
2c0d1c2fe6
Updated CI
2026-02-20 18:29:50 +01:00
maziggy
036ae16ad5
Updated CI
2026-02-18 18:08:23 +01:00
maziggy
a361671952
Updated CI
2026-02-18 17:47:49 +01:00
dependabot[bot]
971aa960a8
build(deps): bump aquasecurity/trivy-action
...
Bumps the github_actions group with 1 update in the /.github/workflows directory: [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action ).
Updates `aquasecurity/trivy-action` from 0.33.1 to 0.34.0
- [Release notes](https://github.com/aquasecurity/trivy-action/releases )
- [Commits](https://github.com/aquasecurity/trivy-action/compare/0.33.1...0.34.0 )
---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
dependency-version: 0.34.0
dependency-type: direct:production
dependency-group: github_actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-18 16:31:35 +00:00
maziggy
10cae700f4
Updated CI
2026-02-18 17:27:37 +01:00
dependabot[bot]
1d0875ee83
build(deps): bump aquasecurity/trivy-action
...
Bumps the github_actions group with 1 update in the /.github/workflows directory: [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action ).
Updates `aquasecurity/trivy-action` from 0.33.1 to 0.34.0
- [Release notes](https://github.com/aquasecurity/trivy-action/releases )
- [Commits](https://github.com/aquasecurity/trivy-action/compare/0.33.1...0.34.0 )
---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
dependency-version: 0.34.0
dependency-type: direct:production
dependency-group: github_actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-18 15:56:12 +00:00
maziggy
46ba5ff417
Fix Bandit detection and update Trivy to v0.69.1
...
- Fix defusedxml import style in print_queue.py to be recognized by Bandit
(use `import defusedxml.ElementTree as ET` not `from defusedxml import`)
- Update Trivy scanner version from 0.65.0 to 0.69.1
2026-02-05 17:50:16 +01:00
maziggy
fc4f565eba
Update Trivy scanner to v0.69.1
...
Pin the latest Trivy scanner version for improved vulnerability detection.
2026-02-05 17:33:51 +01:00
maziggy
7841237d4e
Fixed Trivy workflow
2026-02-05 14:05:29 +01:00
maziggy
45e08b023a
Updated CI
2026-02-05 12:34:06 +01:00
maziggy
c01839b2ce
Added Bandit and Trivy to CI
2026-02-05 12:18:00 +01:00
maziggy
51df60cb91
Fixed CI
2026-01-26 15:53:54 +01:00
maziggy
580225a38d
Add security scanning to CI pipeline
...
- Add pip-audit check to PR workflow (non-blocking warning)
- Add npm audit check to PR workflow (non-blocking, high severity only)
- Create scheduled weekly security audit workflow that:
- Runs strict pip-audit and npm audit
- Creates/updates GitHub issues when vulnerabilities found
- Uploads audit results as artifacts
- Supports manual trigger via workflow_dispatch
2026-01-26 13:21:02 +01:00
maziggy
164d22f2bb
Add security scanning to CI pipeline
...
- Add pip-audit check to PR workflow (non-blocking warning)
- Add npm audit check to PR workflow (non-blocking warning)
- Create scheduled weekly security audit workflow that:
- Runs strict pip-audit and npm audit
- Creates/updates GitHub issues when vulnerabilities found
- Uploads audit results as artifacts
- Supports manual trigger via workflow_dispatch
2026-01-26 13:18:29 +01:00