Commit Graph
19 Commits
Author SHA1 Message Date
maziggy a699270c7a Changed pipeline 2026-03-26 13:53:12 +01:00
maziggy deecc8b7dc Updated .github/workflows/security.yml 2026-03-20 11:07:08 +01:00
maziggy c2cf041af2 Update CI Node.js version from 20 to 22 LTS
Node 20 is being deprecated on GitHub Actions runners.
  Bump to Node 22 (Active LTS) in ci.yml and security.yml.
2026-03-13 15:34:22 +01:00
maziggy 7c0eeed8d5 Both workflows now parse package-lock.json directly instead of trusting npm ls. The lockfile correctly marks minimatch as dev: true and doesn't contain npm/tar at all —
so all three npm-internal packages will be filtered out regardless of which npm version CI uses.
2026-02-20 19:32:07 +01:00
maziggy 5d48ab88f0 Updated CI 2026-02-20 19:10:56 +01:00
maziggy 2c0d1c2fe6 Updated CI 2026-02-20 18:29:50 +01:00
maziggy 036ae16ad5 Updated CI 2026-02-18 18:08:23 +01:00
maziggy a361671952 Updated CI 2026-02-18 17:47:49 +01:00
dependabot[bot] 971aa960a8 build(deps): bump aquasecurity/trivy-action
Bumps the github_actions group with 1 update in the /.github/workflows directory: [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action).


Updates `aquasecurity/trivy-action` from 0.33.1 to 0.34.0
- [Release notes](https://github.com/aquasecurity/trivy-action/releases)
- [Commits](https://github.com/aquasecurity/trivy-action/compare/0.33.1...0.34.0)

---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
  dependency-version: 0.34.0
  dependency-type: direct:production
  dependency-group: github_actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-02-18 16:31:35 +00:00
maziggy 10cae700f4 Updated CI 2026-02-18 17:27:37 +01:00
dependabot[bot] 1d0875ee83 build(deps): bump aquasecurity/trivy-action
Bumps the github_actions group with 1 update in the /.github/workflows directory: [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action).


Updates `aquasecurity/trivy-action` from 0.33.1 to 0.34.0
- [Release notes](https://github.com/aquasecurity/trivy-action/releases)
- [Commits](https://github.com/aquasecurity/trivy-action/compare/0.33.1...0.34.0)

---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
  dependency-version: 0.34.0
  dependency-type: direct:production
  dependency-group: github_actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-02-18 15:56:12 +00:00
maziggy 46ba5ff417 Fix Bandit detection and update Trivy to v0.69.1
- Fix defusedxml import style in print_queue.py to be recognized by Bandit
  (use `import defusedxml.ElementTree as ET` not `from defusedxml import`)
- Update Trivy scanner version from 0.65.0 to 0.69.1
2026-02-05 17:50:16 +01:00
maziggy fc4f565eba Update Trivy scanner to v0.69.1
Pin the latest Trivy scanner version for improved vulnerability detection.
2026-02-05 17:33:51 +01:00
maziggy 7841237d4e Fixed Trivy workflow 2026-02-05 14:05:29 +01:00
maziggy 45e08b023a Updated CI 2026-02-05 12:34:06 +01:00
maziggy c01839b2ce Added Bandit and Trivy to CI 2026-02-05 12:18:00 +01:00
maziggy 51df60cb91 Fixed CI 2026-01-26 15:53:54 +01:00
maziggy 580225a38d Add security scanning to CI pipeline
- Add pip-audit check to PR workflow (non-blocking warning)
- Add npm audit check to PR workflow (non-blocking, high severity only)
- Create scheduled weekly security audit workflow that:
  - Runs strict pip-audit and npm audit
  - Creates/updates GitHub issues when vulnerabilities found
  - Uploads audit results as artifacts
  - Supports manual trigger via workflow_dispatch
2026-01-26 13:21:02 +01:00
maziggy 164d22f2bb Add security scanning to CI pipeline
- Add pip-audit check to PR workflow (non-blocking warning)
- Add npm audit check to PR workflow (non-blocking warning)
- Create scheduled weekly security audit workflow that:
  - Runs strict pip-audit and npm audit
  - Creates/updates GitHub issues when vulnerabilities found
  - Uploads audit results as artifacts
  - Supports manual trigger via workflow_dispatch
2026-01-26 13:18:29 +01:00