maziggy
b7cc68122b
Both workflows now parse package-lock.json directly instead of trusting npm ls. The lockfile correctly marks minimatch as dev: true and doesn't contain npm/tar at all —
...
so all three npm-internal packages will be filtered out regardless of which npm version CI uses.
2026-02-20 19:31:41 +01:00
maziggy
63b668f0ed
Updated CI
2026-02-20 19:10:26 +01:00
maziggy
6ab48fa338
Updated CI
2026-02-20 18:28:34 +01:00
maziggy
fbf676a77f
Updated CI
2026-02-18 18:08:07 +01:00
maziggy
c0948f7868
Updated CI
2026-02-18 17:47:29 +01:00
maziggy
2bfb9d22c5
Updated CI
2026-02-18 17:26:09 +01:00
maziggy
46ba5ff417
Fix Bandit detection and update Trivy to v0.69.1
...
- Fix defusedxml import style in print_queue.py to be recognized by Bandit
(use `import defusedxml.ElementTree as ET` not `from defusedxml import`)
- Update Trivy scanner version from 0.65.0 to 0.69.1
2026-02-05 17:50:16 +01:00
maziggy
fc4f565eba
Update Trivy scanner to v0.69.1
...
Pin the latest Trivy scanner version for improved vulnerability detection.
2026-02-05 17:33:51 +01:00
maziggy
7841237d4e
Fixed Trivy workflow
2026-02-05 14:05:29 +01:00
maziggy
45e08b023a
Updated CI
2026-02-05 12:34:06 +01:00
maziggy
c01839b2ce
Added Bandit and Trivy to CI
2026-02-05 12:18:00 +01:00
maziggy
51df60cb91
Fixed CI
2026-01-26 15:53:54 +01:00
maziggy
580225a38d
Add security scanning to CI pipeline
...
- Add pip-audit check to PR workflow (non-blocking warning)
- Add npm audit check to PR workflow (non-blocking, high severity only)
- Create scheduled weekly security audit workflow that:
- Runs strict pip-audit and npm audit
- Creates/updates GitHub issues when vulnerabilities found
- Uploads audit results as artifacts
- Supports manual trigger via workflow_dispatch
2026-01-26 13:21:02 +01:00
maziggy
164d22f2bb
Add security scanning to CI pipeline
...
- Add pip-audit check to PR workflow (non-blocking warning)
- Add npm audit check to PR workflow (non-blocking warning)
- Create scheduled weekly security audit workflow that:
- Runs strict pip-audit and npm audit
- Creates/updates GitHub issues when vulnerabilities found
- Uploads audit results as artifacts
- Supports manual trigger via workflow_dispatch
2026-01-26 13:18:29 +01:00