-
Notifications
You must be signed in to change notification settings - Fork 0
Add the scan-community-node reusable workflow #3
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,32 @@ | ||
| name: 'CI: Scan Community Node' | ||
|
|
||
| # Exercises the scan-community-node reusable workflow on pull requests that | ||
| # touch it: once against a published package and once against this repository. | ||
|
|
||
| on: | ||
| pull_request: | ||
| paths: | ||
| - '.github/workflows/scan-community-node*.yml' | ||
| - '.github/workflows/ci-scan-community-node.yml' | ||
| - 'scan-community-node/**' | ||
| workflow_dispatch: | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| concurrency: | ||
| group: ${{ github.workflow }}-${{ github.ref }} | ||
| cancel-in-progress: true | ||
|
|
||
| jobs: | ||
| # A consumer that only scans packages needs nothing beyond contents: read. | ||
| package: | ||
| uses: $/.github/workflows/scan-community-node.yml | ||
| with: | ||
| package: n8n-nodes-evolution-api | ||
| version: 1.0.4 | ||
|
|
||
| # Scans this repository. The upload stays off: Semgrep and Scorecard do not | ||
| # know `$/` and would report every self-reference here as an unpinned action. | ||
| workspace: | ||
| uses: $/.github/workflows/scan-community-node.yml |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,77 @@ | ||
| name: 'Scan Community Node (CVE Lite CLI)' | ||
|
|
||
| on: | ||
| workflow_call: | ||
| inputs: | ||
| package: | ||
| description: 'npm package name to scan (e.g. express or @scope/pkg). Leave empty to verify the local package.json.' | ||
| required: false | ||
| type: string | ||
| version: | ||
| description: 'Optional package version to scan (e.g. 4.18.2).' | ||
| required: false | ||
| default: 'latest' | ||
| type: string | ||
| upload-sarif: | ||
| description: 'Whether to upload SARIF reports to GitHub code scanning.' | ||
| required: false | ||
| default: false | ||
| type: boolean | ||
|
|
||
| env: | ||
| PACKAGE_SPEC: ${{ inputs.package }}@${{ inputs.version }} | ||
|
|
||
| jobs: | ||
| cve-lite: | ||
| name: CVE Lite CLI | ||
| runs-on: ubuntu-latest | ||
|
|
||
| steps: | ||
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
|
|
||
| - uses: $/scan-community-node/actions/setup | ||
| with: | ||
| node: 'true' | ||
|
|
||
| - name: Prepare scan target | ||
| id: prep | ||
| env: | ||
| PACKAGE: ${{ inputs.package }} | ||
| run: | | ||
| # With a package name, scan the published npm tarball; otherwise scan this checkout. | ||
| if [ -n "$PACKAGE" ]; then | ||
| # Unpack outside the workspace so the caller's own files are never scanned. | ||
| DIR="$RUNNER_TEMP/cve-lite-target" | ||
| rm -rf "$DIR" && mkdir -p "$DIR" | ||
| # npm pack downloads <name>-<version>.tgz and prints that file name. | ||
| ARCHIVE="$(npm pack --silent "$PACKAGE_SPEC")" | ||
| # The tarball wraps everything in a package/ folder; strip that level. | ||
| tar -xzf "$ARCHIVE" -C "$DIR" --strip-components=1 | ||
| # Tarballs ship no lockfile; without one only pinned direct deps are scanned. | ||
| # --package-lock-only resolves the tree without downloading or running anything. | ||
| (cd "$DIR" && npm install --package-lock-only --ignore-scripts) | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. P2: Running npm inside the extracted, untrusted package tree lets the scanned (possibly malicious) package influence the scan: npm reads project-level Prompt for AI agentsThere was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. P2: Prompt for AI agents |
||
| # Hand the directory to the scan step as steps.prep.outputs.path. | ||
| echo "path=$DIR" >> "$GITHUB_OUTPUT" | ||
| else | ||
| echo "path=." >> "$GITHUB_OUTPUT" | ||
| fi | ||
|
|
||
| - name: Run CVE Lite CLI | ||
| uses: OWASP/cve-lite-cli@e444d847f67d5f2b07f38d66a8e61b9eeba8b18d # v1.37.0 | ||
| with: | ||
| path: ${{ steps.prep.outputs.path }} | ||
| version: 1.37.0 | ||
| sarif: true | ||
| output: security-report | ||
|
|
||
| - name: Write CVE Lite CLI summary | ||
| if: always() | ||
| uses: $/scan-community-node/actions/security-summary | ||
|
|
||
| - name: Upload CVE Lite CLI SARIF file to GitHub | ||
| if: always() | ||
| uses: $/scan-community-node/actions/upload-security-sarif | ||
| with: | ||
| category: cve-lite | ||
| package: ${{ inputs.package }} | ||
| upload: ${{ inputs.upload-sarif }} | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,72 @@ | ||
| name: 'Scan Community Node (Gitleaks)' | ||
|
|
||
| on: | ||
| workflow_call: | ||
| inputs: | ||
| package: | ||
| description: 'npm package name to scan (e.g. express or @scope/pkg). Leave empty to verify the local package.json.' | ||
| required: false | ||
| type: string | ||
| version: | ||
| description: 'Optional package version to scan (e.g. 4.18.2).' | ||
| required: false | ||
| default: 'latest' | ||
| type: string | ||
| upload-sarif: | ||
| description: 'Whether to upload SARIF reports to GitHub code scanning.' | ||
| required: false | ||
| default: false | ||
| type: boolean | ||
|
|
||
| env: | ||
| PACKAGE_SPEC: ${{ inputs.package }}@${{ inputs.version }} | ||
| GITLEAKS_VERSION: 8.30.1 | ||
| # SHA-256 of gitleaks_<version>_linux_x64.tar.gz; update when bumping the version. | ||
| GITLEAKS_SHA256: 551f6fc83ea457d62a0d98237cbad105af8d557003051f41f3e7ca7b3f2470eb | ||
|
|
||
| jobs: | ||
| gitleaks: | ||
| name: Gitleaks | ||
| runs-on: ubuntu-latest | ||
|
|
||
| steps: | ||
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
|
|
||
| - uses: $/scan-community-node/actions/setup | ||
| with: | ||
| node: 'true' | ||
|
|
||
| - name: Install Gitleaks | ||
| run: | | ||
| curl -sSfL "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" -o gitleaks.tar.gz | ||
| echo "${GITLEAKS_SHA256} gitleaks.tar.gz" | sha256sum -c - | ||
| tar -xzf gitleaks.tar.gz gitleaks | ||
| sudo install -m 0755 gitleaks /usr/local/bin/gitleaks | ||
| rm -f gitleaks gitleaks.tar.gz | ||
|
|
||
| - name: Run Gitleaks | ||
| continue-on-error: true | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. P2: Prompt for AI agents |
||
| env: | ||
| PACKAGE: ${{ inputs.package }} | ||
| run: | | ||
| if [ -n "$PACKAGE" ]; then | ||
| DIR="$RUNNER_TEMP/gitleaks-target" | ||
| rm -rf "$DIR" && mkdir -p "$DIR" | ||
| npm pack "$PACKAGE_SPEC" | ||
| tar -xzf ./*.tgz -C "$DIR" --strip-components=1 | ||
| TARGET="$DIR" | ||
| else | ||
| TARGET="." | ||
| fi | ||
| gitleaks dir "$TARGET" --report-format sarif --report-path security-report/gitleaks.sarif | ||
|
|
||
| - name: Write Gitleaks summary | ||
| if: always() | ||
| uses: $/scan-community-node/actions/security-summary | ||
|
|
||
| - name: Upload Gitleaks SARIF file to GitHub | ||
| uses: $/scan-community-node/actions/upload-security-sarif | ||
| with: | ||
| category: gitleaks | ||
| package: ${{ inputs.package }} | ||
| upload: ${{ inputs.upload-sarif }} | ||
| Original file line number | Diff line number | Diff line change | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,68 @@ | ||||||||||||
| name: 'Scan Community Node (GuardDog)' | ||||||||||||
|
|
||||||||||||
| on: | ||||||||||||
| workflow_call: | ||||||||||||
| inputs: | ||||||||||||
| package: | ||||||||||||
| description: 'npm package name to scan (e.g. express or @scope/pkg). Leave empty to verify the local package.json.' | ||||||||||||
| required: false | ||||||||||||
| type: string | ||||||||||||
| version: | ||||||||||||
| description: 'Optional package version to scan (e.g. 4.18.2).' | ||||||||||||
| required: false | ||||||||||||
| default: 'latest' | ||||||||||||
| type: string | ||||||||||||
| sandbox: | ||||||||||||
| description: 'Whether GuardDog should run inside its kernel-level sandbox.' | ||||||||||||
| required: false | ||||||||||||
| default: true | ||||||||||||
| type: boolean | ||||||||||||
| upload-sarif: | ||||||||||||
| description: 'Whether to upload SARIF reports to GitHub code scanning.' | ||||||||||||
| required: false | ||||||||||||
| default: false | ||||||||||||
| type: boolean | ||||||||||||
|
|
||||||||||||
| jobs: | ||||||||||||
| guarddog: | ||||||||||||
| name: GuardDog | ||||||||||||
| runs-on: ubuntu-latest | ||||||||||||
|
|
||||||||||||
| steps: | ||||||||||||
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||||||||||||
|
|
||||||||||||
| - uses: $/scan-community-node/actions/setup | ||||||||||||
|
|
||||||||||||
| - name: Run GuardDog | ||||||||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. P2: This step has no Prompt for AI agents |
||||||||||||
| env: | ||||||||||||
| PACKAGE: ${{ inputs.package }} | ||||||||||||
| VERSION: ${{ inputs.version }} | ||||||||||||
| SANDBOX: ${{ inputs.sandbox }} | ||||||||||||
| run: | | ||||||||||||
| # pipefail so a GuardDog failure isn't masked by tee's exit code. | ||||||||||||
| set -o pipefail | ||||||||||||
| SANDBOX_FLAG="" | ||||||||||||
| if [ "$SANDBOX" = "false" ]; then | ||||||||||||
| SANDBOX_FLAG="--no-sandbox" | ||||||||||||
| fi | ||||||||||||
| if [ -n "$PACKAGE" ]; then | ||||||||||||
| # GuardDog scan can't emit SARIF, so keep its native report. | ||||||||||||
| if [ -n "$VERSION" ] && [ "$VERSION" != "latest" ]; then | ||||||||||||
| uvx guarddog npm scan $SANDBOX_FLAG "$PACKAGE" --version "$VERSION" | tee security-report/guarddog.txt | ||||||||||||
| else | ||||||||||||
| uvx guarddog npm scan $SANDBOX_FLAG "$PACKAGE" | tee security-report/guarddog.txt | ||||||||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. P2: Prompt for AI agents |
||||||||||||
| fi | ||||||||||||
| else | ||||||||||||
| uvx guarddog npm verify $SANDBOX_FLAG --output-format sarif package.json > security-report/guarddog.sarif | ||||||||||||
| fi | ||||||||||||
|
|
||||||||||||
| - name: Write GuardDog summary | ||||||||||||
| if: always() | ||||||||||||
| uses: $/scan-community-node/actions/security-summary | ||||||||||||
|
|
||||||||||||
| - name: Upload SARIF file to GitHub | ||||||||||||
| uses: $/scan-community-node/actions/upload-security-sarif | ||||||||||||
|
Comment on lines
+63
to
+64
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. P2: This upload step has no Prompt for AI agents
Suggested change
|
||||||||||||
| with: | ||||||||||||
| category: guarddog-builtin | ||||||||||||
| package: ${{ inputs.package }} | ||||||||||||
| upload: ${{ inputs.upload-sarif }} | ||||||||||||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
P3: The
packageinput description still reads 'Action to release', but the newscan-community-nodeoption is a reusable workflow (noscan-community-node/action.ymlexists; it is released via.github/workflows/scan-community-node.yml). Update the description to something like 'Package to release' so the dispatch form matches the available options.Prompt for AI agents