Repository navigation
Add Socket Basics security scanning workflow - #2729
kanwalpreetd wants to merge 3 commits into
Conversation
60458b0 to
8a7eeb6
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Fix the incomplete-scan exit handling and align the advertised Trivy coverage with the configured scans.
Review effort: Lite
Findings: 1
What changed in this PR
Adds scheduled/manual Socket Basics security scanning for SAST, secrets, and repository analysis.
Changes:
- Adds Socket Basics configuration and exclusions.
- Adds Semgrep exclusion patterns.
- Adds a pinned Docker-based GitHub Actions workflow.
| File | Summary |
|---|---|
.socket-basics.json |
Scanner settings and exclusions |
.semgrepignore |
SAST path exclusions |
.github/workflows/socket-basics.yml |
Scheduled/manual scan execution |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Critical production-code scan exclusions and workflow failure handling can allow security issues to pass unnoticed.
Review effort: Lite
Findings: 5
Open (6)
Broad soroban-test exclusion skips production SAST coverage · New File-wide secret suppressions hide real credentials · New TruffleHog exclusions hide secrets in production files · New Avoid globally disabling rust-panic-in-production Untrusted scanner output can inject GitHub Actions commands Handle partial scanner failures and distinguish findings from operational errors
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Narrow or remove the broad Rust rule disables and production-file TruffleHog exclusions.
Review effort: Lite
Findings: 5
Open (6)
TruffleHog exclusions hide secrets in production files File-wide secret suppressions hide real credentials Broad soroban-test exclusion skips production SAST coverage Avoid globally disabling rust-panic-in-production Untrusted scanner output can inject GitHub Actions commands Handle partial scanner failures and distinguish findings from operational errors
5cedd5a to
06431ca
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Blanket secret-scanning exclusions allow credentials accidentally committed in tests, fixtures, or examples to go undetected.
Review effort: Lite
Findings: 5
Open (6)
TruffleHog exclusions hide secrets in production files File-wide secret suppressions hide real credentials Broad soroban-test exclusion skips production SAST coverage Avoid globally disabling rust-panic-in-production Untrusted scanner output can inject GitHub Actions commands Avoid excluding test and fixture paths from secret scanning · New
Resolved since last review (1)
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Secret-scanning exclusions are overly broad and may hide credentials in production, test, and example files.
Review effort: Lite
Findings: 5
Open (6)
TruffleHog exclusions hide secrets in production files File-wide secret suppressions hide real credentials Broad soroban-test exclusion skips production SAST coverage Avoid globally disabling rust-panic-in-production Untrusted scanner output can inject GitHub Actions commands Avoid excluding test and fixture paths from secret scanning
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Critical scanner exclusions can hide secrets and vulnerabilities and must be narrowed.
Review effort: Lite
Findings: 7
Open (8)
Keep environment- and SQL-injection rules enabled globally · New Avoid globally excluding credential-bearing source files from secret scans · New TruffleHog exclusions hide secrets in production files File-wide secret suppressions hide real credentials Broad soroban-test exclusion skips production SAST coverage Avoid globally disabling rust-panic-in-production Untrusted scanner output can inject GitHub Actions commands Avoid excluding test and fixture paths from secret scanning
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Narrow the TruffleHog exclusions in .socket-basics.json to preserve coverage of future credentials.
Review effort: Lite
Findings: 7
Open (8)
Avoid globally excluding credential-bearing source files from secret scans Keep environment- and SQL-injection rules enabled globally TruffleHog exclusions hide secrets in production files File-wide secret suppressions hide real credentials Broad soroban-test exclusion skips production SAST coverage Avoid globally disabling rust-panic-in-production Untrusted scanner output can inject GitHub Actions commands Avoid excluding test and fixture paths from secret scanning
Runs SAST through OpenGrep, secret scanning through TruffleHog, and
Dockerfile misconfiguration scanning through Trivy, submitting results
to Socket.dev.
.github/workflows/socket-basics.yml scheduled weekly + manual dispatch
.socket-basics.json scanner configuration
.semgrepignore SAST path exclusions
.trivyignore Dockerfile lint rules with no
security dimension (only present
where the repo has a Dockerfile)
Separate from socket-scan.yml, which covers dependency CVEs and Tier 1
reachability.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
No unresolved blocking issues were identified.
Review effort: Lite
Findings: None
Resolved since last review (8)
Avoid globally excluding credential-bearing source files from secret scans Keep environment- and SQL-injection rules enabled globally TruffleHog exclusions hide secrets in production files File-wide secret suppressions hide real credentials Broad soroban-test exclusion skips production SAST coverage Avoid globally disabling rust-panic-in-production Untrusted scanner output can inject GitHub Actions commands Avoid excluding test and fixture paths from secret scanning


More info: https://stellarorg.atlassian.net/wiki/spaces/SCRT/pages/5901680652/Socket+Basics+Integration+Guide