Skip to content

Add Socket Basics security scanning workflow - #2729

Open
kanwalpreetd wants to merge 3 commits into
stellar:mainfrom
kanwalpreetd:main
Open

kanwalpreetd wants to merge 3 commits into
stellar:mainfrom
kanwalpreetd:main

Conversation

@kanwalpreetd

@kanwalpreetd kanwalpreetd commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

@github-project-automation github-project-automation Bot moved this to Backlog (Not Ready) in DevX Sep 17, 2026
@kanwalpreetd
kanwalpreetd force-pushed the main branch 5 times, most recently from 60458b0 to 8a7eeb6 Compare September 26, 2026 01:30
@kanwalpreetd
kanwalpreetd marked this pull request as ready for review September 28, 2026 12:40
Copilot AI lite review requested due to automatic review settings September 28, 2026 12:40

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Fix the incomplete-scan exit handling and align the advertised Trivy coverage with the configured scans.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Adds scheduled/manual Socket Basics security scanning for SAST, secrets, and repository analysis.

Changes:

  • Adds Socket Basics configuration and exclusions.
  • Adds Semgrep exclusion patterns.
  • Adds a pinned Docker-based GitHub Actions workflow.
File Summary
.socket-basics.json Scanner settings and exclusions
.semgrepignore SAST path exclusions
.github/​workflows/​socket-basics.yml Scheduled/manual scan execution

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/socket-basics.yml Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Address the workflow command-injection risk and narrow or correct the scanner exclusions and disabled checks.

Review effort: Lite
Findings: 1 High severity

Open (1)
Resolved since last review (1)

Comment thread .github/workflows/socket-basics.yml Outdated
Copilot AI review requested due to automatic review settings September 29, 2026 07:30

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved critical and moderate findings affect scan coverage, authentication, failure handling, and timeout behavior.

Review effort: Lite
Findings: 2 High severity · 1 Medium severity

Open (3)

Comment thread .socket-basics.json
Comment thread .github/workflows/socket-basics.yml Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Critical production-code scan exclusions and workflow failure handling can allow security issues to pass unnoticed.

Review effort: Lite
Findings: 5 High severity · 1 Medium severity

Open (6)

Comment thread .semgrepignore Outdated
Comment thread .socket-basics.json
Comment thread .socket-basics.json Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kanwalpreetd
kanwalpreetd force-pushed the main branch 2 times, most recently from 5cedd5a to 06431ca Compare September 29, 2026 22:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread .socket-basics.json Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot AI lite review requested due to automatic review settings October 2, 2026 01:51

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread .socket-basics.json
Comment thread .socket-basics.json Outdated
Copilot AI lite review requested due to automatic review settings October 2, 2026 02:26

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Runs SAST through OpenGrep, secret scanning through TruffleHog, and
Dockerfile misconfiguration scanning through Trivy, submitting results
to Socket.dev.

  .github/workflows/socket-basics.yml  scheduled weekly + manual dispatch
  .socket-basics.json                  scanner configuration
  .semgrepignore                       SAST path exclusions
  .trivyignore                         Dockerfile lint rules with no
                                       security dimension (only present
                                       where the repo has a Dockerfile)

Separate from socket-scan.yml, which covers dependency CVEs and Tier 1
reachability.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings October 2, 2026 04:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kanwalpreetd
kanwalpreetd requested a review from fnando October 2, 2026 20:01
Copilot AI lite review requested due to automatic review settings October 2, 2026 21:57

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Narrow the TruffleHog exclusions so production source files remain covered.

Review effort: Lite
Findings: None

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Backlog (Not Ready)

Development

Successfully merging this pull request may close these issues.

3 participants