Skip to content

Add Socket Basics security scanning workflow - #2862

Open
kanwalpreetd wants to merge 1 commit into
stellar:mainfrom
kanwalpreetd:main
Open

kanwalpreetd wants to merge 1 commit into
stellar:mainfrom
kanwalpreetd:main

Conversation

@kanwalpreetd

@kanwalpreetd kanwalpreetd commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

@kanwalpreetd
kanwalpreetd force-pushed the main branch 6 times, most recently from 6fdd801 to a6a9b4d Compare September 26, 2026 01:30
@kanwalpreetd
kanwalpreetd marked this pull request as ready for review September 28, 2026 12:41
Copilot AI lite review requested due to automatic review settings September 28, 2026 12:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Address the workflow credential exposure, incomplete-scan success path, and overly broad secret-scan exclusions.

Review effort: Lite
Findings: 2 High severity · 1 Medium severity

Open (3)
What changed in this PR

Adds a scheduled and manually triggered Socket Basics security-scanning workflow for SAST, secret detection, and Dockerfile checks.

Changes:

  • Adds Socket Basics scanner configuration and exclusions.
  • Adds Trivy and Semgrep ignore rules.
  • Adds a pinned Docker-based GitHub Actions workflow.
File Summary
.trivyignore Configures Dockerfile scan exclusions.
.socket-basics.json Configures scanners and exclusions; broad exclusions may hide secrets.
.semgrepignore Defines SAST path exclusions.
.github/​workflows/​socket-basics.yml Runs the security scan; checkout credentials must not be exposed, and incomplete scans must fail nonzero.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/socket-basics.yml
Comment thread .github/workflows/socket-basics.yml Outdated
Comment thread .socket-basics.json
"dockerfiles": "Dockerfile",
"socket_tier_1_enabled": false,
"trivy_vuln_enabled": false,
"trufflehog_exclude_dir": "node_modules,dist,build,.git,__fixtures__,__mocks__,__snapshots__,__tests__,acceptance-test,acceptance-tests,acceptance_test,acceptance_tests,benches,browser-test,browser-tests,browser_test,browser_tests,e2e,e2e-test,e2e-tests,e2e_test,e2e_tests,example,examples,fixtures,functional-test,functional-tests,functional_test,functional_tests,integration-test,integration-tests,integration_test,integration_tests,integrationtest,integrationtests,mock,mock-dapp,mocks,perf-test,perf-tests,perf_test,perf_tests,performance-test,performance-tests,performance_test,performance_tests,regression-test,regression-tests,regression_test,regression_tests,smoke-test,smoke-tests,smoke_test,smoke_tests,spec,specs,test,test-data,test-fixtures,testFixtures,testdata,testfixtures,tests,unit-test,unit-tests,unit_test,unit_tests,*.test.js,*.test.jsx,*.test.ts,*.test.tsx,*.test.mjs,*.spec.js,*.spec.jsx,*.spec.ts,*.spec.tsx,*_test.go,*_test.py,*_test.rb,*_test.exs,test_*.py,*Test.java,*Tests.java,*Test.kt,*Tests.kt,*Test.scala,*Test.cs,*Tests.cs,tests.rs,test.rs,yarn.lock,package-lock.json,pnpm-lock.yaml,Cargo.lock,go.sum,poetry.lock,Gemfile.lock,composer.lock,docs/platforms/stellar-disbursement-platform/api-reference/log-in.StatusCodes.json,docs/platforms/stellar-disbursement-platform/api-reference/refresh-token.StatusCodes.json,openapi/stellar-disbursement-platform/bundled.yaml,openapi/stellar-disbursement-platform/main.yaml,docs/platforms/anchor-platform/api-reference/callbacks/put-customer.api.mdx,docs/data/apis/horizon/api-reference/list-all-operations.api.mdx,docusaurus.config.ts"

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Disable checkout credential persistence before mounting the repository into the third-party scanner container.

Review effort: Lite
Findings: 1 High severity · 1 Medium severity

Open (2)
Resolved since last review (1)

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Address the checkout credential exposure and narrow secret-scan exclusions.

Review effort: Lite
Findings: 1 High severity · 1 Medium severity

Open (2)

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Address the three moderate security-scanning workflow and configuration issues before approval.

Review effort: Lite
Findings: 1 High severity · 2 Medium severity

Open (3)

Comment thread .socket-basics.json
"dockerfiles": "Dockerfile",
"socket_tier_1_enabled": false,
"trivy_vuln_enabled": false,
"trufflehog_exclude_dir": "node_modules,dist,build,.git,__fixtures__,__mocks__,__snapshots__,__tests__,acceptance-test,acceptance-tests,acceptance_test,acceptance_tests,benches,browser-test,browser-tests,browser_test,browser_tests,e2e,e2e-test,e2e-tests,e2e_test,e2e_tests,example,examples,fixtures,functional-test,functional-tests,functional_test,functional_tests,integration-test,integration-tests,integration_test,integration_tests,integrationtest,integrationtests,mock,mock-dapp,mocks,perf-test,perf-tests,perf_test,perf_tests,performance-test,performance-tests,performance_test,performance_tests,regression-test,regression-tests,regression_test,regression_tests,smoke-test,smoke-tests,smoke_test,smoke_tests,spec,specs,test,test-data,test-fixtures,testFixtures,testdata,testfixtures,tests,unit-test,unit-tests,unit_test,unit_tests,*.test.js,*.test.jsx,*.test.ts,*.test.tsx,*.test.mjs,*.spec.js,*.spec.jsx,*.spec.ts,*.spec.tsx,*_test.go,*_test.py,*_test.rb,*_test.exs,test_*.py,*Test.java,*Tests.java,*Test.kt,*Tests.kt,*Test.scala,*Test.cs,*Tests.cs,tests.rs,test.rs,yarn.lock,package-lock.json,pnpm-lock.yaml,Cargo.lock,go.sum,poetry.lock,Gemfile.lock,composer.lock,docs/platforms/stellar-disbursement-platform/api-reference/log-in.StatusCodes.json,docs/platforms/stellar-disbursement-platform/api-reference/refresh-token.StatusCodes.json,openapi/stellar-disbursement-platform/bundled.yaml,openapi/stellar-disbursement-platform/main.yaml,docs/platforms/anchor-platform/api-reference/callbacks/put-customer.api.mdx,docs/data/apis/horizon/api-reference/list-all-operations.api.mdx,docusaurus.config.ts"

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Address stale artifact handling, fail-closed submission status, and overly broad example-directory secret exclusions.

Review effort: Lite
Findings: 1 High severity · 2 Medium severity

Open (3)
Resolved since last review (1)

Comment thread .github/workflows/socket-basics.yml Outdated
Copilot AI lite review requested due to automatic review settings September 29, 2026 22:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Copilot AI lite review requested due to automatic review settings September 29, 2026 23:19

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Update the workflow’s checkout action from v6.0.3 to the repository-standard pinned v7.0.1.

Review effort: Lite
Findings: 1 High severity · 2 Medium severity

Open (3)

Runs SAST through OpenGrep, secret scanning through TruffleHog, and
Dockerfile misconfiguration scanning through Trivy, submitting results
to Socket.dev.

  .github/workflows/socket-basics.yml  scheduled weekly + manual dispatch
  .socket-basics.json                  scanner configuration
  .semgrepignore                       SAST path exclusions
  .trivyignore                         Dockerfile lint rules with no
                                       security dimension (only present
                                       where the repo has a Dockerfile)

Separate from socket-scan.yml, which covers dependency CVEs and Tier 1
reachability.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Narrow the secret-scanner exclusions so examples, fixtures, tests, and docusaurus.config.ts remain covered.

Review effort: Lite
Findings: 2 Medium severity

Open (2)
Resolved since last review (1)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants