Skip to content

Add Socket Basics security scanning workflow - #2729

Open
kanwalpreetd wants to merge 1 commit into
stellar:mainfrom
kanwalpreetd:main
Open

kanwalpreetd wants to merge 1 commit into
stellar:mainfrom
kanwalpreetd:main

Conversation

@kanwalpreetd

@kanwalpreetd kanwalpreetd commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

@github-project-automation github-project-automation Bot moved this to Backlog (Not Ready) in DevX Sep 17, 2026
@kanwalpreetd
kanwalpreetd force-pushed the main branch 4 times, most recently from dcab412 to 60458b0 Compare September 26, 2026 00:10
Runs SAST through OpenGrep, secret scanning through TruffleHog, and
Dockerfile misconfiguration scanning through Trivy, submitting results
to Socket.dev.

  .github/workflows/socket-basics.yml  scheduled weekly + manual dispatch
  .socket-basics.json                  scanner configuration
  .semgrepignore                       SAST path exclusions
  .trivyignore                         Dockerfile lint rules with no
                                       security dimension (only present
                                       where the repo has a Dockerfile)

Separate from socket-scan.yml, which covers dependency CVEs and Tier 1
reachability.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@kanwalpreetd
kanwalpreetd marked this pull request as ready for review September 28, 2026 12:40
Copilot AI lite review requested due to automatic review settings September 28, 2026 12:40

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Fix the incomplete-scan exit handling and align the advertised Trivy coverage with the configured scans.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Adds scheduled/manual Socket Basics security scanning for SAST, secrets, and repository analysis.

Changes:

  • Adds Socket Basics configuration and exclusions.
  • Adds Semgrep exclusion patterns.
  • Adds a pinned Docker-based GitHub Actions workflow.
File Summary
.socket-basics.json Scanner settings and exclusions
.semgrepignore SAST path exclusions
.github/​workflows/​socket-basics.yml Scheduled/manual scan execution

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

exit 0
fi
echo "::error::Socket Basics did not complete (docker exit $rc)"
exit "${rc:-1}"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Backlog (Not Ready)

Development

Successfully merging this pull request may close these issues.

2 participants