Skip to content

ci(security): pinned osv-scanner job (closes #91) - #94

Merged
FabioLeitao merged 3 commits into
mainfrom
chore/osv-scanner-91
Sep 22, 2026
Merged

FabioLeitao merged 3 commits into
mainfrom
chore/osv-scanner-91

Conversation

@FabioLeitao

@FabioLeitao FabioLeitao commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Closes #91

Summary

  • Default branch confirmed: main.
  • Job osv-scanner on .github/workflows/security.yml: binary v2.6.0, sha256 ca69b3d3… (same as keen-platypus production job).
  • actions/checkout stays @11bd7190… (v4.2.2) like the other jobs in this file and KP security.yml — the 2026-09-16 issue comment used a v6 checkout SHA that is not what KP runs today.
  • Local mirror: scripts/check-all.sh (+ --skip-osv-scanner), cache under scripts/.cache/ (gitignored).
  • Real scan before PR: osv-scanner scan source -r . → exit 128 (No package sources found). With --allow-no-lockfiles → exit 0, no vulns. Static site has no lockfiles; the flag is required or CI stays red. Guardrail test pins the checksum + flag.

Test plan

Scan the static tree locally: no lockfiles, so CI/check-all use
--allow-no-lockfiles (bare scan source -r . exits 128). Binary 2.6.0
sha256 matches keen-platypus; default branch is main.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Comment thread scripts/check-all.sh Outdated
set -uo pipefail without -e let a failed sha256sum -c still mv the blob
into scripts/.cache. Check the checksum exit code before promote, and
cover the mismatch path in test_guardrails.py with a fake curl payload.
check-all runs ruff on tests/; use re.MULTILINE and removesuffix so the
local gate stays green after the checksum-fail coverage.
@FabioLeitao
FabioLeitao merged commit bbc0ae3 into main Sep 22, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci(security): dependency-vulnerability scan (osv-scanner) — implementação real disponível no keen-platypus

1 participant