-
Notifications
You must be signed in to change notification settings - Fork 225
147 lines (115 loc) · 3.78 KB
/
Copy pathsecurity.yml
File metadata and controls
147 lines (115 loc) · 3.78 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
name: Security Checks
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
on:
push:
branches: [ main, develop ]
pull_request:
branches: [ main, develop ]
schedule:
- cron: '0 2 * * 0'
jobs:
dependency-check:
name: Dependency Vulnerability Scan
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: '20.19.0'
cache: 'npm'
- name: Install dependencies
env:
HUSKY: 0
run: npm ci
- name: Run npm audit (production dependencies)
run: npm audit --omit=dev --audit-level=high
- name: Check for known vulnerabilities in frontend (production dependencies)
run: npm audit --workspace=frontend --omit=dev --audit-level=high
- name: Check for known vulnerabilities in backend (production dependencies)
run: npm audit --workspace=backend --omit=dev --audit-level=high
- name: Setup Rust toolchain for contract audit
uses: dtolnay/rust-toolchain@stable
- name: Cache cargo-audit
id: cargo-audit-cache
uses: actions/cache@v4
with:
path: ~/.cargo/bin/cargo-audit
key: cargo-audit-${{ runner.os }}
- name: Install cargo-audit
if: steps.cargo-audit-cache.outputs.cache-hit != 'true'
run: cargo install cargo-audit --locked
- name: Check for known vulnerabilities in smart contracts (cargo audit)
run: cargo audit
working-directory: contracts
- name: Setup Rust toolchain for contract audit
uses: dtolnay/rust-toolchain@stable
- name: Cache cargo-audit
id: cargo-audit-cache
uses: actions/cache@v4
with:
path: ~/.cargo/bin/cargo-audit
key: cargo-audit-${{ runner.os }}-0.22.0
- name: Install cargo-audit
if: steps.cargo-audit-cache.outputs.cache-hit != 'true'
run: cargo install cargo-audit --version 0.22.0 --locked
- name: Check for known vulnerabilities in smart contracts (cargo audit)
run: cargo audit
working-directory: contracts
- name: Verify security setup
run: npm run verify-security
cargo-audit:
name: Cargo Dependency Vulnerability Scan
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Install Rust stable
uses: dtolnay/rust-toolchain@stable
- name: Install cargo-audit
run: cargo install cargo-audit
- name: Run cargo audit on contracts
run: cargo audit
working-directory: contracts
codeql-analysis:
name: CodeQL Analysis
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write
strategy:
fail-fast: false
matrix:
language: [ 'javascript', 'typescript', 'rust' ]
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Setup Rust toolchain
if: matrix.language == 'rust'
uses: dtolnay/rust-toolchain@stable
with:
toolchain: stable
targets: wasm32-unknown-unknown
components: clippy
- name: Rust Cache
if: matrix.language == 'rust'
uses: Swatinem/rust-cache@v2
with:
workspace: "contracts -> target"
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
with:
languages: ${{ matrix.language }}
- name: Build Rust contracts for CodeQL
if: matrix.language == 'rust'
run: cargo check --workspace --all-targets
working-directory: contracts
- name: Autobuild
if: matrix.language != 'rust'
uses: github/codeql-action/autobuild@v3
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3