Skip to content

Security

Security #15

Workflow file for this run

name: Security
on:
push:
branches: [ main, develop ]
pull_request:
branches: [ main, develop ]
schedule:
# Run security checks weekly
- cron: '0 0 * * 0'
jobs:
security:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v4
with:
python-version: '3.11'
- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -r requirements.txt
pip install bandit safety
- name: Run Bandit security linter
run: |
bandit -r . -f json -o bandit-report.json || true
bandit -r . -f txt -o bandit-report.txt || true
- name: Run Safety check
run: |
safety check --json --output safety-report.json || true
safety check --output safety-report.txt || true
- name: Upload Bandit results to GitHub Security tab
uses: github/codeql-action/upload-sarif@v2
if: always()
with:
sarif_file: bandit-report.json
- name: Comment PR with security results
if: github.event_name == 'pull_request'
uses: actions/github-script@v6
with:
script: |
const fs = require('fs');
let banditOutput = '';
let safetyOutput = '';
try {
banditOutput = fs.readFileSync('bandit-report.txt', 'utf8');
} catch (e) {
banditOutput = 'No Bandit issues found';
}
try {
safetyOutput = fs.readFileSync('safety-report.txt', 'utf8');
} catch (e) {
safetyOutput = 'No Safety issues found';
}
const comment = `## Security Scan Results
### Bandit Security Linter
\`\`\`
${banditOutput}
\`\`\`
### Dependency Safety Check
\`\`\`
${safetyOutput}
\`\`\`
`;
github.rest.issues.createComment({
issue_number: context.issue.number,
owner: context.repo.owner,
repo: context.repo.repo,
body: comment
});