Repository navigation
fix(telemetry): include Anthropic cache tokens in total token extraction #508
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Security | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| jobs: | |
| secrets: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v6 | |
| with: | |
| fetch-depth: 0 | |
| - name: Secret Scanning | |
| uses: trufflesecurity/trufflehog@main | |
| with: | |
| # Lob is excluded: through v3.96.0 its key pattern is `test_` + 35 word characters, so | |
| # every 40-character pytest function name matches and Lob's API answers 403, which that | |
| # version reads as "verified". Fixed upstream in 43b8e371a, unreleased. We don't use Lob. | |
| # uv.lock files are excluded via .trufflehog-exclude-paths; see that file for why. | |
| extra_args: >- | |
| --results=verified,unknown --exclude-detectors=Lob | |
| --exclude-paths=.trufflehog-exclude-paths | |
| changes: | |
| if: github.event_name != 'push' | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| # paths-filter reads the PR's changed-file list from the API. | |
| pull-requests: read | |
| outputs: | |
| services: ${{ steps.resolve.outputs.services }} | |
| paths: ${{ steps.resolve.outputs.paths }} | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v6 | |
| - name: Check for file changes | |
| if: github.event_name == 'pull_request' | |
| uses: dorny/paths-filter@v3 | |
| id: filter | |
| with: | |
| filters: | | |
| backend: | |
| - 'apps/backend/**' | |
| frontend: | |
| - 'apps/frontend/**' | |
| sdk: | |
| - 'sdk/**' | |
| penelope: | |
| - 'penelope/**' | |
| worker: | |
| - 'apps/worker/**' | |
| chatbot: | |
| - 'apps/chatbot/**' | |
| polyphemus: | |
| - 'apps/polyphemus/**' | |
| telemetry-processor: | |
| - 'apps/telemetry-processor/**' | |
| - name: Resolve services to scan | |
| id: resolve | |
| env: | |
| SERVICES: | | |
| {"backend": "apps/backend", | |
| "frontend": "apps/frontend", | |
| "sdk": "sdk", | |
| "penelope": "penelope", | |
| "worker": "apps/worker", | |
| "chatbot": "apps/chatbot", | |
| "polyphemus": "apps/polyphemus", | |
| "telemetry-processor": "apps/telemetry-processor"} | |
| CHANGED: ${{ steps.filter.outputs.changes }} | |
| run: | | |
| set -euo pipefail | |
| PATHS=$(jq -c . <<<"$SERVICES") | |
| if [ "${{ github.event_name }}" = "workflow_dispatch" ]; then | |
| SERVICE_LIST=$(jq -c 'keys' <<<"$PATHS") | |
| else | |
| SERVICE_LIST="$CHANGED" | |
| fi | |
| echo "paths=$PATHS" >> "$GITHUB_OUTPUT" | |
| echo "services=$SERVICE_LIST" >> "$GITHUB_OUTPUT" | |
| echo "Scanning: $SERVICE_LIST" | |
| trivy: | |
| needs: changes | |
| if: needs.changes.outputs.services != '[]' | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| security-events: write | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| service: ${{ fromJSON(needs.changes.outputs.services) }} | |
| env: | |
| SCAN_REF: ${{ fromJSON(needs.changes.outputs.paths)[matrix.service] }} | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v6 | |
| - name: Run Trivy vulnerability scanner | |
| uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # v0.35.0 | |
| with: | |
| scan-type: fs | |
| scan-ref: ${{ env.SCAN_REF }} | |
| format: table | |
| exit-code: 0 | |
| severity: CRITICAL,HIGH,MEDIUM | |
| scanners: vuln | |
| version: v0.69.2 | |
| - name: Run Trivy (SARIF upload) | |
| uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # v0.35.0 | |
| with: | |
| scan-type: fs | |
| scan-ref: ${{ env.SCAN_REF }} | |
| format: sarif | |
| output: trivy-${{ matrix.service }}.sarif | |
| exit-code: 0 | |
| severity: CRITICAL,HIGH,MEDIUM | |
| scanners: vuln | |
| version: v0.69.2 | |
| - name: Upload SARIF to GitHub Security | |
| uses: github/codeql-action/upload-sarif@v3 | |
| with: | |
| sarif_file: trivy-${{ matrix.service }}.sarif | |
| category: trivy-${{ matrix.service }} |