checkov: high-signal exposure/access checks -> high, best-practice noise -> low (was 51 undifferentiated mediums). npm audit wired for Node dep CVEs. Report collapses the low/info tail to a count. Adds ci/security-review.yml (PR backstop) and DEPLOY-R720.md (Phase 3 host runbook).
61 lines
2.6 KiB
YAML
61 lines
2.6 KiB
YAML
# Sea Haven security-review CI backstop (Phase 3).
|
|
# Drop into a target repo as .github/workflows/security-review.yml, OR (preferred, per
|
|
# engineering-handbook/cicd.md) promote into Sea-Haven-Industries/.github as a reusable workflow.
|
|
#
|
|
# This is the UNBYPASSABLE deterministic backstop: local hooks can be skipped with --no-verify,
|
|
# this cannot. It runs the SAME review.sh as local. The agentic detector/verifier pass (Path B)
|
|
# is gated behind SECURITY_REVIEW_AGENTIC=1 and requires the headless orchestrator runner +
|
|
# ANTHROPIC creds (see DEPLOY-R720.md) — until that exists, CI runs the scanners-only gate.
|
|
name: security-review
|
|
on:
|
|
pull_request:
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
security-review:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Install scanners
|
|
run: |
|
|
python3 -m pip install --quiet pipx && python3 -m pipx ensurepath
|
|
pipx install semgrep >/dev/null
|
|
pipx install checkov >/dev/null
|
|
pipx install pip-audit >/dev/null
|
|
pip install --quiet cfn-lint
|
|
# gitleaks binary
|
|
curl -sSL https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_linux_x64.tar.gz \
|
|
| tar -xz -C /usr/local/bin gitleaks
|
|
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
|
|
|
|
- name: Fetch review.sh
|
|
run: |
|
|
# Pin to the orchestrator repo / a release artifact. Placeholder: vendor a copy or curl a tag.
|
|
git clone --depth 1 https://github.com/amoussa1229/orchestrator /tmp/orch
|
|
chmod +x /tmp/orch/security-review/review.sh
|
|
|
|
- name: Run gate (scanners; agentic if enabled)
|
|
env:
|
|
SECURITY_REVIEW_AGENTIC: ${{ vars.SECURITY_REVIEW_AGENTIC }} # set to 1 once headless runner exists
|
|
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
|
|
run: |
|
|
SCOPE="${SECURITY_REVIEW_SCOPE:-src scripts template.yaml}"
|
|
if [ "${SECURITY_REVIEW_AGENTIC:-0}" = "1" ]; then
|
|
python3 /tmp/orch/security-review/run_headless.py --scope "$SCOPE" --out /tmp/agent.json .
|
|
/tmp/orch/security-review/review.sh --scope "$SCOPE" --agent-findings /tmp/agent.json \
|
|
--suppressions .security-review/suppressions.json --json-out /tmp/review.json .
|
|
else
|
|
/tmp/orch/security-review/review.sh --scope "$SCOPE" --scanners-only \
|
|
--suppressions .security-review/suppressions.json --json-out /tmp/review.json .
|
|
fi
|
|
|
|
- name: Upload findings
|
|
if: always()
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: security-review-findings
|
|
path: /tmp/review.json
|