Skip to content

Add Socket Basics security scanning workflow - #55

Open
kanwalpreetd wants to merge 1 commit into
stellar:mainfrom
kanwalpreetd:main
Open

kanwalpreetd wants to merge 1 commit into
stellar:mainfrom
kanwalpreetd:main

Conversation

@kanwalpreetd

@kanwalpreetd kanwalpreetd commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

@kanwalpreetd
kanwalpreetd force-pushed the main branch 4 times, most recently from de73303 to fb2258f Compare September 26, 2026 01:26
@kanwalpreetd
kanwalpreetd marked this pull request as ready for review September 28, 2026 12:37
Copilot AI lite review requested due to automatic review settings September 28, 2026 12:37

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Moderate findings leave security coverage gaps and may allow an incomplete scan to pass.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds scheduled and manual Socket Basics security scanning with SAST, secret scanning, exclusions, and Socket result submission.

Changes:

  • Adds scanner configuration.
  • Adds Semgrep exclusion rules.
  • Adds a pinned Docker-based GitHub Actions workflow.
File Description
.socket-basics.json Configures scanner features and exclusions.
.semgrepignore Defines SAST scan exclusions.
.github/​workflows/​socket-basics.yml Runs scheduled/manual security scans.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .socket-basics.json

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Add a job timeout, verify submission success, and narrow the sensitive-data suppression.

Review effort: Lite
Findings: 2 Medium severity

Open (2)

Comment thread .github/workflows/socket-basics.yml

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Address the workflow credential exposure and narrow or remove the broad security-rule suppressions.

Review effort: Lite
Findings: 1 High severity · 2 Medium severity

Open (3)

Comment thread .github/workflows/socket-basics.yml

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The workflow can report success after a partial scan when the scanner exits nonzero.

Review effort: Lite
Findings: 2 High severity · 2 Medium severity

Open (4)

Comment thread .github/workflows/socket-basics.yml Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The workflow incorrectly fails successful scans that produce zero findings.

Review effort: Lite
Findings: 2 High severity · 3 Medium severity

Open (5)

Comment thread .github/workflows/socket-basics.yml Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Fix workflow failure handling and narrow the broad scanning exclusions.

Review effort: Lite
Findings: 1 High severity · 3 Medium severity

Open (4)
Resolved since last review (1)

Copilot AI lite review requested due to automatic review settings September 29, 2026 22:39

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved critical and moderate findings affect secret coverage and security workflow correctness.

Review effort: Lite
Findings: 2 High severity · 3 Medium severity

Open (5)

Comment thread .socket-basics.json Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The workflow can succeed without submitting results when the API secret is missing.

Review effort: Lite
Findings: 1 High severity · 4 Medium severity

Open (5)
Resolved since last review (1)

Comment thread .github/workflows/socket-basics.yml Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Broad suppressions can hide real security issues and must be narrowed or removed.

Review effort: Lite
Findings: 1 High severity · 3 Medium severity

Open (4)
Resolved since last review (1)

Copilot AI lite review requested due to automatic review settings October 2, 2026 01:43

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Security-scanning workflow changes warrant final human review.

Review effort: Lite
Findings: 1 High severity · 3 Medium severity

Open (4)

Runs SAST through OpenGrep, secret scanning through TruffleHog, and
Dockerfile misconfiguration scanning through Trivy, submitting results
to Socket.dev.

  .github/workflows/socket-basics.yml  scheduled weekly + manual dispatch
  .socket-basics.json                  scanner configuration
  .semgrepignore                       SAST path exclusions
  .trivyignore                         Dockerfile lint rules with no
                                       security dimension (only present
                                       where the repo has a Dockerfile)

Separate from socket-scan.yml, which covers dependency CVEs and Tier 1
reachability.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings October 2, 2026 02:23

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review issues were identified.

Review effort: Lite
Findings: None

Resolved since last review (4)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants