Skip to content

Add Socket Basics security scanning workflow - #985

Open
kanwalpreetd wants to merge 1 commit into
stellar:masterfrom
kanwalpreetd:master
Open

kanwalpreetd wants to merge 1 commit into
stellar:masterfrom
kanwalpreetd:master

Conversation

@kanwalpreetd

@kanwalpreetd kanwalpreetd commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

@kanwalpreetd
kanwalpreetd force-pushed the master branch 4 times, most recently from 69ec578 to 632fc93 Compare September 26, 2026 01:27
@kanwalpreetd
kanwalpreetd marked this pull request as ready for review September 28, 2026 12:38
Copilot AI lite review requested due to automatic review settings September 28, 2026 12:38

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Resolve the workflow status handling and align the documented Trivy coverage with the configuration.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds a scheduled/manual Socket Basics security-scanning workflow with configuration and scan exclusions.

Changes:

  • Adds Socket Basics scanner configuration.
  • Adds Semgrep exclusion rules.
  • Adds a pinned-container GitHub Actions workflow.
File Summary Review status
.socket-basics.json Configures Socket security checks and exclusions. Moderate issue: Trivy is disabled despite the workflow’s documented coverage.
.semgrepignore Defines excluded SAST paths. No findings.
.github/​workflows/​socket-basics.yml Runs and evaluates scheduled/manual scans. Moderate issue: a missing completion message can still produce a successful status.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/socket-basics.yml Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

All reviewed changes have no unresolved blocking issues.

Review effort: Lite
Findings: None

Resolved since last review (1)

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Scope the promise-rejection suppression to the specific known false-positive location.

Review effort: Lite
Findings: None

Copilot AI review requested due to automatic review settings September 29, 2026 08:51

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The workflow can mask non-zero scanner results and fail clean scans.

Review effort: Lite
Findings: 1 High severity

Open (1)

Comment thread .github/workflows/socket-basics.yml Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Preserve non-zero scanner exit statuses so high/critical findings block the job.

Review effort: Lite
Findings: 1 High severity

Open (1)

Copilot AI lite review requested due to automatic review settings September 29, 2026 22:41
@kanwalpreetd
kanwalpreetd force-pushed the master branch 2 times, most recently from aa76c8a to 9f9db73 Compare September 29, 2026 22:41

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The workflow can mask nonzero scanner failures when the facts file is non-empty.

Review effort: Lite
Findings: 1 High severity

Open (1)

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Moderate issues remain in credential handling, alert counting, scan validation, and broad security suppression.

Review effort: Lite
Findings: 1 High severity

Open (1)

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review issues were identified.

Review effort: Lite
Findings: None

Resolved since last review (1)

Copilot AI lite review requested due to automatic review settings October 2, 2026 01:44

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Moderate issues remain with overly broad exclusions for lockfiles and authorization code.

Review effort: Lite
Findings: None

Runs SAST through OpenGrep, secret scanning through TruffleHog, and
Dockerfile misconfiguration scanning through Trivy, submitting results
to Socket.dev.

  .github/workflows/socket-basics.yml  scheduled weekly + manual dispatch
  .socket-basics.json                  scanner configuration
  .semgrepignore                       SAST path exclusions
  .trivyignore                         Dockerfile lint rules with no
                                       security dimension (only present
                                       where the repo has a Dockerfile)

Separate from socket-scan.yml, which covers dependency CVEs and Tier 1
reachability.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings October 2, 2026 02:24

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review issues were identified.

Review effort: Lite
Findings: None

@kanwalpreetd
kanwalpreetd requested a review from Ryang-21 October 2, 2026 20:01

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants