diff --git a/.github/workflows/socket-basics.yml b/.github/workflows/socket-basics.yml new file mode 100644 index 00000000..876e26f1 --- /dev/null +++ b/.github/workflows/socket-basics.yml @@ -0,0 +1,48 @@ +# Socket Basics security scan for js-stellar-base. +# Upstream: https://github.com/SocketDev/socket-basics +# Scanner settings live in .socket-basics.json; SAST path exclusions live in +# .semgrepignore. +# +# This workflow does SAST through OpenGrep and secret scanning through +# TruffleHog, and submits results to Socket.dev + +name: Socket Basics security scan + +on: + workflow_dispatch: + schedule: + - cron: "34 13 * * 6" + +permissions: + contents: read + +jobs: + socket-basics: + runs-on: ubuntu-latest + timeout-minutes: 30 + steps: + - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + with: + # Remove the GitHub token from the workspace after checkout, so it is + # not mounted into the Socket Basics container, which doesn't need it. + persist-credentials: false + + - name: Run Socket Basics + env: + SOCKET_SECURITY_API_TOKEN: ${{ secrets.SOCKET_SECURITY_API_TOKEN }} + SOCKET_ORG: stellar + run: | + # Socket Basics is pinned by digest since rule tuning is calibrated + # to the exact ruleset contained in this image. Automatic updates + # could introduce new rules and a sudden increase in false + # positives, as these tools are generally noisy without tuning. + docker run --rm \ + -v "$PWD:/github/workspace" \ + -w /github/workspace \ + -e SOCKET_SECURITY_API_TOKEN \ + -e SOCKET_ORG \ + -e GITHUB_REPOSITORY \ + -e GITHUB_REF_NAME \ + -e GITHUB_SHA \ + ghcr.io/socketdev/socket-basics@sha256:d463bae84f21d0240d5e197acb81e95144a966a20ab7cd05cca3a70e1796a4bb \ + --config .socket-basics.json diff --git a/.semgrepignore b/.semgrepignore new file mode 100644 index 00000000..6da5e00d --- /dev/null +++ b/.semgrepignore @@ -0,0 +1,107 @@ +# This file excludes scan paths from Socket Basics SAST scanning (through OpenGrep). +# It replaces the built-in ignore list for scanning with a more thorough list of paths. + +# --- third-party / generated --- +.git/ +node_modules/ +vendor/ +third_party/ +thirdparty/ +.devcontainer/ +dist/ +build/ +target/ +.venv/ +venv/ +__pycache__/ +.yarn/ +generated/ +*.min.js + +# --- test / example / mock code --- +__fixtures__/ +__mocks__/ +__snapshots__/ +__tests__/ +acceptance-test/ +acceptance-tests/ +acceptance_test/ +acceptance_tests/ +benches/ +browser-test/ +browser-tests/ +browser_test/ +browser_tests/ +e2e/ +e2e-test/ +e2e-tests/ +e2e_test/ +e2e_tests/ +example/ +examples/ +fixtures/ +functional-test/ +functional-tests/ +functional_test/ +functional_tests/ +integration-test/ +integration-tests/ +integration_test/ +integration_tests/ +integrationtest/ +integrationtests/ +mock/ +mock-dapp/ +mocks/ +perf-test/ +perf-tests/ +perf_test/ +perf_tests/ +performance-test/ +performance-tests/ +performance_test/ +performance_tests/ +regression-test/ +regression-tests/ +regression_test/ +regression_tests/ +smoke-test/ +smoke-tests/ +smoke_test/ +smoke_tests/ +spec/ +specs/ +test/ +test-data/ +test-fixtures/ +testFixtures/ +testdata/ +testfixtures/ +tests/ +unit-test/ +unit-tests/ +unit_test/ +unit_tests/ +*.test.js +*.test.jsx +*.test.ts +*.test.tsx +*.test.mjs +*.spec.js +*.spec.jsx +*.spec.ts +*.spec.tsx +*_test.go +*_test.py +*_test.rb +*_test.exs +test_*.py +*Test.java +*Tests.java +*Test.kt +*Tests.kt +*Test.scala +*Test.cs +*Tests.cs +tests.rs +test.rs diff --git a/.socket-basics.json b/.socket-basics.json new file mode 100644 index 00000000..9552ec00 --- /dev/null +++ b/.socket-basics.json @@ -0,0 +1,10 @@ +{ + "workspace": ".", + "javascript_sast_enabled": true, + "sast_ignore_overrides": "js-unhandled-promise-rejection:src/auth.js", + "secret_scanning_enabled": true, + "console_tabular_enabled": true, + "socket_tier_1_enabled": false, + "trivy_vuln_enabled": false, + "trufflehog_exclude_dir": "node_modules,dist,build,.git,yarn.lock,package-lock.json,pnpm-lock.yaml,Cargo.lock,go.sum,poetry.lock,Gemfile.lock,composer.lock" +}