Files
cairnobs/.github/workflows/security-scan.yml
T
jcoffey-dev 81ee47b1cd ci: fix the security scan, which has failed on every push
Two unrelated causes, plus one that hid the others.

govulncheck: setup-go used go-version-file, so it installed exactly what
each go.mod pins -- `go 1.25.0` -- and then reported 28 CVEs in that
release's standard library (crypto/x509 quadratic name-constraint
parsing, GO-2025-4007, and friends), all fixed in 1.25.3. None of it
described anything we ship: every Dockerfile builds FROM
golang:1.25-alpine, a floating tag that resolves to the newest 1.25.x,
so the binaries already had the fixes. The go directive is a minimum
language version, not a statement about which toolchain to audit with.
Track the floating 1.25 line instead, and the scan matches production.
Confirmed by running govulncheck against a patched toolchain locally:
deploy/operator reports 0 vulnerabilities and exits 0.

cargo-deny: RUSTSEC-2024-0384, `instant` is unmaintained. A maintenance
advisory rather than a vulnerability -- no CVE, nothing to patch -- and
it arrives transitively via tantivy 0.22.1 -> measure_time 0.8.3, so it
cannot be dropped without moving off the pinned Tantivy. The advisory's
substance does not apply here anyway: instant papers over
std::time::Instant being missing on wasm, and search builds native musl.
Ignored in search/deny.toml with that reasoning recorded and a note to
delete the entry at the next Tantivy upgrade rather than let it ossify.

Both matrices now set fail-fast: false. Only two of the twelve jobs
actually failed; the other nine were cancelled, which made a two-cause
failure look like a total collapse and hid every finding but the first.
2026-08-22 19:22:42 -07:00

97 lines
3.7 KiB
YAML

name: Security scan
# Closes a real gap the security audit found: license-compliance.yml
# (this repo's only other workflow) checks license text, never
# vulnerabilities -- and agent/deny.toml and search/deny.toml already
# ship an [advisories] policy that nothing in CI ever invoked. Same
# matrix-per-language shape as license-compliance.yml, extended to the
# equivalent vulnerability-scanning tool per ecosystem: cargo-deny's
# other command for Rust, govulncheck for Go, npm audit for the one
# npm package. A new dependency with a known vulnerability now fails
# the build here, not months later when someone happens to re-run this
# by hand.
on:
push:
branches: [master, main]
pull_request:
jobs:
rust-advisories:
name: Rust vulnerability check (cargo-deny)
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
crate_dir: [agent, search]
steps:
- uses: actions/checkout@v4
- uses: EmbarkStudios/cargo-deny-action@v2
with:
manifest-path: ${{ matrix.crate_dir }}/Cargo.toml
command: check advisories
go-vulncheck:
name: Go vulnerability check (govulncheck)
runs-on: ubuntu-latest
strategy:
# One module's findings must not cancel the other eight -- with
# fail-fast a single failure hid the whole matrix behind one log.
fail-fast: false
matrix:
# Same module list as license-compliance.yml's go-licenses job --
# see that job's own comment for why cli/hack-webhook-sink/
# hack-alert-load-test are excluded (no third-party dependencies
# at audit time).
module_dir:
- api
- ingest
- alerting
- enterprise
- deploy/operator
- terraform
- proto
- hack/benchmark-fixture
- hack/windows-fixture
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
# Deliberately NOT go-version-file. Each go.mod pins an exact
# patch (`go 1.25.0`), so go-version-file made CI scan against
# the *unpatched* 1.25.0 standard library and fail on 28
# stdlib CVEs -- crypto/x509 quadratic name-constraint parsing
# (GO-2025-4007) and friends, all fixed in 1.25.3. None of it
# was real: every Dockerfile builds `FROM golang:1.25-alpine`,
# a floating tag that resolves to the newest 1.25.x, so the
# shipped binaries already had the fixes. The go directive
# states the minimum language version, not the toolchain to
# audit with. Track the floating 1.25 line so this scans what
# production actually builds.
go-version: '1.25'
- run: go install golang.org/x/vuln/cmd/govulncheck@latest
- name: Check for known vulnerabilities
working-directory: ${{ matrix.module_dir }}
run: govulncheck ./...
npm-audit:
name: npm vulnerability check (npm audit)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 22
- working-directory: web
run: npm ci
- name: Audit production dependencies
working-directory: web
# --omit=dev, not the deprecated --production: this deliberately
# only gates the runtime bundle a real deployment actually
# ships. The one known finding in web's full dependency tree
# today (a `cookie` advisory) lives entirely in the SvelteKit
# build toolchain, not the production bundle -- fixing it needs
# a deliberate, tested major-version bump, not an automated
# `audit fix --force`, so it's out of scope for this gate.
run: npm audit --omit=dev