Skip to content

Would you take a pull-request security scan workflow? #2734

Description

@ralyodio

Would a pull-request security scan be useful here, or is this already covered?

One workflow. On each pull request it scans the checked-out repository for
hardcoded credentials, injection, SSRF and unsafe deserialisation, and writes
findings to the Security tab. Report-only — findings never fail the build.

Two files under .github/, a pinned @profullstack/threatcrush@0.11.0 whose tarball is hashed before
install, and pull_request rather than pull_request_target.

A pull request is open alongside this with the diff, if reading it is easier
than discussing it.

Disclosure: I maintain ThreatCrush;
MIT and free. Written with AI assistance. Closing this is a fine answer and I
will not ask again.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status
    Backlog

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions