AlfredoSequeida / AlfredoSequeida/hints

Add free security scanning CI (CodeQL + pip-audit + Dependabot)

Aperta
#91 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
Python
Stelle
1.4k
Fork
47
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

## Summary

The repository currently has no security scanning or CI/CD workflows. This means:
- Python logic bugs and unsafe API usage go undetected (no SAST)
- Vulnerable dependency versions aren't flagged (no SCA)
- Dependency updates require manual tracking

## Proposal

Add free, automated security scanning at two levels:

### CI (GitHub Actions)
1. **CodeQL** (GitHub's own SAST) — finds Python logic bugs, injection flaws, unsafe API usage. Results appear in the Security > Code scanning tab.
2. **pip-audit** — scans installed dependencies against the OSV database for known CVEs. The full project (including PyGObject) is installed in a clean Ubuntu runner with system libs, so all dependencies including transitive ones are covered.
3. **Dependabot** — automatically opens PRs when dependencies have security updates, and keeps GitHub Actions action versions current.

### Local (pre-commit)
4. **bandit** — runs SAST on staged Python files before each commit, giving immediate local feedback without waiting for CI.
5. **pip-audit** — scans direct dependencies from `requirements.txt` (which mirrors `install_requires` in `setup.py`) against the OSV database before each commit.
- PyGObject is excluded from `requirements.txt` because it requires `gobject-introspection` system headers to build metadata, which are not universally available. It is fully covered by pip-audit in CI.
- Transitive dependency CVEs are covered by pip-audit in CI.

## Implementation

- `.github/workflows/security.yml` — CodeQL + pip-audit jobs triggered on push, PR, weekly schedule, and manual dispatch
- `.github/dependabot.yml` — weekly checks for pip and GitHub Actions ecosystems
- `.pre-commit-config.yaml` — bandit SAST + pip-audit hooks running on staged files / before commit
- `requirements.txt` — direct dependencies for local pip-audit (mirrors `setup.py install_requires`)

No external accounts, tokens, or paid services required.

I'd like to submit a PR implementing this if you're open to it.

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.