AlfredoSequeida / AlfredoSequeida/hints
Add free security scanning CI (CodeQL + pip-audit + Dependabot)
- Ngôn ngữ chính
- Python
- Star
- 1.4k
- Fork
- 47
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Mô tả
## Summary
The repository currently has no security scanning or CI/CD workflows. This means:
- Python logic bugs and unsafe API usage go undetected (no SAST)
- Vulnerable dependency versions aren't flagged (no SCA)
- Dependency updates require manual tracking
## Proposal
Add free, automated security scanning at two levels:
### CI (GitHub Actions)
1. **CodeQL** (GitHub's own SAST) — finds Python logic bugs, injection flaws, unsafe API usage. Results appear in the Security > Code scanning tab.
2. **pip-audit** — scans installed dependencies against the OSV database for known CVEs. The full project (including PyGObject) is installed in a clean Ubuntu runner with system libs, so all dependencies including transitive ones are covered.
3. **Dependabot** — automatically opens PRs when dependencies have security updates, and keeps GitHub Actions action versions current.
### Local (pre-commit)
4. **bandit** — runs SAST on staged Python files before each commit, giving immediate local feedback without waiting for CI.
5. **pip-audit** — scans direct dependencies from `requirements.txt` (which mirrors `install_requires` in `setup.py`) against the OSV database before each commit.
- PyGObject is excluded from `requirements.txt` because it requires `gobject-introspection` system headers to build metadata, which are not universally available. It is fully covered by pip-audit in CI.
- Transitive dependency CVEs are covered by pip-audit in CI.
## Implementation
- `.github/workflows/security.yml` — CodeQL + pip-audit jobs triggered on push, PR, weekly schedule, and manual dispatch
- `.github/dependabot.yml` — weekly checks for pip and GitHub Actions ecosystems
- `.pre-commit-config.yaml` — bandit SAST + pip-audit hooks running on staged files / before commit
- `requirements.txt` — direct dependencies for local pip-audit (mirrors `setup.py install_requires`)
No external accounts, tokens, or paid services required.
I'd like to submit a PR implementing this if you're open to it.
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Đánh giá
Issue này chưa được đánh giá.