github / github/spec-kit

[Security hardening] Add automated security audit checks for Python dependencies and static analysis

Ouverte
#2,438 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub
stale
Langage dominant
Python
Étoiles
137k
Forks
12.3k
Merge moyen
2 j 12 h
PR mergées (30 j)
159

Description

## Summary

Add lightweight automated security checks to CI for Python dependency vulnerabilities and static-analysis findings.

## Why

Manual audit runs are useful, but dependency and static-analysis checks should be repeatable in CI. `pip-audit` can catch known Python package vulnerabilities, and Bandit can flag Python security-sensitive patterns for review.

## Proposed direction

- Add a CI job or workflow for `pip-audit`.
- Add a Bandit job configured for actionable findings.
- Keep initial scope focused so the signal is useful and does not fail on low-value noise.
- Document how to run the checks locally.

## Acceptance criteria

- CI runs dependency vulnerability checks.
- CI runs Python static security checks with an explicit configuration.
- The current dependency set passes the audit.
- Any intentionally accepted Bandit findings are documented or excluded explicitly.

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.