You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Runs SAST through OpenGrep, secret scanning through TruffleHog, and
Dockerfile misconfiguration scanning through Trivy, submitting results
to Socket.dev.
.github/workflows/socket-basics.yml scheduled weekly + manual dispatch
.socket-basics.json scanner configuration
.semgrepignore SAST path exclusions
.trivyignore Dockerfile lint rules with no
security dimension (only present
where the repo has a Dockerfile)
Separate from socket-scan.yml, which covers dependency CVEs and Tier 1
reachability.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The generic test patterns (63 directory names, 23 file globs) were applied
to TruffleHog as well as OpenGrep. Excluding test code from SAST is sound,
but a credential committed to a test file is as live as one anywhere else,
and trufflehog_exclude_dir stops the file being opened -- making it a
permanent blind spot for every future secret in those paths.
Measured across all 120 repos: dropping the test patterns surfaces 77
additional detections in 20 files across 7 repos, and all 77 are false
positives -- 43 are UUIDs and random column values in CSV migration
fixtures, the rest one generated ECDSA test key pasted into nine files,
localhost postgres DSNs, and test JWTs. Those 20 files are now listed
individually, so every other test file is scanned for secrets.
.semgrepignore is unchanged; SAST keeps its test exclusions.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The reason will be displayed to describe this comment to others. Learn more.
Copilot review overview
🔵 Needs a closer look
Add or document SAST coverage for the repository’s F# code.
Review effort: Lite Findings: None
Previously missed (1)
In code that hasn't changed since last review
SAST excludes predominantly F# source code
.socket-basics.json:4
The SAST configuration enables analyzers only for C# and Python, but this repository's application and library logic is predominantly F# (src/App and src/FSLibrary). As a result, the SAST portion of this workflow leaves the main source tree unscanned; enable an available F# analyzer or document/use a separate analyzer that covers F# before treating this as repository-wide SAST.
The job inherited GitHub's 360-minute default. Measured scan work across
all 120 repos is 30.3s at the slowest and 8.3s at the median, so 30
minutes leaves roughly sixty times the observed worst case while still
failing a hung run in minutes rather than hours.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The reason will be displayed to describe this comment to others. Learn more.
Copilot review overview
🔵 Needs a closer look
Add explicit F# SAST coverage and enable or separately provide Trivy vulnerability scanning.
Review effort: Lite Findings: None
Previously missed (1)
In code that hasn't changed since last review
F# source files are excluded from SAST coverage
.socket-basics.json:4
This enables SAST only for C# and Python, but this repository's primary implementation is F# (README.md:18-20; doc/fsharp.md:1-3), so the 80+ .fs source files are not covered by either enabled analyzer. Please add an F#-capable scan (or another explicit control covering the F# tree) and document the coverage if Socket Basics cannot analyze F#; otherwise this workflow gives incomplete SAST coverage of the main codebase.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
More info: https://stellarorg.atlassian.net/wiki/spaces/SCRT/pages/5901680652/Socket+Basics+Integration+Guide