Skip to content

Add Socket Basics security scanning workflow - #436

Open
kanwalpreetd wants to merge 4 commits into
stellar:mainfrom
kanwalpreetd:main
Open

kanwalpreetd wants to merge 4 commits into
stellar:mainfrom
kanwalpreetd:main

Conversation

@kanwalpreetd

@kanwalpreetd kanwalpreetd commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

@kanwalpreetd
kanwalpreetd force-pushed the main branch 4 times, most recently from e57bc7e to 0dd804b Compare September 26, 2026 01:31
@kanwalpreetd
kanwalpreetd marked this pull request as ready for review September 28, 2026 12:41
Copilot AI lite review requested due to automatic review settings September 28, 2026 12:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Address the command-injection suppression and ensure incomplete scans fail explicitly.

Review effort: Lite
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Adds a scheduled/manual Socket Basics security-scanning workflow for SAST, secret, and Dockerfile checks.

Changes:

  • Adds pinned Docker-based GitHub Actions workflow.
  • Configures Socket Basics scanners and targets.
  • Adds Semgrep and Trivy exclusions.
File Description
.trivyignore Defines Dockerfile scan exclusions.
.socket-basics.json Configures Socket Basics scanning.
.semgrepignore Defines SAST exclusions.
.github/​workflows/​socket-basics.yml Runs and reports scheduled security scans.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .socket-basics.json
Comment thread .github/workflows/socket-basics.yml Outdated
Copilot AI review requested due to automatic review settings September 29, 2026 07:19

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Moderate issues remain in scan-result counting, secret validation, and shell-injection finding suppression.

Review effort: Lite
Findings: 1 High severity

Open (1)
Resolved since last review (1)

Copilot AI review requested due to automatic review settings September 29, 2026 09:33

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The workflow has result-validation and submission gaps, and suppresses a real command-injection finding.

Review effort: Lite
Findings: 2 High severity

Open (2)

Comment thread .github/workflows/socket-basics.yml Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The workflow can mark runtime or reporting failures as successful when facts are present.

Review effort: Lite
Findings: 3 High severity

Open (3)

Comment thread .github/workflows/socket-basics.yml Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved blocking issues were identified.

Review effort: Lite
Findings: 2 High severity

Open (2)
Resolved since last review (1)

Runs SAST through OpenGrep, secret scanning through TruffleHog, and
Dockerfile misconfiguration scanning through Trivy, submitting results
to Socket.dev.

  .github/workflows/socket-basics.yml  scheduled weekly + manual dispatch
  .socket-basics.json                  scanner configuration
  .semgrepignore                       SAST path exclusions
  .trivyignore                         Dockerfile lint rules with no
                                       security dimension (only present
                                       where the repo has a Dockerfile)

Separate from socket-scan.yml, which covers dependency CVEs and Tier 1
reachability.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review issues were identified.

Review effort: Lite
Findings: 1 High severity

Open (1)
Resolved since last review (1)

Copilot AI lite review requested due to automatic review settings October 2, 2026 00:57

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Address missing F# SAST coverage and correct the Trivy suppression configuration.

Review effort: Lite
Findings: None

Resolved since last review (1)

The generic test patterns (63 directory names, 23 file globs) were applied
to TruffleHog as well as OpenGrep. Excluding test code from SAST is sound,
but a credential committed to a test file is as live as one anywhere else,
and trufflehog_exclude_dir stops the file being opened -- making it a
permanent blind spot for every future secret in those paths.

Measured across all 120 repos: dropping the test patterns surfaces 77
additional detections in 20 files across 7 repos, and all 77 are false
positives -- 43 are UUIDs and random column values in CSV migration
fixtures, the rest one generated ECDSA test key pasted into nine files,
localhost postgres DSNs, and test JWTs. Those 20 files are now listed
individually, so every other test file is scanned for secrets.

.semgrepignore is unchanged; SAST keeps its test exclusions.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings October 2, 2026 01:50

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Add or document SAST coverage for the repository’s F# code.

Review effort: Lite
Findings: None

Previously missed (1)

In code that hasn't changed since last review

Medium severity SAST excludes predominantly F# source code

.socket-basics.json:4

The SAST configuration enables analyzers only for C# and Python, but this repository's application and library logic is predominantly F# (src/App and src/FSLibrary). As a result, the SAST portion of this workflow leaves the main source tree unscanned; enable an available F# analyzer or document/use a separate analyzer that covers F# before treating this as repository-wide SAST.

The job inherited GitHub's 360-minute default. Measured scan work across
all 120 repos is 30.3s at the slowest and 8.3s at the median, so 30
minutes leaves roughly sixty times the observed worst case while still
failing a hung run in minutes rather than hours.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings October 2, 2026 02:27

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Add explicit F# SAST coverage and enable or separately provide Trivy vulnerability scanning.

Review effort: Lite
Findings: None

Previously missed (1)

In code that hasn't changed since last review

Medium severity F# source files are excluded from SAST coverage

.socket-basics.json:4

This enables SAST only for C# and Python, but this repository's primary implementation is F# (README.md:18-20; doc/fsharp.md:1-3), so the 80+ .fs source files are not covered by either enabled analyzer. Please add an F#-capable scan (or another explicit control covering the F# tree) and document the coverage if Socket Basics cannot analyze F#; otherwise this workflow gives incomplete SAST coverage of the main codebase.

@kanwalpreetd
kanwalpreetd requested a review from anupsdf October 2, 2026 19:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants