#!/usr/bin/env bash set -euo pipefail reports="${RUNNER_TEMP:?}/security-reports" mkdir -p "$reports" failed=0 for project in root backend frontend log-exporter; do directory=. [[ "$project" == root ]] || directory="apps/$project" if ! (cd "$directory" && timeout 10m npm audit --package-lock-only --audit-level=high --json) > "$reports/npm-audit-$project.json"; then echo "Dependency audit failed: $project (see report)" failed=1 fi done source_dir=$(mktemp -d "$RUNNER_TEMP/security-source.XXXXXX") git archive HEAD | tar -x -C "$source_dir" echo "Scoped monitoring exceptions: .trivyignore.yaml (see expiration dates in that file)" if ! trivy fs --scanners secret,misconfig --severity HIGH,CRITICAL --exit-code 1 \ --ignorefile "$source_dir/.trivyignore.yaml" --timeout 10m --format json --output "$RUNNER_TEMP/source-security-raw.json" "$source_dir"; then failed=1 fi python3 - <<'PYTHON' import json, os from pathlib import Path raw = Path(os.environ['RUNNER_TEMP']) / 'source-security-raw.json' if not raw.exists(): raise SystemExit('Source scanner produced no report') report = json.loads(raw.read_text()) for result in report.get('Results', []): for secret in result.get('Secrets', []): secret.pop('Match', None) secret.pop('Code', None) (raw.parent / 'security-reports' / 'source-security.json').write_text(json.dumps(report)) PYTHON exit "$failed"