34 lines
1.2 KiB
Bash
34 lines
1.2 KiB
Bash
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
reports="${RUNNER_TEMP:?}/security-reports"
|
|
mkdir -p "$reports"
|
|
failed=0
|
|
for project in root backend frontend log-exporter; do
|
|
directory=.
|
|
[[ "$project" == root ]] || directory="apps/$project"
|
|
if ! (cd "$directory" && timeout 10m npm audit --package-lock-only --audit-level=high --json) > "$reports/npm-audit-$project.json"; then
|
|
echo "Dependency audit failed: $project (see report)"
|
|
failed=1
|
|
fi
|
|
done
|
|
source_dir=$(mktemp -d "$RUNNER_TEMP/security-source.XXXXXX")
|
|
git archive HEAD | tar -x -C "$source_dir"
|
|
if ! trivy fs --scanners secret,misconfig --severity HIGH,CRITICAL --exit-code 1 \
|
|
--timeout 10m --format json --output "$RUNNER_TEMP/source-security-raw.json" "$source_dir"; then
|
|
failed=1
|
|
fi
|
|
python3 - <<'PYTHON'
|
|
import json, os
|
|
from pathlib import Path
|
|
raw = Path(os.environ['RUNNER_TEMP']) / 'source-security-raw.json'
|
|
if not raw.exists():
|
|
raise SystemExit('Source scanner produced no report')
|
|
report = json.loads(raw.read_text())
|
|
for result in report.get('Results', []):
|
|
for secret in result.get('Secrets', []):
|
|
secret.pop('Match', None)
|
|
secret.pop('Code', None)
|
|
(raw.parent / 'security-reports' / 'source-security.json').write_text(json.dumps(report))
|
|
PYTHON
|
|
exit "$failed"
|