Originally created by: ralyodio
Adds one workflow. On each pull request it scans the checked-out repository for
hardcoded credentials, injection, SSRF and unsafe deserialisation.
.github/workflows/threatcrush-scan.ymlFindings go to the Security tab and a pull request comment. If you would rather
not grant those write scopes, say so and I will send the contents: read build:
same scan, findings in the job summary and a SARIF artifact, and the two steps
that need a write scope removed from the file rather than switched off.
Report-only. failOn is empty, so findings never fail the build. An install
or scan failure does fail the job: a scanner that reports clean when it did not
run is worse than no scanner.
Pre-existing findings. The report leads with findings in the files the pull
request changes and folds the rest of the repository behind a <details> summary,
so an existing backlog is visible without being posted at the author of an
unrelated change. Anything intentional can be excluded with a .threatcrushignore
or a // threatcrush-disable-next-line <rule-id> comment.
Scope: it scans the whole checked-out repository, not only the diff.
Supply chain. Pinned to @profullstack/threatcrush@0.11.9; the tarball is hashed and checked against
a value in the workflow before install (npm view it yourself), installed with
--ignore-scripts, actions pinned to commit SHAs, and it runs on pull_request
rather than pull_request_target.
Asked first in https://github.com/imshaikot/browsentic/issues/11.
Disclosure: I maintain ThreatCrush;
MIT and free. Written with AI assistance. Closing this is a fine answer and I
will not send another.