Menu ▾ ▴

#12 ci: scan pull requests for credentials and injection with ThreatCrush

open
nobody
None
2026-09-21
2026-09-21
Anonymous
No

Originally created by: ralyodio

Adds one workflow. On each pull request it scans the checked-out repository for
hardcoded credentials, injection, SSRF and unsafe deserialisation.

  • .github/workflows/threatcrush-scan.yml

Findings go to the Security tab and a pull request comment. If you would rather
not grant those write scopes, say so and I will send the contents: read build:
same scan, findings in the job summary and a SARIF artifact, and the two steps
that need a write scope removed from the file rather than switched off.

Report-only. failOn is empty, so findings never fail the build. An install
or scan failure does fail the job: a scanner that reports clean when it did not
run is worse than no scanner.

Pre-existing findings. The report leads with findings in the files the pull
request changes and folds the rest of the repository behind a <details> summary,
so an existing backlog is visible without being posted at the author of an
unrelated change. Anything intentional can be excluded with a .threatcrushignore
or a // threatcrush-disable-next-line <rule-id> comment.

Scope: it scans the whole checked-out repository, not only the diff.

Supply chain. Pinned to @profullstack/threatcrush@0.11.9; the tarball is hashed and checked against
a value in the workflow before install (npm view it yourself), installed with
--ignore-scripts, actions pinned to commit SHAs, and it runs on pull_request
rather than pull_request_target.

Asked first in https://github.com/imshaikot/browsentic/issues/11.

Disclosure: I maintain ThreatCrush;
MIT and free. Written with AI assistance. Closing this is a fine answer and I
will not send another.

Discussion


Log in to post a comment.