Skip to content

Add Socket Basics security scanning workflow - #386

Open
kanwalpreetd wants to merge 1 commit into
stellar:mainfrom
kanwalpreetd:main
Open

kanwalpreetd wants to merge 1 commit into
stellar:mainfrom
kanwalpreetd:main

Conversation

@kanwalpreetd

@kanwalpreetd kanwalpreetd commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

@kanwalpreetd
kanwalpreetd force-pushed the main branch 4 times, most recently from 4cb9726 to 1148328 Compare September 26, 2026 01:30
@kanwalpreetd
kanwalpreetd marked this pull request as ready for review September 28, 2026 12:40
Copilot AI lite review requested due to automatic review settings September 28, 2026 12:40

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved workflow failure-handling and timeout issues block approval.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Adds scheduled/manual Socket Basics scanning for SAST, secrets, and Dockerfile issues.

Changes:

  • Adds scanner configuration and exclusions.
  • Adds Trivy and Semgrep ignore files.
  • Adds a pinned GitHub Actions workflow with annotations.

Review findings include a critical false-success path, a moderate missing job timeout, and a nit regarding inaccurate Trivy documentation.

File Description
.trivyignore Defines excluded Dockerfile rules.
.socket-basics.json Configures Socket Basics scanners and exclusions.
.semgrepignore Defines SAST scan exclusions.
.github/​workflows/​socket-basics.yml Runs the scheduled Socket Basics scan.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/socket-basics.yml Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The workflow may expose the GitHub token to the scanner container, and secret scanning exclusions are overly broad.

Review effort: Lite
Findings: 1 High severity

Open (1)
Resolved since last review (1)

Comment thread .github/workflows/socket-basics.yml
Copilot AI review requested due to automatic review settings September 29, 2026 08:53

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The workflow must fail on scanner errors that occur after partial output.

Review effort: Lite
Findings: 2 High severity

Open (2)

Comment thread .github/workflows/socket-basics.yml Outdated
Copilot AI lite review requested due to automatic review settings September 29, 2026 22:06

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review issues were identified.

Review effort: Lite
Findings: 1 High severity

Open (1)
Resolved since last review (1)

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The workflow contains two unresolved moderate validation issues.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
Resolved since last review (1)

Comment thread .github/workflows/socket-basics.yml Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

All reviewed changes are covered with no unresolved blocking issues.

Review effort: Lite
Findings: None

Resolved since last review (1)

Copilot AI lite review requested due to automatic review settings October 2, 2026 01:51

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved blocking issues were identified.

Review effort: Lite
Findings: None

Runs SAST through OpenGrep, secret scanning through TruffleHog, and
Dockerfile misconfiguration scanning through Trivy, submitting results
to Socket.dev.

  .github/workflows/socket-basics.yml  scheduled weekly + manual dispatch
  .socket-basics.json                  scanner configuration
  .semgrepignore                       SAST path exclusions
  .trivyignore                         Dockerfile lint rules with no
                                       security dimension (only present
                                       where the repo has a Dockerfile)

Separate from socket-scan.yml, which covers dependency CVEs and Tier 1
reachability.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings October 2, 2026 02:26

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved blocking issues were identified.

Review effort: Lite
Findings: None

@jeesunikim

Copy link
Copy Markdown
Contributor

@kanwalpreetd pr preview is failing

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants