Files
Coworker/.gitea/workflows/security-scan.yml
MrSphay 2ec18964b7
Some checks failed
Codex Template Compliance / compliance (push) Successful in 7s
Release Dry Run / release-dry-run (push) Failing after 44s
Build / build (push) Failing after 45s
Initial Coworker app scaffold
2026-06-19 01:07:16 +02:00

31 lines
790 B
YAML

name: Scheduled Security Scan
on:
schedule:
- cron: "17 3 * * 1"
workflow_dispatch:
jobs:
security-scan:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Scan suspicious patterns
run: |
rg -n "eval\\(|new Function|innerHTML\\s*=|shell:\\s*true|LOCALHOST_BYPASS|coworker_token" apps packages docs || true
- name: Scan secret-prone files
run: |
if find . -type f \( -name ".env" -o -name "*.pem" -o -name "*.pfx" -o -name "*.p12" -o -name "*.key" \) | rg .; then
echo "Secret-prone file is tracked or present in workspace"
exit 1
fi
- name: Install dependencies
run: npm install
- name: Audit
run: npm run audit