From 713d531f5c58354518149b11927104fd13a0ff17 Mon Sep 17 00:00:00 2001 From: Kanwalpreet Dhindsa Date: Thu, 17 Sep 2026 09:53:10 -0700 Subject: [PATCH] Add Socket Basics security scanning workflow Runs SAST through OpenGrep, secret scanning through TruffleHog, and Dockerfile misconfiguration scanning through Trivy, submitting results to Socket.dev. .github/workflows/socket-basics.yml scheduled weekly + manual dispatch .socket-basics.json scanner configuration .semgrepignore SAST path exclusions .trivyignore Dockerfile lint rules with no security dimension (only present where the repo has a Dockerfile) Separate from socket-scan.yml, which covers dependency CVEs and Tier 1 reachability. Co-Authored-By: Claude Opus 5 --- .github/workflows/socket-basics.yml | 49 +++++++++++++ .semgrepignore | 107 ++++++++++++++++++++++++++++ .socket-basics.json | 11 +++ .trivyignore | 27 +++++++ 4 files changed, 194 insertions(+) create mode 100644 .github/workflows/socket-basics.yml create mode 100644 .semgrepignore create mode 100644 .socket-basics.json create mode 100644 .trivyignore diff --git a/.github/workflows/socket-basics.yml b/.github/workflows/socket-basics.yml new file mode 100644 index 000000000..aed1633b3 --- /dev/null +++ b/.github/workflows/socket-basics.yml @@ -0,0 +1,49 @@ +# Socket Basics security scan for stellar-docs. +# Upstream: https://github.com/SocketDev/socket-basics +# Scanner settings live in .socket-basics.json; SAST path exclusions live in +# .semgrepignore. +# +# This workflow does SAST through OpenGrep, secret scanning through TruffleHog, +# Dockerfile misconfiguration scanning through Trivy, and submits results to +# Socket.dev + +name: Socket Basics security scan + +on: + workflow_dispatch: + schedule: + - cron: "42 14 * * 6" + +permissions: + contents: read + +jobs: + socket-basics: + runs-on: ubuntu-latest + timeout-minutes: 30 + steps: + - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 + with: + # Remove the GitHub token from the workspace after checkout, so it is + # not mounted into the Socket Basics container, which doesn't need it. + persist-credentials: false + + - name: Run Socket Basics + env: + SOCKET_SECURITY_API_TOKEN: ${{ secrets.SOCKET_SECURITY_API_TOKEN }} + SOCKET_ORG: stellar + run: | + # Socket Basics is pinned by digest since rule tuning is calibrated + # to the exact ruleset contained in this image. Automatic updates + # could introduce new rules and a sudden increase in false + # positives, as these tools are generally noisy without tuning. + docker run --rm \ + -v "$PWD:/github/workspace" \ + -w /github/workspace \ + -e SOCKET_SECURITY_API_TOKEN \ + -e SOCKET_ORG \ + -e GITHUB_REPOSITORY \ + -e GITHUB_REF_NAME \ + -e GITHUB_SHA \ + ghcr.io/socketdev/socket-basics@sha256:d463bae84f21d0240d5e197acb81e95144a966a20ab7cd05cca3a70e1796a4bb \ + --config .socket-basics.json diff --git a/.semgrepignore b/.semgrepignore new file mode 100644 index 000000000..6da5e00d0 --- /dev/null +++ b/.semgrepignore @@ -0,0 +1,107 @@ +# This file excludes scan paths from Socket Basics SAST scanning (through OpenGrep). +# It replaces the built-in ignore list for scanning with a more thorough list of paths. + +# --- third-party / generated --- +.git/ +node_modules/ +vendor/ +third_party/ +thirdparty/ +.devcontainer/ +dist/ +build/ +target/ +.venv/ +venv/ +__pycache__/ +.yarn/ +generated/ +*.min.js + +# --- test / example / mock code --- +__fixtures__/ +__mocks__/ +__snapshots__/ +__tests__/ +acceptance-test/ +acceptance-tests/ +acceptance_test/ +acceptance_tests/ +benches/ +browser-test/ +browser-tests/ +browser_test/ +browser_tests/ +e2e/ +e2e-test/ +e2e-tests/ +e2e_test/ +e2e_tests/ +example/ +examples/ +fixtures/ +functional-test/ +functional-tests/ +functional_test/ +functional_tests/ +integration-test/ +integration-tests/ +integration_test/ +integration_tests/ +integrationtest/ +integrationtests/ +mock/ +mock-dapp/ +mocks/ +perf-test/ +perf-tests/ +perf_test/ +perf_tests/ +performance-test/ +performance-tests/ +performance_test/ +performance_tests/ +regression-test/ +regression-tests/ +regression_test/ +regression_tests/ +smoke-test/ +smoke-tests/ +smoke_test/ +smoke_tests/ +spec/ +specs/ +test/ +test-data/ +test-fixtures/ +testFixtures/ +testdata/ +testfixtures/ +tests/ +unit-test/ +unit-tests/ +unit_test/ +unit_tests/ +*.test.js +*.test.jsx +*.test.ts +*.test.tsx +*.test.mjs +*.spec.js +*.spec.jsx +*.spec.ts +*.spec.tsx +*_test.go +*_test.py +*_test.rb +*_test.exs +test_*.py +*Test.java +*Tests.java +*Test.kt +*Tests.kt +*Test.scala +*Test.cs +*Tests.cs +tests.rs +test.rs diff --git a/.socket-basics.json b/.socket-basics.json new file mode 100644 index 000000000..92bbbcf28 --- /dev/null +++ b/.socket-basics.json @@ -0,0 +1,11 @@ +{ + "workspace": ".", + "javascript_sast_enabled": true, + "sast_ignore_overrides": "js-express-async-no-error-handler:src/components/CodeExample.tsx,js-express-async-no-error-handler:src/components/WalletCodeExample.tsx,js-sensitive-data-in-logs:scripts/stellar_cli_plugins.mjs,js-unhandled-promise-rejection:docusaurus.config.ts,js-unhandled-promise-rejection:openrpc/scripts/build.mjs,js-unhandled-promise-rejection:openrpc/scripts/validate.mjs,js-unhandled-promise-rejection:src/clientModules/webmcp.ts,js-unhandled-promise-rejection:src/sidebar-generator.js", + "secret_scanning_enabled": true, + "console_tabular_enabled": true, + "dockerfiles": "Dockerfile", + "socket_tier_1_enabled": false, + "trivy_vuln_enabled": false, + "trufflehog_exclude_dir": "node_modules,dist,build,.git,yarn.lock,package-lock.json,pnpm-lock.yaml,Cargo.lock,go.sum,poetry.lock,Gemfile.lock,composer.lock,docs/platforms/stellar-disbursement-platform/api-reference/log-in.StatusCodes.json,docs/platforms/stellar-disbursement-platform/api-reference/refresh-token.StatusCodes.json,openapi/stellar-disbursement-platform/bundled.yaml,openapi/stellar-disbursement-platform/main.yaml,docs/platforms/anchor-platform/api-reference/callbacks/put-customer.api.mdx,docs/data/apis/horizon/api-reference/list-all-operations.api.mdx,docusaurus.config.ts" +} diff --git a/.trivyignore b/.trivyignore new file mode 100644 index 000000000..2857632dc --- /dev/null +++ b/.trivyignore @@ -0,0 +1,27 @@ +# This file excludes non-security rules from Socket Basics Dockerfile scanning (through Trivy). +# +# Trivy reads this file from the working directory. socket-basics has no config +# key that can disable a Trivy rule, so this is the only lever. +# +# Rules that ARE kept: DS-0002 (no USER - runs as root), DS-0001 (:latest tag), +# DS-0017 (package-manager update alone, which can install from a stale index). + +# Excluded rules: + +# 'apt-get' missing '--no-install-recommends' +DS-0029 + +# 'RUN cd ...' instead of WORKDIR +DS-0013 + +# Deprecated MAINTAINER instruction +DS-0022 + +# 'apk add' missing '--no-cache' +DS-0025 + +# WORKDIR path not absolute +DS-0009 + +# 'apt-get' missing '-y' +DS-0021