From 4fe2d8ef1cfce133dddac936f88cfb371257b511 Mon Sep 17 00:00:00 2001 From: yuli Date: Tue, 21 Jul 2026 18:33:12 +0300 Subject: [PATCH 1/2] Add Semgrep SAST workflow, pin CI actions, document security - Add semgrep.yml caller for the shared reusable SAST workflow - Pin checkout/setup-python (@v2 -> v4/v5 SHAs) across all jobs - Add Security section and Features bullet to README Co-Authored-By: Claude Opus 4.8 --- .github/workflows/ci.yml | 12 ++++++------ .github/workflows/semgrep.yml | 22 ++++++++++++++++++++++ README.md | 21 +++++++++++++++++++++ 3 files changed, 49 insertions(+), 6 deletions(-) create mode 100644 .github/workflows/semgrep.yml diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index c8545fc..ff6bf20 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -15,10 +15,10 @@ jobs: python-version: [3.9, '3.10'] steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: Set up Python ${{ matrix.python-version }} - uses: actions/setup-python@v2 + uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0 with: python-version: ${{ matrix.python-version }} @@ -38,10 +38,10 @@ jobs: lint: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: Set up Python - uses: actions/setup-python@v2 + uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0 with: python-version: '3.10' @@ -64,10 +64,10 @@ jobs: if: github.ref == 'refs/heads/main' runs-on: ubuntu-latest steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: Set up Python - uses: actions/setup-python@v2 + uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0 with: python-version: '3.10' diff --git a/.github/workflows/semgrep.yml b/.github/workflows/semgrep.yml new file mode 100644 index 0000000..2ad131a --- /dev/null +++ b/.github/workflows/semgrep.yml @@ -0,0 +1,22 @@ +# Caller: scans THIS repo using the shared reusable Semgrep workflow in databunker-devops. +# Ruleset = Python language pack + the common security packs (see semgrep-reusable.yml). +name: semgrep + +on: + workflow_dispatch: # manual "Run workflow" button in the Actions tab + pull_request: + push: + branches: [main] + schedule: + - cron: "13 7 * * 1" # weekly full sweep (Mon 07:13 UTC) — offset from gitleaks (06:27) + +permissions: + contents: read + security-events: write + +jobs: + sast: + name: sast # display + required-check name + uses: securitybunker/databunker-devops/.github/workflows/semgrep-reusable.yml@main + with: + config: "p/python p/secrets p/security-audit p/owasp-top-ten" diff --git a/README.md b/README.md index 7d82edb..59161d4 100644 --- a/README.md +++ b/README.md @@ -62,6 +62,7 @@ print(f"Created token in uuid format: {token_result['tokenuuid']}") - System Statistics - Type hints and comprehensive documentation - Error handling and validation +- Continuous security scanning (Semgrep SAST, pinned CI actions) ## Development @@ -83,6 +84,26 @@ pip install -e ".[dev]" pytest ``` +## Security + +This library is scanned on every push and pull request, with a weekly scheduled sweep to catch drift: + +- **SAST (Semgrep):** static analysis using the `p/python`, `p/secrets`, `p/security-audit`, and `p/owasp-top-ten` rulesets. A finding fails the check, and results are published to the repository's **Code Scanning** tab. See [`.github/workflows/semgrep.yml`](.github/workflows/semgrep.yml). +- **Supply-chain hardening:** every GitHub Action is pinned to a full commit SHA, so a mutable tag (`@v4`) cannot be silently repointed to malicious code. + +Reproduce the SAST scan locally: + +```bash +pip install semgrep +semgrep scan \ + --config p/python \ + --config p/secrets \ + --config p/security-audit \ + --config p/owasp-top-ten +``` + +To report a security vulnerability, please email hello@databunker.org rather than opening a public issue. + ## Contributing Contributions are welcome! Please feel free to submit a Pull Request. From b611707ce8b3c93e387fb5c3a64b248802e63268 Mon Sep 17 00:00:00 2001 From: yuli Date: Tue, 21 Jul 2026 18:59:12 +0300 Subject: [PATCH 2/2] Inline Semgrep workflow (public repo can't call private reusable workflow) GitHub blocks public repos from using a reusable workflow in a private repo, causing a startup_failure. Replace the caller with a self-contained scan. Co-Authored-By: Claude Opus 4.8 --- .github/workflows/semgrep.yml | 52 +++++++++++++++++++++++++++++++---- 1 file changed, 47 insertions(+), 5 deletions(-) diff --git a/.github/workflows/semgrep.yml b/.github/workflows/semgrep.yml index 2ad131a..9c87020 100644 --- a/.github/workflows/semgrep.yml +++ b/.github/workflows/semgrep.yml @@ -1,5 +1,7 @@ -# Caller: scans THIS repo using the shared reusable Semgrep workflow in databunker-devops. -# Ruleset = Python language pack + the common security packs (see semgrep-reusable.yml). +# Self-contained Semgrep SAST scan (Semgrep OSS engine + community rules — LGPL, no account needed). +# Inlined rather than calling the shared reusable workflow in databunker-devops, because GitHub +# blocks a PUBLIC repo from using a reusable workflow stored in a PRIVATE repo (org access does +# not lift this). Keep the ruleset in sync with the other public SDK repos. name: semgrep on: @@ -10,6 +12,8 @@ on: schedule: - cron: "13 7 * * 1" # weekly full sweep (Mon 07:13 UTC) — offset from gitleaks (06:27) +# Least privilege. security-events:write publishes SARIF to the Code Scanning tab (free on +# public repos). Semgrep itself needs no write scope. permissions: contents: read security-events: write @@ -17,6 +21,44 @@ permissions: jobs: sast: name: sast # display + required-check name - uses: securitybunker/databunker-devops/.github/workflows/semgrep-reusable.yml@main - with: - config: "p/python p/secrets p/security-audit p/owasp-top-ten" + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + + - name: Set up Python + uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0 + with: + python-version: "3.12" + + - name: Install Semgrep (pinned) + run: pip install semgrep==1.170.0 # bump deliberately (semgrep.dev/docs/release-notes) + + - name: Run Semgrep + env: + SEMGREP_SEND_METRICS: "off" # no telemetry; community rules only + run: | + # --error: exit non-zero on any finding -> blocks merge when set as a required check. + # SARIF is written before the non-zero exit, so the upload steps (if: always()) run. + semgrep scan \ + --config p/python \ + --config p/secrets \ + --config p/security-audit \ + --config p/owasp-top-ten \ + --error \ + --sarif --output semgrep.sarif + + - name: Upload SARIF to Code Scanning + if: always() # publish findings even when the scan fails the check + uses: github/codeql-action/upload-sarif@bb16b9baa2ec4010b29f5c606d57d01190139edd # v4.37.1 + with: + sarif_file: semgrep.sarif + category: semgrep + + - name: Upload SARIF artifact (dated evidence, retained 180d) + if: always() # keep the report for triage + audit evidence even on failure + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + with: + name: semgrep-report-${{ github.sha }} + path: semgrep.sarif + retention-days: 180