Skip to content

ci: security scanning, with the findings read and justified - #12

Merged
marcos-mendez merged 1 commit into
masterfrom
ci/security-scan
Oct 7, 2026
Merged

marcos-mendez merged 1 commit into
masterfrom
ci/security-scan

Conversation

@marcos-mendez

Copy link
Copy Markdown
Collaborator

Calls security-scan.yml of keel-linux/.github (gitleaks, bandit,
semgrep, shellcheck on hosted runners, no secrets) on pull requests,
pushes to master and by hand. Not a required check.

Baseline from a scan of master, none a risk. B103 and semgrep's
insecure-file-permissions: 0755 on scripts that must run in the build
chroot. B324 and semgrep's MD5 rule: md5 keys a dict of comments, and
fills the MD5sum field of a local Packages index beside SHA256. Plus six
shellcheck warnings in share/initctl.dummy. gitleaks finds nothing.

Calls security-scan.yml of keel-linux/.github (gitleaks, bandit,
semgrep, shellcheck on hosted runners, no secrets) on pull requests,
pushes to master and by hand. Not a required check.

Baseline from a scan of master, none a risk. B103 and semgrep's
insecure-file-permissions: 0755 on scripts that must run in the build
chroot. B324 and semgrep's MD5 rule: md5 keys a dict of comments, and
fills the MD5sum field of a local Packages index beside SHA256. Plus six
shellcheck warnings in share/initctl.dummy. gitleaks finds nothing.
@marcos-mendez
marcos-mendez merged commit e9af9ed into master Oct 7, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant