Skip to content

ci: security scanning, with the findings read and justified - #5

Merged
marcos-mendez merged 1 commit into
masterfrom
ci/security-scan
Oct 7, 2026
Merged

marcos-mendez merged 1 commit into
masterfrom
ci/security-scan

Conversation

@marcos-mendez

Copy link
Copy Markdown
Collaborator

Calls security-scan.yml of keel-linux/.github (gitleaks, bandit,
semgrep, shellcheck on hosted runners, no secrets) on pull requests,
pushes to master and by hand. Not a required check.

A scan of master finds no secret in the history, no Python, nothing
for semgrep, and two shellcheck warnings in tkldev-squid-refresh
(unquoted pid and find pattern, over root-owned squid files), justified
in .github/security-baseline.

Calls security-scan.yml of keel-linux/.github (gitleaks, bandit,
semgrep, shellcheck on hosted runners, no secrets) on pull requests,
pushes to master and by hand. Not a required check.

A scan of master finds no secret in the history, no Python, nothing
for semgrep, and two shellcheck warnings in tkldev-squid-refresh
(unquoted pid and find pattern, over root-owned squid files), justified
in .github/security-baseline.
@marcos-mendez
marcos-mendez merged commit ab4e6db into master Oct 7, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant