This repository was archived by the owner on Sep 28, 2026. It is now read-only.
Repository navigation
98 lines (81 loc) · 3.61 KB
/
Copy pathSecurity-Reachability.yml
File metadata and controls
98 lines (81 loc) · 3.61 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
# Display Name of the workflow
name: Static Analysis - CVE Reachability Scan
# When this workflow triggers
on:
# Run by hand
workflow_dispatch: # Run on PR
# Run when PR is raised to protected branches
pull_request:
branches: [main]
# Run on a schedule (weekly) to ensure scan with latest definitions
schedule:
- cron: '59 23 * * 0' # Weekly on Sundays at midnight
# Only allow one scan to run at a time
concurrency:
group: socket-scan-${{ github.ref }}-${{ github.sha }}
cancel-in-progress: true
# Define each session of execution that should be executed
jobs:
socket-security:
# Display name of the job
name: Compute Tier-1 Reachability
# Configures the filter for which operating system that should be used when selecting runners
runs-on: ubuntu-latest
# Sets the scopes available to the github_token injected to the GH Actions runner
permissions:
issues: write
contents: read
pull-requests: write
# Set of commands to run to compute the reachability of CVEs in the codebase
steps:
# Downloads the repo at the specified depth calculated previously
- name: Clone Repo
uses: actions/checkout@v7
with:
# For PRs, fetch one additional commit for proper diff analysis
fetch-depth: ${{ github.event_name == 'pull_request' && 2 || 0 }}
# Read the package's minimum supported runtime so CI validates the lowest common denominator.
- name: Read Required Node.JS Runtime
id: node-runtime
run: echo "runtime=$(node ./scripts/get-minimum-node-runtime.ts)" >> "$GITHUB_OUTPUT"
# Set up NodeJS on the build host with caching support to optimize execution
- name: Set up Node.js
uses: actions/setup-node@v6
background: true
with:
node-version: ${{ steps.node-runtime.outputs.runtime }}
# Set up Python runtime on the build host
- name: Set up Python
uses: actions/setup-python@v6
background: true
with:
python-version: '3.14'
# Set up the socket firewall binary
- name: Install - Socket Firewall
uses: SocketDev/action@ba6de6cc0565af1f42295590380973573297e31f
background: true
with:
mode: firewall-free
# Bring job back to sync execution by awaiting for all async jobs to finish before continuing
- name: Steps - Convert Back To Synchronous Execution - Environment Setup
wait-all: true
# Update the NPM CLI to the latest available version
- name: Update NPM CLI
background: true
run: sfw npm install -g npm
# Install the Socket CLI tool using pip and ensure it's up to date.
# The local validate:package command maintains this pin using the latest non-yanked stable
# release that has been available on PyPI for at least 24 hours. CI runs the corresponding
# validate:package:skip-reachability command so workflow validation does not modify its checkout.
- name: Install Socket CLI
background: true
run: sfw pip install socketsecurity==2.10.0 uv --upgrade
# Bring job back to sync execution by awaiting for all async jobs to finish before continuing
- name: Steps - Convert Back To Synchronous Execution - Packages Updates/Setup
wait-all: true
# Run the reachability scan
- name: Run Socket Security Scan
env:
SOCKET_SECURITY_API_KEY: ${{ secrets.SOCKET_REACHABILITY }}
GH_API_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: socketcli --target-path $GITHUB_WORKSPACE --scm github --pr-number ${{ github.event.pull_request.number || 0 }} --reach