Skip to content

fix(sast): scope curl-pipe-shell off the declarative check corpus (#21) #143

fix(sast): scope curl-pipe-shell off the declarative check corpus (#21)

fix(sast): scope curl-pipe-shell off the declarative check corpus (#21) #143

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
permissions:
contents: read
env:
CARGO_TERM_COLOR: always
RUST_BACKTRACE: 1
jobs:
# -------------------------------------------------------------------------
# Test
# -------------------------------------------------------------------------
test:
name: Test (${{ matrix.toolchain }})
runs-on: ubuntu-latest
strategy:
matrix:
toolchain: [stable, nightly]
fail-fast: false
continue-on-error: ${{ matrix.toolchain == 'nightly' }}
steps:
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
persist-credentials: false
- name: Checkout grc-controls sibling
run: git clone --depth 1 "https://x-access-token:${GRC_TOKEN}@github.com/grcengineering/grc-controls.git" ../grc-controls
env:
GRC_TOKEN: ${{ secrets.GRC_CONTROLS_TOKEN }}
- uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # master
with:
toolchain: ${{ matrix.toolchain }}
- uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2
with:
key: ${{ matrix.toolchain }}
- name: Unit tests
run: cargo test --lib --bins
- name: Integration tests
run: cargo test --test integration
- name: E2E tests
if: matrix.toolchain == 'stable'
run: cargo test --test e2e
# -------------------------------------------------------------------------
# Security audit (cargo-audit)
# -------------------------------------------------------------------------
audit:
name: Security Audit
runs-on: ubuntu-latest
steps:
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
persist-credentials: false
- name: Checkout grc-controls sibling
run: git clone --depth 1 "https://x-access-token:${GRC_TOKEN}@github.com/grcengineering/grc-controls.git" ../grc-controls
env:
GRC_TOKEN: ${{ secrets.GRC_CONTROLS_TOKEN }}
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
- uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2
- name: Install cargo-audit
run: cargo install cargo-audit --locked
- name: Run audit
run: cargo audit
# -------------------------------------------------------------------------
# Supply chain audit (cargo-vet: dependency vetting)
# -------------------------------------------------------------------------
vet:
name: Supply Chain (cargo-vet)
runs-on: ubuntu-latest
steps:
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
persist-credentials: false
- name: Checkout grc-controls sibling
run: git clone --depth 1 "https://x-access-token:${GRC_TOKEN}@github.com/grcengineering/grc-controls.git" ../grc-controls
env:
GRC_TOKEN: ${{ secrets.GRC_CONTROLS_TOKEN }}
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
- uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2
- name: Install cargo-vet
run: cargo install cargo-vet --locked
- name: Run cargo-vet check
run: cargo vet check --locked
# -------------------------------------------------------------------------
# Supply chain (cargo-deny: licenses + advisories + bans + sources)
# -------------------------------------------------------------------------
deny:
name: Supply Chain (cargo-deny)
runs-on: ubuntu-latest
steps:
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
persist-credentials: false
- name: Checkout grc-controls sibling
run: git clone --depth 1 "https://x-access-token:${GRC_TOKEN}@github.com/grcengineering/grc-controls.git" ../grc-controls
env:
GRC_TOKEN: ${{ secrets.GRC_CONTROLS_TOKEN }}
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
- uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2
- name: Install cargo-deny
run: cargo install cargo-deny --locked
- name: Run cargo-deny check
run: cargo deny --all-features check all
# -------------------------------------------------------------------------
# Behavioral dependency analysis (Socket.dev)
# Activates only when SOCKET_SECURITY_API_KEY secret is configured.
# -------------------------------------------------------------------------
socket:
name: Behavioral Analysis (Socket.dev)
runs-on: ubuntu-latest
if: ${{ vars.SOCKET_ENABLED == 'true' }}
steps:
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
persist-credentials: false
- name: Run Socket.dev scan
uses: SocketDev/socket-sdk-js@7631a686c3eb51ec5a44b91059bb405f43348350 # v1.11.2
with:
api_key: ${{ secrets.SOCKET_SECURITY_API_KEY }}
# -------------------------------------------------------------------------
# Lint (clippy + fmt)
# -------------------------------------------------------------------------
lint:
name: Lint
runs-on: ubuntu-latest
steps:
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
persist-credentials: false
- name: Checkout grc-controls sibling
run: git clone --depth 1 "https://x-access-token:${GRC_TOKEN}@github.com/grcengineering/grc-controls.git" ../grc-controls
env:
GRC_TOKEN: ${{ secrets.GRC_CONTROLS_TOKEN }}
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
with:
components: clippy, rustfmt
- uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2
- run: cargo clippy -- -D warnings
- run: cargo fmt --check
# -------------------------------------------------------------------------
# Secrets detection (TruffleHog)
# -------------------------------------------------------------------------
secrets:
name: Secret Scanning (TruffleHog)
runs-on: ubuntu-latest
steps:
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
fetch-depth: 0
persist-credentials: false
- name: TruffleHog scan
uses: trufflesecurity/trufflehog@17456f8c7d042d8c82c9a8ca9e937231f9f42e26 # v3.95.2
with:
extra_args: --only-verified
# -------------------------------------------------------------------------
# SAST (Semgrep)
# -------------------------------------------------------------------------
semgrep:
name: SAST (Semgrep)
runs-on: ubuntu-latest
container:
image: semgrep/semgrep
steps:
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
persist-credentials: false
- name: Run Semgrep
run: semgrep scan --config auto --config p/rust --config p/owasp-top-ten --error --sarif --output semgrep.sarif .
- name: Upload SARIF
if: always()
uses: github/codeql-action/upload-sarif@865f5f5c36632f18690a3d569fa0a764f2da0c3e # v3
with:
sarif_file: semgrep.sarif
continue-on-error: true
# -------------------------------------------------------------------------
# Build matrix (Linux, macOS, Windows)
# -------------------------------------------------------------------------
build-linux:
name: Build (ubuntu-latest)
needs: [test, lint, audit, deny, vet]
runs-on: ubuntu-latest
steps:
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
persist-credentials: false
- name: Checkout grc-controls sibling
run: git clone --depth 1 "https://x-access-token:${GRC_TOKEN}@github.com/grcengineering/grc-controls.git" ../grc-controls
env:
GRC_TOKEN: ${{ secrets.GRC_CONTROLS_TOKEN }}
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
- uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2
with:
key: ubuntu-latest
- run: cargo build --release
build-macos:
name: Build (macos-latest)
needs: [test, lint, audit, deny, vet]
runs-on: macos-latest
steps:
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
persist-credentials: false
- name: Checkout grc-controls sibling
run: git clone --depth 1 "https://x-access-token:${GRC_TOKEN}@github.com/grcengineering/grc-controls.git" ../grc-controls
env:
GRC_TOKEN: ${{ secrets.GRC_CONTROLS_TOKEN }}
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
- uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2
with:
key: macos-latest
- run: cargo build --release
build-windows:
name: Build (windows-latest)
needs: [test, lint, audit, deny, vet]
runs-on: windows-latest
steps:
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
persist-credentials: false
- name: Checkout grc-controls sibling
run: git clone --depth 1 "https://x-access-token:${GRC_TOKEN}@github.com/grcengineering/grc-controls.git" ../grc-controls
env:
GRC_TOKEN: ${{ secrets.GRC_CONTROLS_TOKEN }}
shell: bash
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
- uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2
with:
key: windows-latest
- run: cargo build --release
# -------------------------------------------------------------------------
# Coverage gate (cargo-llvm-cov, Linux only)
# -------------------------------------------------------------------------
coverage:
name: Coverage (70% gate)
runs-on: ubuntu-latest
steps:
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
persist-credentials: false
- name: Checkout grc-controls sibling
run: git clone --depth 1 "https://x-access-token:${GRC_TOKEN}@github.com/grcengineering/grc-controls.git" ../grc-controls
env:
GRC_TOKEN: ${{ secrets.GRC_CONTROLS_TOKEN }}
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
with:
components: llvm-tools-preview
- uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2
- name: Install cargo-llvm-cov
run: cargo install cargo-llvm-cov --locked
- name: Run coverage with 70% gate
run: |
cargo llvm-cov \
--locked \
--all-features \
--workspace \
--ignore-run-fail \
--fail-under-lines 70 \
--lcov \
--output-path lcov.info
- name: Upload coverage to Codecov
uses: codecov/codecov-action@b9fd7d16f6d7d1b5d2bec1a2887e65ceed900238 # v4
with:
files: lcov.info
fail_ci_if_error: false
env:
CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}
# -------------------------------------------------------------------------
# HTH parity manifest consistency (no HTH checkout needed — validates the
# committed parity/hth-parity.json against checks/ + references.hth)
# -------------------------------------------------------------------------
parity:
name: HTH Parity Validate
runs-on: ubuntu-latest
steps:
- uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
persist-credentials: false
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
with:
python-version: '3.12'
- run: pip install pyyaml
- run: python3 scripts/hth_parity.py --validate