fix(sast): scope curl-pipe-shell off the declarative check corpus (#21) #143
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| permissions: | |
| contents: read | |
| env: | |
| CARGO_TERM_COLOR: always | |
| RUST_BACKTRACE: 1 | |
| jobs: | |
| # ------------------------------------------------------------------------- | |
| # Test | |
| # ------------------------------------------------------------------------- | |
| test: | |
| name: Test (${{ matrix.toolchain }}) | |
| runs-on: ubuntu-latest | |
| strategy: | |
| matrix: | |
| toolchain: [stable, nightly] | |
| fail-fast: false | |
| continue-on-error: ${{ matrix.toolchain == 'nightly' }} | |
| steps: | |
| - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 | |
| with: | |
| egress-policy: audit | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | |
| with: | |
| persist-credentials: false | |
| - name: Checkout grc-controls sibling | |
| run: git clone --depth 1 "https://x-access-token:${GRC_TOKEN}@github.com/grcengineering/grc-controls.git" ../grc-controls | |
| env: | |
| GRC_TOKEN: ${{ secrets.GRC_CONTROLS_TOKEN }} | |
| - uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # master | |
| with: | |
| toolchain: ${{ matrix.toolchain }} | |
| - uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2 | |
| with: | |
| key: ${{ matrix.toolchain }} | |
| - name: Unit tests | |
| run: cargo test --lib --bins | |
| - name: Integration tests | |
| run: cargo test --test integration | |
| - name: E2E tests | |
| if: matrix.toolchain == 'stable' | |
| run: cargo test --test e2e | |
| # ------------------------------------------------------------------------- | |
| # Security audit (cargo-audit) | |
| # ------------------------------------------------------------------------- | |
| audit: | |
| name: Security Audit | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 | |
| with: | |
| egress-policy: audit | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | |
| with: | |
| persist-credentials: false | |
| - name: Checkout grc-controls sibling | |
| run: git clone --depth 1 "https://x-access-token:${GRC_TOKEN}@github.com/grcengineering/grc-controls.git" ../grc-controls | |
| env: | |
| GRC_TOKEN: ${{ secrets.GRC_CONTROLS_TOKEN }} | |
| - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable | |
| - uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2 | |
| - name: Install cargo-audit | |
| run: cargo install cargo-audit --locked | |
| - name: Run audit | |
| run: cargo audit | |
| # ------------------------------------------------------------------------- | |
| # Supply chain audit (cargo-vet: dependency vetting) | |
| # ------------------------------------------------------------------------- | |
| vet: | |
| name: Supply Chain (cargo-vet) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 | |
| with: | |
| egress-policy: audit | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | |
| with: | |
| persist-credentials: false | |
| - name: Checkout grc-controls sibling | |
| run: git clone --depth 1 "https://x-access-token:${GRC_TOKEN}@github.com/grcengineering/grc-controls.git" ../grc-controls | |
| env: | |
| GRC_TOKEN: ${{ secrets.GRC_CONTROLS_TOKEN }} | |
| - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable | |
| - uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2 | |
| - name: Install cargo-vet | |
| run: cargo install cargo-vet --locked | |
| - name: Run cargo-vet check | |
| run: cargo vet check --locked | |
| # ------------------------------------------------------------------------- | |
| # Supply chain (cargo-deny: licenses + advisories + bans + sources) | |
| # ------------------------------------------------------------------------- | |
| deny: | |
| name: Supply Chain (cargo-deny) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 | |
| with: | |
| egress-policy: audit | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | |
| with: | |
| persist-credentials: false | |
| - name: Checkout grc-controls sibling | |
| run: git clone --depth 1 "https://x-access-token:${GRC_TOKEN}@github.com/grcengineering/grc-controls.git" ../grc-controls | |
| env: | |
| GRC_TOKEN: ${{ secrets.GRC_CONTROLS_TOKEN }} | |
| - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable | |
| - uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2 | |
| - name: Install cargo-deny | |
| run: cargo install cargo-deny --locked | |
| - name: Run cargo-deny check | |
| run: cargo deny --all-features check all | |
| # ------------------------------------------------------------------------- | |
| # Behavioral dependency analysis (Socket.dev) | |
| # Activates only when SOCKET_SECURITY_API_KEY secret is configured. | |
| # ------------------------------------------------------------------------- | |
| socket: | |
| name: Behavioral Analysis (Socket.dev) | |
| runs-on: ubuntu-latest | |
| if: ${{ vars.SOCKET_ENABLED == 'true' }} | |
| steps: | |
| - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 | |
| with: | |
| egress-policy: audit | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | |
| with: | |
| persist-credentials: false | |
| - name: Run Socket.dev scan | |
| uses: SocketDev/socket-sdk-js@7631a686c3eb51ec5a44b91059bb405f43348350 # v1.11.2 | |
| with: | |
| api_key: ${{ secrets.SOCKET_SECURITY_API_KEY }} | |
| # ------------------------------------------------------------------------- | |
| # Lint (clippy + fmt) | |
| # ------------------------------------------------------------------------- | |
| lint: | |
| name: Lint | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 | |
| with: | |
| egress-policy: audit | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | |
| with: | |
| persist-credentials: false | |
| - name: Checkout grc-controls sibling | |
| run: git clone --depth 1 "https://x-access-token:${GRC_TOKEN}@github.com/grcengineering/grc-controls.git" ../grc-controls | |
| env: | |
| GRC_TOKEN: ${{ secrets.GRC_CONTROLS_TOKEN }} | |
| - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable | |
| with: | |
| components: clippy, rustfmt | |
| - uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2 | |
| - run: cargo clippy -- -D warnings | |
| - run: cargo fmt --check | |
| # ------------------------------------------------------------------------- | |
| # Secrets detection (TruffleHog) | |
| # ------------------------------------------------------------------------- | |
| secrets: | |
| name: Secret Scanning (TruffleHog) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 | |
| with: | |
| egress-policy: audit | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | |
| with: | |
| fetch-depth: 0 | |
| persist-credentials: false | |
| - name: TruffleHog scan | |
| uses: trufflesecurity/trufflehog@17456f8c7d042d8c82c9a8ca9e937231f9f42e26 # v3.95.2 | |
| with: | |
| extra_args: --only-verified | |
| # ------------------------------------------------------------------------- | |
| # SAST (Semgrep) | |
| # ------------------------------------------------------------------------- | |
| semgrep: | |
| name: SAST (Semgrep) | |
| runs-on: ubuntu-latest | |
| container: | |
| image: semgrep/semgrep | |
| steps: | |
| - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 | |
| with: | |
| egress-policy: audit | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | |
| with: | |
| persist-credentials: false | |
| - name: Run Semgrep | |
| run: semgrep scan --config auto --config p/rust --config p/owasp-top-ten --error --sarif --output semgrep.sarif . | |
| - name: Upload SARIF | |
| if: always() | |
| uses: github/codeql-action/upload-sarif@865f5f5c36632f18690a3d569fa0a764f2da0c3e # v3 | |
| with: | |
| sarif_file: semgrep.sarif | |
| continue-on-error: true | |
| # ------------------------------------------------------------------------- | |
| # Build matrix (Linux, macOS, Windows) | |
| # ------------------------------------------------------------------------- | |
| build-linux: | |
| name: Build (ubuntu-latest) | |
| needs: [test, lint, audit, deny, vet] | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 | |
| with: | |
| egress-policy: audit | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | |
| with: | |
| persist-credentials: false | |
| - name: Checkout grc-controls sibling | |
| run: git clone --depth 1 "https://x-access-token:${GRC_TOKEN}@github.com/grcengineering/grc-controls.git" ../grc-controls | |
| env: | |
| GRC_TOKEN: ${{ secrets.GRC_CONTROLS_TOKEN }} | |
| - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable | |
| - uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2 | |
| with: | |
| key: ubuntu-latest | |
| - run: cargo build --release | |
| build-macos: | |
| name: Build (macos-latest) | |
| needs: [test, lint, audit, deny, vet] | |
| runs-on: macos-latest | |
| steps: | |
| - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 | |
| with: | |
| egress-policy: audit | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | |
| with: | |
| persist-credentials: false | |
| - name: Checkout grc-controls sibling | |
| run: git clone --depth 1 "https://x-access-token:${GRC_TOKEN}@github.com/grcengineering/grc-controls.git" ../grc-controls | |
| env: | |
| GRC_TOKEN: ${{ secrets.GRC_CONTROLS_TOKEN }} | |
| - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable | |
| - uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2 | |
| with: | |
| key: macos-latest | |
| - run: cargo build --release | |
| build-windows: | |
| name: Build (windows-latest) | |
| needs: [test, lint, audit, deny, vet] | |
| runs-on: windows-latest | |
| steps: | |
| - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 | |
| with: | |
| egress-policy: audit | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | |
| with: | |
| persist-credentials: false | |
| - name: Checkout grc-controls sibling | |
| run: git clone --depth 1 "https://x-access-token:${GRC_TOKEN}@github.com/grcengineering/grc-controls.git" ../grc-controls | |
| env: | |
| GRC_TOKEN: ${{ secrets.GRC_CONTROLS_TOKEN }} | |
| shell: bash | |
| - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable | |
| - uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2 | |
| with: | |
| key: windows-latest | |
| - run: cargo build --release | |
| # ------------------------------------------------------------------------- | |
| # Coverage gate (cargo-llvm-cov, Linux only) | |
| # ------------------------------------------------------------------------- | |
| coverage: | |
| name: Coverage (70% gate) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 | |
| with: | |
| egress-policy: audit | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | |
| with: | |
| persist-credentials: false | |
| - name: Checkout grc-controls sibling | |
| run: git clone --depth 1 "https://x-access-token:${GRC_TOKEN}@github.com/grcengineering/grc-controls.git" ../grc-controls | |
| env: | |
| GRC_TOKEN: ${{ secrets.GRC_CONTROLS_TOKEN }} | |
| - uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable | |
| with: | |
| components: llvm-tools-preview | |
| - uses: Swatinem/rust-cache@42dc69e1aa15d09112580998cf2ef0119e2e91ae # v2 | |
| - name: Install cargo-llvm-cov | |
| run: cargo install cargo-llvm-cov --locked | |
| - name: Run coverage with 70% gate | |
| run: | | |
| cargo llvm-cov \ | |
| --locked \ | |
| --all-features \ | |
| --workspace \ | |
| --ignore-run-fail \ | |
| --fail-under-lines 70 \ | |
| --lcov \ | |
| --output-path lcov.info | |
| - name: Upload coverage to Codecov | |
| uses: codecov/codecov-action@b9fd7d16f6d7d1b5d2bec1a2887e65ceed900238 # v4 | |
| with: | |
| files: lcov.info | |
| fail_ci_if_error: false | |
| env: | |
| CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }} | |
| # ------------------------------------------------------------------------- | |
| # HTH parity manifest consistency (no HTH checkout needed — validates the | |
| # committed parity/hth-parity.json against checks/ + references.hth) | |
| # ------------------------------------------------------------------------- | |
| parity: | |
| name: HTH Parity Validate | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 | |
| with: | |
| egress-policy: audit | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | |
| with: | |
| persist-credentials: false | |
| - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0 | |
| with: | |
| python-version: '3.12' | |
| - run: pip install pyyaml | |
| - run: python3 scripts/hth_parity.py --validate |