Skip to content

Security: einyx/vector-storage-engine

Security

SECURITY.md

Security Scanning Setup

License

This repository is distributed under the Business Source License 1.1. Review LICENSE for the Additional Use Grant, Change Date, and Change License. Contributions are accepted under the same terms; see CONTRIBUTING.md.

Reporting security vulnerabilities

Report sensitive security issues privately (for example via GitHub Security Advisories or maintainer contact from the repository homepage) rather than in public issues. Include reproduction steps and affected versions when possible.


This project implements comprehensive security scanning using multiple tools to ensure code quality and security.

Security Tools

1. TruffleHog

  • Purpose: Detect and prevent secrets in git repos

2. Gosec

  • Purpose: Go security checker
  • Usage: make gosec
  • Output: gosec-report.json

3. Trivy

  • Purpose: Vulnerability scanner for containers and filesystems
  • Config: .trivyignore
  • Usage: make trivy

4. Semgrep

  • Purpose: Static analysis tool
  • Config: .semgrep.yml
  • Usage: make semgrep

5. Pre-commit Hooks

  • Config: .pre-commit-config.yaml
  • Includes:
    • Gitleaks for secret scanning
    • Go formatting and linting
    • Detect-secrets baseline
    • File fixes and checks

Quick Start

  1. Install all security tools:

    make install-security-tools
  2. Set up pre-commit hooks:

    make pre-commit-install
  3. Generate secrets baseline:

    make generate-secrets-baseline

Running Security Scans

Quick scan (development):

make quick-scan

Full security scan:

make security-check

All checks (test + security):

make check

Manual pre-commit run:

make pre-commit-run

GitHub Actions Integration

The .github/workflows/security.yml workflow runs automatically on:

  • Push to main/develop branches
  • Pull requests
  • Weekly schedule (Sunday midnight)

It includes:

  • Gitleaks secret scanning
  • Gosec security analysis
  • Trivy vulnerability scanning
  • Semgrep static analysis
  • CodeQL analysis
  • Dependency vulnerability checks
  • License compliance
  • SBOM generation

Security Best Practices

  1. Never commit secrets - Use environment variables or secret management tools
  2. Run pre-commit hooks - Catches issues before they're committed
  3. Review security reports - Check GitHub Security tab regularly
  4. Keep dependencies updated - Use go mod tidy and update regularly
  5. Follow secure coding practices - See .semgrep.yml for common patterns to avoid

Handling Security Issues

  1. If a secret is detected:

    • Immediately revoke the compromised credential
    • Remove from git history if needed
    • Update .gitleaks.toml allowlist if false positive
  2. If vulnerabilities are found:

    • Review the severity and impact
    • Update dependencies if patches available
    • Add to .trivyignore if risk accepted (with justification)
  3. For false positives:

    • Update tool configurations to exclude
    • Document the reason for exclusion
    • Regularly review exclusions

Local Development

Before pushing code:

# Run quick security scan
make quick-scan

# Run full test suite
make test

# Or run everything
make all

Additional Resources

There aren't any published security advisories