This repository is distributed under the Business Source License 1.1. Review LICENSE for the Additional Use Grant, Change Date, and Change License. Contributions are accepted under the same terms; see CONTRIBUTING.md.
Report sensitive security issues privately (for example via GitHub Security Advisories or maintainer contact from the repository homepage) rather than in public issues. Include reproduction steps and affected versions when possible.
This project implements comprehensive security scanning using multiple tools to ensure code quality and security.
- Purpose: Detect and prevent secrets in git repos
- Purpose: Go security checker
- Usage:
make gosec - Output:
gosec-report.json
- Purpose: Vulnerability scanner for containers and filesystems
- Config:
.trivyignore - Usage:
make trivy
- Purpose: Static analysis tool
- Config:
.semgrep.yml - Usage:
make semgrep
- Config:
.pre-commit-config.yaml - Includes:
- Gitleaks for secret scanning
- Go formatting and linting
- Detect-secrets baseline
- File fixes and checks
-
Install all security tools:
make install-security-tools
-
Set up pre-commit hooks:
make pre-commit-install
-
Generate secrets baseline:
make generate-secrets-baseline
make quick-scanmake security-checkmake checkmake pre-commit-runThe .github/workflows/security.yml workflow runs automatically on:
- Push to main/develop branches
- Pull requests
- Weekly schedule (Sunday midnight)
It includes:
- Gitleaks secret scanning
- Gosec security analysis
- Trivy vulnerability scanning
- Semgrep static analysis
- CodeQL analysis
- Dependency vulnerability checks
- License compliance
- SBOM generation
- Never commit secrets - Use environment variables or secret management tools
- Run pre-commit hooks - Catches issues before they're committed
- Review security reports - Check GitHub Security tab regularly
- Keep dependencies updated - Use
go mod tidyand update regularly - Follow secure coding practices - See
.semgrep.ymlfor common patterns to avoid
-
If a secret is detected:
- Immediately revoke the compromised credential
- Remove from git history if needed
- Update
.gitleaks.tomlallowlist if false positive
-
If vulnerabilities are found:
- Review the severity and impact
- Update dependencies if patches available
- Add to
.trivyignoreif risk accepted (with justification)
-
For false positives:
- Update tool configurations to exclude
- Document the reason for exclusion
- Regularly review exclusions
Before pushing code:
# Run quick security scan
make quick-scan
# Run full test suite
make test
# Or run everything
make all