Skip to content

Fix security workflow findings from the first real trial - #2

Merged
PavlosIsaris merged 1 commit into
mainfrom
fix-security-trial
Sep 30, 2026
Merged

PavlosIsaris merged 1 commit into
mainfrom
fix-security-trial

Conversation

@PavlosIsaris

Copy link
Copy Markdown
Contributor

The first real run of security.yml@v0.1 (in annotation-management-system) found two bugs. This repository has no composer.lock and no env template at its root, so the self-check could not see them.

  • Dependency audit: Composer 2.10 refuses composer audit without vendor/. The job now runs composer audit --locked, which reads composer.lock directly.
  • Secrets: the env file check flagged .github/templates/.env.j2, a Jinja deployment template. Template suffixes (.dist, .sample, .template, .tpl, .j2, .jinja, .jinja2) are now allowed. Real env files such as .env or .env.production still fail.

Also:

  • working-directory input for the npm hardening and audit checks, and in verify-npm-hardening.
  • New fixture tests/fixtures/security/ with no dependencies: lock files, a hardened .npmrc and a Jinja .env template. The self-check runs security.yml against it.
  • README: releases get an immutable tag (v0.1.1), and the short tag v0.1 moves to the latest release.

Release plan after merge: tag v0.1.1 and move v0.1 to it.

- composer audit: use --locked; Composer 2.10 refuses to audit without
  vendor/ otherwise
- Env file check: allow template suffixes (.dist, .sample, .template, .tpl,
  .j2, .jinja, .jinja2); the trial flagged a Jinja deployment template
- Add working-directory for the npm hardening and audit checks
- Self-check: run security.yml on a fixture with lock files and an env
  template, so both cases are covered
- README: document the moving short tag and immutable release tags
@PavlosIsaris
PavlosIsaris merged commit d339302 into main Sep 30, 2026
28 checks passed
@PavlosIsaris
PavlosIsaris deleted the fix-security-trial branch September 30, 2026 08:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant