69 lines
2 KiB
YAML
69 lines
2 KiB
YAML
name: predeploy-security
|
|
|
|
# Runs on every PR/push to main and can be triggered manually before a deploy.
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
pull_request:
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: read
|
|
security-events: write
|
|
|
|
jobs:
|
|
secrets-scan:
|
|
name: Secret scanning
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: Scan for leaked secrets
|
|
uses: gitleaks/gitleaks-action@v2
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
shellcheck:
|
|
name: Lint deploy scripts
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: Run shellcheck on deploy scripts
|
|
run: |
|
|
shellcheck deploy/hardening.sh deploy/verify-hardening.sh
|
|
|
|
cargo-audit:
|
|
name: Dependency vulnerability audit
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: dtolnay/rust-toolchain@stable
|
|
- uses: Swatinem/rust-cache@v2
|
|
- name: Install cargo-audit
|
|
run: cargo install cargo-audit --locked
|
|
- name: Audit dependencies
|
|
run: cargo audit
|
|
|
|
build-release:
|
|
name: Release build check
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: dtolnay/rust-toolchain@stable
|
|
- uses: Swatinem/rust-cache@v2
|
|
- name: Build broadcast_server (release)
|
|
run: cargo build --release --features b_server --bin broadcast_server
|
|
env:
|
|
CARGO_TERM_COLOR: always
|
|
|
|
hardening-verify:
|
|
name: Verify hardening checks
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: Syntax-check hardening scripts
|
|
run: bash -n deploy/hardening.sh deploy/verify-hardening.sh
|
|
- name: Create mock environment and run verification
|
|
run: |
|
|
# Build a minimal fake environment to prove verify-hardening.sh is safe to run
|
|
# on a server and fails cleanly when nothing is hardened (non-root here).
|
|
bash deploy/verify-hardening.sh || echo "verify-hardening.sh correctly reported unhardened state (exit $?)"
|