Repository navigation
Add full Snyk security pipeline (SCA + SAST + IaC + Container) with d… #10
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Snyk Full Security Pipeline (SCA + SAST + IaC + Container) | |
| on: | |
| push: | |
| branches: [ main, master ] | |
| workflow_dispatch: | |
| env: | |
| SNYK_ORG: "2c2549f7-de55-4c31-aaea-bea685244487" | |
| REPO_URL: "https://github.com/${{ github.repository }}" | |
| DOCKER_IMAGE: "nodejs-goof:${{ github.sha }}" | |
| jobs: | |
| # ── Open Source (SCA) ──────────────────────────────────────────────── | |
| snyk-sca-scan: | |
| name: SCA - Open Source Scan | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: '18' | |
| - name: Install dependencies | |
| run: npm install | |
| - name: Setup Snyk CLI | |
| uses: snyk/actions/setup@master | |
| - name: Authenticate Snyk | |
| run: snyk auth ${{ secrets.SNYK_TOKEN }} | |
| env: | |
| SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} | |
| - name: "SCA: Test (find vulnerable dependencies)" | |
| continue-on-error: true | |
| run: | | |
| snyk test \ | |
| --severity-threshold=high \ | |
| --org=${{ env.SNYK_ORG }} | |
| env: | |
| SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} | |
| - name: "SCA: Monitor (upload to dashboard)" | |
| continue-on-error: true | |
| run: | | |
| snyk monitor \ | |
| --org=${{ env.SNYK_ORG }} \ | |
| --remote-repo-url=${{ env.REPO_URL }} \ | |
| --project-name="nodejs-github-action sca" \ | |
| --target-reference=${{ github.ref_name }} | |
| env: | |
| SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} | |
| # ── Code (SAST) ───────────────────────────────────────────────────── | |
| snyk-code-scan: | |
| name: SAST - Snyk Code Scan | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| - name: Setup Snyk CLI | |
| uses: snyk/actions/setup@master | |
| - name: Authenticate Snyk | |
| run: snyk auth ${{ secrets.SNYK_TOKEN }} | |
| env: | |
| SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} | |
| - name: "SAST: Test (find code vulnerabilities)" | |
| continue-on-error: true | |
| run: | | |
| snyk code test \ | |
| --severity-threshold=high \ | |
| --org=${{ env.SNYK_ORG }} | |
| env: | |
| SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} | |
| - name: "SAST: Report (upload to dashboard)" | |
| continue-on-error: true | |
| run: | | |
| snyk code test \ | |
| --report \ | |
| --severity-threshold=high \ | |
| --org=${{ env.SNYK_ORG }} \ | |
| --remote-repo-url=${{ env.REPO_URL }} \ | |
| --project-name="nodejs-github-action sast" | |
| env: | |
| SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} | |
| # ── Infrastructure as Code (IaC) ──────────────────────────────────── | |
| snyk-iac-scan: | |
| name: IaC - Infrastructure as Code Scan | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| - name: Setup Snyk CLI | |
| uses: snyk/actions/setup@master | |
| - name: Authenticate Snyk | |
| run: snyk auth ${{ secrets.SNYK_TOKEN }} | |
| env: | |
| SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} | |
| - name: "IaC: Test (find misconfigurations)" | |
| continue-on-error: true | |
| run: | | |
| snyk iac test vulnerable.tf \ | |
| --org=${{ env.SNYK_ORG }} | |
| env: | |
| SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} | |
| - name: "IaC: Report (upload to dashboard)" | |
| continue-on-error: true | |
| run: | | |
| snyk iac test vulnerable.tf \ | |
| --report \ | |
| --org=${{ env.SNYK_ORG }} \ | |
| --remote-repo-url=${{ env.REPO_URL }} | |
| env: | |
| SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} | |
| # ── Container ─────────────────────────────────────────────────────── | |
| snyk-container-scan: | |
| name: Container - Docker Image Scan | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| - name: Setup Snyk CLI | |
| uses: snyk/actions/setup@master | |
| - name: Authenticate Snyk | |
| run: snyk auth ${{ secrets.SNYK_TOKEN }} | |
| env: | |
| SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} | |
| - name: Build Docker image | |
| run: docker build -t ${{ env.DOCKER_IMAGE }} . | |
| - name: "Container: Test (find OS-level vulnerabilities)" | |
| continue-on-error: true | |
| run: | | |
| snyk container test ${{ env.DOCKER_IMAGE }} \ | |
| --file=Dockerfile \ | |
| --severity-threshold=high \ | |
| --org=${{ env.SNYK_ORG }} | |
| env: | |
| SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} | |
| - name: "Container: Monitor (upload to dashboard)" | |
| continue-on-error: true | |
| run: | | |
| snyk container monitor ${{ env.DOCKER_IMAGE }} \ | |
| --file=Dockerfile \ | |
| --org=${{ env.SNYK_ORG }} \ | |
| --project-name="nodejs-github-action container" | |
| env: | |
| SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} |