diff --git a/.github/workflows/horusec-security-scan.yml b/.github/workflows/horusec-security-scan.yml deleted file mode 100644 index 4445f3f..0000000 --- a/.github/workflows/horusec-security-scan.yml +++ /dev/null @@ -1,100 +0,0 @@ -name: Horusec Security Scan - -on: - push: - branches: [main] - pull_request: - branches: [main] - schedule: - - cron: "0 0 * * 0" # Weekly at midnight on Sunday - -# Cancel in-progress runs when a new workflow with the same group is triggered -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true - -jobs: - horusec-security: - name: Horusec Security Scan - runs-on: ubuntu-latest - steps: - - name: Checkout code - uses: actions/checkout@v4 - with: - fetch-depth: 0 - - # Cache Horusec to speed up subsequent runs - - name: Cache Horusec - uses: actions/cache@v4 - with: - path: ~/.horusec - key: ${{ runner.os }}-horusec-${{ hashFiles('**/mix.lock') }} - restore-keys: | - ${{ runner.os }}-horusec- - - # Install Horusec CLI directly since the action isn't available - - name: Install Horusec CLI - run: | - curl -fsSL https://raw.githubusercontent.com/ZupIT/horusec/main/deployments/scripts/install.sh | bash -s latest - horusec version - - - name: Running Horusec Security Scan - id: horusec - run: | - horusec start -p="./" --config-file-path="./horusec-config.json" --output-format="json" --output="./horusec-report.json" || echo "::warning::Vulnerabilities found" - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - - # Upload security scan results as an artifact - - name: Upload Horusec Report - uses: actions/upload-artifact@v4 - if: always() - with: - name: horusec-report - path: horusec-report.json - retention-days: 7 - - # Analyze Elixir-specific vulnerabilities with Sobelow - - name: Set up Elixir - if: always() - uses: erlef/setup-beam@v1 - with: - elixir-version: "1.17.x" - otp-version: "26.x" - - - name: Cache Elixir deps - if: always() - uses: actions/cache@v4 - with: - path: | - deps - _build - key: ${{ runner.os }}-mix-${{ hashFiles('**/mix.lock') }} - restore-keys: | - ${{ runner.os }}-mix- - - - name: Install dependencies - if: always() - run: mix deps.get - - - name: Run Sobelow (Elixir-specific security scan) - if: always() - run: mix sobelow --format=json --out=sobelow-report.json --exit || echo "::warning::Sobelow detected vulnerabilities" - - - name: Upload Sobelow Report - uses: actions/upload-artifact@v4 - if: always() - with: - name: sobelow-report - path: sobelow-report.json - retention-days: 7 - - # Optional: Fail the workflow if critical vulnerabilities are found - - name: Check for critical vulnerabilities - if: always() - run: | - if grep -q "CRITICAL" horusec-report.json; then - echo "Critical vulnerabilities found in the security scan!" - echo "Review the security reports in the workflow artifacts." - exit 1 - fi