Skip to content

Add Socket Basics security scanning - #8

Merged
sgrammargs merged 2 commits into
mainfrom
add-socket-basics-scanning
Sep 3, 2026
Merged

sgrammargs merged 2 commits into
mainfrom
add-socket-basics-scanning

Conversation

@sgrammargs

Copy link
Copy Markdown
Contributor

Adds Socket Basics (SAST) scanning to this repo, calling the shared ynab-sast-scanner workflow — the same setup already in place across other YNAB repos.

.github/workflows/socket-basics.yml:

  • uses: ynab/ynab-sast-scanner/.github/workflows/socket-basics.yml@main
  • SOCKET_SECURITY_API_KEY and SAST_SUPPRESSIONS_APP_PRIVATE_KEY secrets (both org-level, nothing per-repo needed)

Adds the standard CI wrapper calling ynab-sast-scanner, matching the migrated
setup already in place across other repos.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Socket SAST-GENERIC

✅ Socket Basics found no active findings in the latest run.

@github-actions github-actions Bot added the security: critical Critical security vulnerabilities label Sep 2, 2026
@grantcox

grantcox commented Sep 3, 2026

Copy link
Copy Markdown
Collaborator

@sgrammargs I will update that test, it doesn't need to use Marshal.load

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot removed the security: critical Critical security vulnerabilities label Sep 3, 2026
@sgrammargs
sgrammargs marked this pull request as ready for review September 3, 2026 13:54
@sgrammargs
sgrammargs merged commit 67b21fd into main Sep 3, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants