feat(security): add security headers middleware #57
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Dependency Scanning | ||
|
Check failure on line 1 in .github/workflows/dependency-scan.yml
|
||
| on: | ||
| push: | ||
| branches: | ||
| - main | ||
| - master | ||
| - develop | ||
| pull_request: | ||
| branches: | ||
| - main | ||
| - develop | ||
| schedule: | ||
| # Run daily at 03:00 UTC for continuous vulnerability checks | ||
| - cron: "0 3 * * *" | ||
| workflow_dispatch: | ||
| jobs: | ||
| npm-audit: | ||
| name: npm audit (block high/critical) | ||
| runs-on: ubuntu-latest | ||
| permissions: | ||
| contents: read | ||
| security-events: write | ||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v6 | ||
| - name: Use Node.js 20 | ||
| uses: actions/setup-node@v6 | ||
| with: | ||
| node-version: 20 | ||
| cache: "npm" | ||
| - name: Install dependencies | ||
| run: npm ci --legacy-peer-deps | ||
| - name: npm audit (high+ threshold) | ||
| run: npm audit --audit-level=high | ||
| snyk-test: | ||
| name: Snyk test (block high/critical) | ||
| needs: npm-audit | ||
| if: ${{ secrets.SNYK_TOKEN != '' }} | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v6 | ||
| - name: Use Node.js 20 | ||
| uses: actions/setup-node@v6 | ||
| with: | ||
| node-version: 20 | ||
| cache: "npm" | ||
| - name: Install dependencies | ||
| run: npm ci --legacy-peer-deps | ||
| - name: Snyk test | ||
| uses: snyk/actions/node@master | ||
| env: | ||
| SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} | ||
| with: | ||
| args: --severity-threshold=high | ||
| snyk-monitor: | ||
| name: Snyk monitor (continuous alerts) | ||
| needs: snyk-test | ||
| if: ${{ github.event_name != 'pull_request' && secrets.SNYK_TOKEN != '' }} | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v6 | ||
| - name: Use Node.js 20 | ||
| uses: actions/setup-node@v6 | ||
| with: | ||
| node-version: 20 | ||
| cache: "npm" | ||
| - name: Install dependencies | ||
| run: npm ci --legacy-peer-deps | ||
| - name: Snyk monitor | ||
| uses: snyk/actions/node@master | ||
| env: | ||
| SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} | ||
| with: | ||
| command: monitor | ||