Skip to content

deps: bump vitest from 4.1.10 to 5.0.0 #237

deps: bump vitest from 4.1.10 to 5.0.0

deps: bump vitest from 4.1.10 to 5.0.0 #237

Workflow file for this run

name: Security Scanning
on:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
# Run weekly security scan
- cron: '0 0 * * 0'
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
dependency-audit:
name: Dependency Audit
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
with:
egress-policy: audit
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Setup Node.js
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: '24'
cache: 'npm'
- name: Install dependencies
run: npm ci
- name: Check production config safety
run: |
if grep -rn "ENABLE_MOCK_ADMIN=true" --include="*.yml" --include="*.yaml" --include="*.env" . 2>/dev/null | grep -v ".git" | grep -v "node_modules" | grep -v "security.yml"; then
echo "ERROR: ENABLE_MOCK_ADMIN=true found in config files — must not be enabled in production"
exit 1
fi
echo "✓ Production config check passed"
- name: Run npm audit
run: npm audit --audit-level=high
continue-on-error: true
- name: Run audit-ci
run: npm run check:audit
continue-on-error: true
gitleaks:
name: Secret Scanning
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
with:
egress-policy: audit
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- name: Install & Run Gitleaks
run: |
curl -sSfL https://github.com/gitleaks/gitleaks/releases/download/v8.24.0/gitleaks_8.24.0_linux_x64.tar.gz | tar -xz
./gitleaks detect --verbose --redact