Skip to content

Technical guide · Overview

Page status: Active

Security CI Scans

NutsNews uses GitHub Actions and repository security settings to catch dependency, workflow, secret, and supply-chain risks before release.

Visual overview

Primary diagram

System map

NutsNews uses GitHub Actions and repository security settings to catch dependency, workflow, secret, and supply-chain risks before release.

Render the repository-owned system map when you need it.

Diagram is not rendered yet.

View as text
Security CI Scans

NutsNews uses GitHub Actions and repository security settings to catch dependency, workflow, secret, and supply-chain risks before release.

flowchart TB
  accTitle: Security CI Scans
  accDescr {
    NutsNews uses GitHub Actions and repository security settings to catch dependency, workflow, secret, and supply-chain risks before release.
  }
  A["Security CI Scans"] --> B["SECURITY_CI_SCANS.md"]
  B --> C["Auto-generated placeholder diagram"]

Security CI Scans

Fullscreen diagram view.

NutsNews uses GitHub Actions and repository security settings to catch dependency, workflow, secret, and supply-chain risks before release.

The NutsNews repos now have more safety checks, like extra locks on a door, so risky code, leaked secrets, and unsafe dependencies are easier to catch before they ship.

This update adds or verifies recommended security scans for ramideltoro/nutsnews and ramideltoro/nutsnews-worker. It covers CodeQL, Dependency Review, Dependabot, Gitleaks, OSV-Scanner, actionlint, OpenSSF Scorecard, Lighthouse CI for the web app, and OWASP ZAP baseline scanning for the public web URL. Trivy is skipped because neither repo has Dockerfiles or container manifests. Worker Lighthouse and ZAP are skipped because the Worker repo does not define public web pages or a safe staging URL for baseline scanning.

The web app already had CodeQL, Snyk, Dependabot npm updates, and Lighthouse CI. The new web workflows add Dependency Review, Gitleaks, OSV-Scanner, actionlint, OpenSSF Scorecard, and a non-blocking OWASP ZAP baseline scan against https://www.nutsnews.com on schedule or manual dispatch. The Worker repo now has CodeQL for JavaScript/TypeScript and GitHub Actions, Dependency Review, Gitleaks, OSV-Scanner, actionlint, OpenSSF Scorecard, and expanded Dependabot coverage for GitHub Actions and local-ai-service. The Worker PR also fixes existing workflow YAML health issues so actionlint can validate the baseline. Manual repository settings are still REQUIRED for GitHub Secret Scanning and Push Protection because those controls cannot be fully enabled from workflow files.

ScanStatusWorkflow or configNotes
CodeQLAlready installed and verified.github/workflows/codeql.ymlScans JavaScript/TypeScript and GitHub Actions on PR, push, weekly schedule, and manual dispatch.
Dependency ReviewAdded, non-blocking until Dependency graph is enabled.github/workflows/dependency-review.ymlReports high-severity dependency changes. Enable Dependency graph before making this required.
DependabotStrengthened.github/dependabot.ymlExisting npm updates kept; GitHub Actions updates added.
Secret scanAdded Gitleaks; manual GitHub settings still REQUIRED.github/workflows/gitleaks.ymlCI scans committed secrets; GitHub Secret Scanning and Push Protection must be enabled in repo settings.
OSV-ScannerAdded.github/workflows/osv-scanner.ymlScans lockfiles and manifests recursively.
actionlintAdded.github/workflows/actionlint.ymlValidates workflow syntax and common GitHub Actions mistakes.
OpenSSF ScorecardAdded.github/workflows/openssf-scorecard.ymlPublishes SARIF and OpenSSF results.
TrivySkippedNot applicableNo Dockerfiles, container images, or container manifests were found.
Lighthouse CIAlready installed and verified.github/workflows/lighthouse-ci.ymlApplies to web-facing app pages.
OWASP ZAP baselineAdded.github/workflows/owasp-zap-baseline.ymlNon-blocking passive scan of https://www.nutsnews.com; can be manually pointed at staging.
ScanStatusWorkflow or configNotes
CodeQLAdded.github/workflows/codeql.ymlScans JavaScript/TypeScript and GitHub Actions.
Dependency ReviewAdded, non-blocking until Dependency graph is enabled.github/workflows/dependency-review.ymlReports high-severity dependency changes. Enable Dependency graph before making this required.
DependabotStrengthened.github/dependabot.ymlExisting /worker and /controller npm updates kept; GitHub Actions and /local-ai-service updates added.
Secret scanAdded Gitleaks; manual GitHub settings still REQUIRED.github/workflows/gitleaks.ymlCI scans committed secrets; GitHub Secret Scanning and Push Protection must be enabled in repo settings.
OSV-ScannerAdded.github/workflows/osv-scanner.ymlScans lockfiles and manifests recursively.
actionlintAdded with protected workflow exclusions.github/workflows/actionlint.ymlValidates editable workflow syntax and common GitHub Actions mistakes. worker-controller-ci.yml and worker-pipeline.yml are immutable-guarded and require explicit owner approval before fixes.
OpenSSF ScorecardAdded.github/workflows/openssf-scorecard.ymlPublishes SARIF and OpenSSF results.
TrivySkippedNot applicableNo Dockerfiles, container images, or container manifests were found.
Lighthouse CISkippedNot applicableWorker repo does not own public web pages.
OWASP ZAP baselineSkipped with blockerNot addedNo safe staging Worker URL is configured for baseline scanning. Add one before enabling ZAP for Worker endpoints.
  • CodeQL catches code and workflow security issues.
  • Dependency Review blocks risky dependency changes before merge.
  • Dependabot keeps package and action versions current.
  • Gitleaks catches committed secrets in CI.
  • GitHub Secret Scanning and Push Protection stop secret exposure at the repository platform layer.
  • OSV-Scanner checks manifests and lockfiles against open vulnerability databases.
  • actionlint prevents broken workflow YAML and common Actions mistakes.
  • OpenSSF Scorecard highlights supply-chain posture gaps.
  • Lighthouse CI protects public web quality.
  • OWASP ZAP baseline passively checks deployed web pages for common security header and passive scanner findings.
CheckHow to interpret a failureCommon response
CodeQLA code or workflow query found a security issue.Review the SARIF alert, patch the code or workflow, and rerun.
Dependency ReviewA PR introduces a dependency with a high-severity advisory, or the repo Dependency graph is disabled.Enable Dependency graph, then upgrade, remove, or justify the dependency before merge.
DependabotA version or security update PR failed validation.Inspect the failing project tests and adjust the dependency update.
GitleaksA secret-like value appears in history or the PR diff.Revoke the secret, rotate credentials, remove it from history when required, and rerun.
OSV-ScannerA manifest or lockfile resolves to a vulnerable package.Upgrade the vulnerable package or document a temporary exception.
actionlintA workflow has invalid YAML, invalid expressions, or unsafe Actions syntax.Fix the workflow file before merging.
OpenSSF ScorecardThe repo has a supply-chain posture gap.Treat as advisory unless the workflow itself fails; improve score over time.
Lighthouse CIWeb performance or quality budget regressed.Inspect the Lighthouse report and fix public-page regressions.
OWASP ZAP baselinePassive scanner found a deployed-page concern.Review the report; tune false positives or fix headers/content issues.

The following settings are REQUIRED and must be enabled in GitHub repository settings for both ramideltoro/nutsnews and ramideltoro/nutsnews-worker:

  • Secret Scanning.
  • Push Protection.
  • Dependency graph.
  • Dependabot alerts.
  • Dependabot security updates.
  • Code scanning alerts.

These settings cannot be fully enforced from repository workflow files alone. A maintainer must verify them in GitHub under repository security settings.

  • Keep workflow permissions minimal. Add write permissions only when an action needs SARIF upload or another documented write path.
  • Keep noisy scans non-blocking at first when they target deployed public URLs or produce posture scores.
  • Keep Dependency Review blocking for high-severity dependency changes.
  • Keep Dependency Review non-blocking until Dependency graph is enabled in each repository.
  • Update action versions through Dependabot GitHub Actions PRs.
  • Review OpenSSF Scorecard trends periodically instead of treating every score change as a release blocker.
  • Add Trivy only if Dockerfiles, container images, or container filesystem artifacts are introduced.
  • Add Worker ZAP only after a safe staging Worker URL exists and rate/side-effect risk is documented.
  • Fix immutable-guarded Worker workflow health issues only after the repo owner explicitly approves edits to .github/workflows/worker-controller-ci.yml and .github/workflows/worker-pipeline.yml.

Simple Summary: OSV found a few unsafe helper packages, so the web app now tells npm to use fixed versions.

Intermediate Summary: The OSV Scanner scheduled/push run failed on ramideltoro/nutsnews because web/package-lock.json resolved vulnerable transitive versions of postcss, tmp, and uuid. The app fix adds npm overrides in web/package.json and refreshes web/package-lock.json so the scanner sees fixed versions without changing public reader behavior.

Expert Summary: Run 28718139650 failed in the Scan repository dependencies / osv-scan job during Run osv-scanner-reporter. The scanner reported postcss@8.4.31, tmp@0.0.33, tmp@0.1.0, and uuid@8.3.2 from web/package-lock.json. postcss was pulled through next; tmp and uuid were pulled through @lhci/cli and its external-editor dependency. @lhci/cli was already current, so the smallest fix was to add npm overrides for postcss, tmp, and uuid, regenerate the lockfile, and validate with npm ls, npm audit, lhci --version, lint, build, and lockfile checks. Roll back by reverting the dependency override PR and rerunning OSV Scanner; if a future parent dependency release removes the need for overrides, remove the overrides in a normal dependency maintenance PR.

flowchart TD
A[OSV Scanner scheduled/push run] --> B[Scan web/package-lock.json]
B --> C{Vulnerable transitive package?}
C -->|Yes| D[Fail Run osv-scanner-reporter]
D --> E[Add npm override for fixed version]
E --> F[Regenerate package-lock.json]
F --> G[Validate npm ls and npm audit]
G --> H[Rerun OSV Scanner]
C -->|No| I[Security scan passes]

2026-07-20 OSV Dev Dependency Lockfile Refresh

Section titled “2026-07-20 OSV Dev Dependency Lockfile Refresh”

Simple Summary: The safety checker found three old helper packages in the web app lockfile. The lockfile now points to the fixed versions.

Intermediate Summary: The OSV Scanner push run failed on ramideltoro/nutsnews after PR #291 merged because web/package-lock.json still resolved vulnerable dev-only versions of body-parser, brace-expansion, and js-yaml. The app fix refreshes only the lockfile to versions already allowed by the parent dependency ranges, so there is no product behavior, runtime configuration, database, or deployment-flow change.

Expert Summary: Run 29788781874 failed in Scan repository dependencies / osv-scan during Run osv-scanner-reporter. OSV reported body-parser@1.20.5, brace-expansion@1.1.15, and js-yaml@4.2.0 from web/package-lock.json; the fixed versions are 1.20.6, 1.1.16, and 4.3.0. npm update body-parser brace-expansion js-yaml --package-lock-only moved the lockfile to the fixed versions without changing web/package.json. Risk is limited to dev/test tooling dependency resolution. Mitigation is to rerun npm audit, route tests, CPU/cache guardrails, lint, build, and the GitHub OSV workflow. Roll back by reverting the dependency PR if CI exposes tooling regressions.

flowchart TD
A[Push to main] --> B[OSV Scanner scans web/package-lock.json]
B --> C{Vulnerable dev packages?}
C -->|Yes| D[Fail main OSV run]
D --> E[Refresh lockfile within existing semver ranges]
E --> F[npm audit and web checks]
F --> G[PR merge reruns OSV]
G --> H[Main release pipeline can stay green]
C -->|No| I[Security scan passes]

Related issue: https://github.com/ramideltoro/nutsnews/issues/496 Related app PR: https://github.com/ramideltoro/nutsnews/pull/508 Related main run: https://github.com/ramideltoro/nutsnews/actions/runs/30046855929

Simple Summary: After the standby workflow merged, the main safety checker found an unsafe login helper package. The web app now uses the fixed login helper version.

Intermediate Summary: The OSV Scanner main-push run failed after app PR #507 merged because web/package-lock.json resolved next-auth@5.0.0-beta.31 and @auth/core@0.41.2. The app fix updates the direct dependency to next-auth@^5.0.0-beta.32, which resolves @auth/core@0.41.3, removing the OSV findings without changing standby workflow behavior or runtime configuration.

Expert Summary: Run 30046855929 reported seven OSV findings across next-auth and @auth/core, including GHSA-7rqj-j65f-68wh, GHSA-8fpg-xm3f-6cx3, GHSA-x445-f3h2-j279, and GHSA-xmf8-cvqr-rfgj. npm view next-auth@5.0.0-beta.32 confirmed the fixed package resolves @auth/core@0.41.3. The fix is limited to web/package.json and web/package-lock.json; expected validation is npm audit, OSV, authentication/runtime regressions, lint, and build with the same CI runtime env used by Merge Gate. Roll back by reverting the dependency PR if auth regression tests or production smoke checks expose a compatibility issue, then reopen the OSV blocker with a narrower Auth.js mitigation plan.

flowchart TD
A[Main push after PR #507] --> B[OSV Scanner scans web/package-lock.json]
B --> C{next-auth or @auth/core vulnerable?}
C -->|Yes| D[Main post-merge stage fails]
D --> E[Bump next-auth to beta.32]
E --> F[Lock @auth/core to 0.41.3 through dependency resolution]
F --> G[Run audit, regressions, lint, build, and OSV]
G --> H[Main post-merge stage returns green]
C -->|No| I[Security scan passes]
flowchart TD
A[Pull request opened] --> B[Dependency Review checks changed manifests]
A --> C[CodeQL analyzes code and workflows]
A --> D[Gitleaks scans for committed secrets]
A --> E[OSV scans lockfiles and manifests]
A --> F[actionlint validates workflow YAML]
B --> G{Blocking issue?}
C --> G
D --> G
E --> G
F --> G
G -->|Yes| H[Patch PR and rerun checks]
G -->|No| I[Review advisory scans and merge when approved]
J[Scheduled scans] --> K[OpenSSF Scorecard]
J --> L[OWASP ZAP for public web app]
J --> M[Dependabot update PRs]

Revert the app and Worker workflow PRs and this documentation update. If a scan is too noisy but still valuable, prefer temporarily narrowing its triggers or marking the job non-blocking before removing it completely.