Commit Graph

2 Commits

Author SHA1 Message Date
f627ef018a feat: integrate security audits into pre-commit and CI/CD with backend pip-audit migration (#74)
Some checks failed
CICD / Build and Publish CICD Base Image (push) Successful in 36s
CICD / Build and Push CICD Image (push) Has been cancelled
CICD / Build CICD Image Failure Postmortem (push) Has been cancelled
CICD / Backend Tests (push) Has been cancelled
CICD / Pre-commit Checks (push) Has been cancelled
CICD / Frontend Tests (push) Has been cancelled
CICD / Backend Doctests (push) Has been cancelled
CICD / Frontend Dependency Audit (push) Has been cancelled
CICD / Backend Dependency Audit (push) Has been cancelled
CICD / CICD Tests Complete (push) Has been cancelled
CICD / Build Backend Base Image (push) Has been cancelled
CICD / Build Frontend Base Image (push) Has been cancelled
CICD / Build Integration Tester Image (push) Has been cancelled
CICD / Build E2E Tester Image (push) Has been cancelled
CICD / Build Frontend Main Image (push) Has been cancelled
CICD / Production Images Complete (push) Has been cancelled
CICD / End-to-End Tests (push) Has been cancelled
CICD / E2E Tests Failure Postmortem (push) Has been cancelled
CICD / Build Backend Main Image (push) Has been cancelled
CICD / Production Image Failures Postmortem (push) Has been cancelled
CICD / Source Lanes Failure Postmortem (push) Has been cancelled
CICD / Runtime Black-Box Integration Tests (push) Has been cancelled
CICD / Integration Tests Failure Postmortem (push) Has been cancelled
## Summary

This PR integrates security-focused checks into the existing quality gates and aligns local workflows with CI/CD execution.

## What changed

- Added Bandit to pre-commit backend checks.
- Integrated eslint-plugin-security into the existing frontend ESLint setup used by pre-commit.
- Added dedicated audit tasks:
  - backend audit via pip-audit
  - frontend audit via yarn npm audit
- Updated CI/CD workflow to include and gate on frontend/backend audit jobs.
- Switched backend vulnerability scanning from Safety to pip-audit to avoid interactive/auth requirements in CI.
- Updated backend dependency set and lockfile to resolve test dependency conflicts and keep the environment solvable.
- Marked backend integration API tests with the integration marker so marker-based unit/integration separation works consistently.

## Validation

- Pre-commit hooks run and pass after formatting/autofixes.
- Branch commit created successfully after hook-driven file updates.
- Branch pushed to remote and tracking is configured.

## Notes

- pip-audit now executes from backend context (for example via uv --directory backend run ...), matching project layout.
- Remaining reported vulnerabilities depend on upstream package fix availability/constraints and may require follow-up once publishable fix versions are consumable.

## Follow-ups (optional)

- Add a curated pip-audit ignore policy for non-actionable/transient advisories with rationale.
- Open a focused follow-up PR for remaining dependency advisories once upstream fixes are practically installable.

Co-authored-by: copilotcoder <copilotcoder@darkhelm.org>
Reviewed-on: #74
2026-07-13 22:19:57 -04:00
4454e9aef5 Adding renovate stuff.
Some checks failed
Tests / Build and Push CICD Base Image (push) Successful in 1m7s
Tests / Build and Push CICD Complete Image (push) Successful in 34m29s
Tests / YAML Syntax Check (push) Successful in 46s
Tests / Mixed Line Ending Check (push) Successful in 35s
Tests / TOML Formatting Check (push) Successful in 42s
Tests / Ruff Linting (push) Successful in 36s
Tests / Ruff Format Check (push) Successful in 36s
Tests / Pyright Type Check (push) Successful in 1m2s
Tests / Darglint Docstring Check (push) Successful in 48s
Tests / No Docstring Types Check (push) Successful in 31s
Tests / ESLint Check (push) Successful in 1m1s
Tests / Prettier Format Check (push) Successful in 44s
Tests / TypeScript Type Check (push) Successful in 1m18s
Tests / TSDoc Lint Check (push) Successful in 1m3s
Tests / Backend Tests (push) Successful in 49s
Tests / Frontend Tests (push) Successful in 1m39s
Tests / Backend Doctests (push) Successful in 35s
Tests / End-to-End Tests (push) Successful in 7m58s
Tests / Trailing Whitespace Check (push) Successful in 30m11s
Tests / Integration Tests (push) Failing after 22m6s
Tests / TOML Syntax Check (push) Failing after 38m33s
Tests / End of File Check (push) Successful in 41m46s
Signed-off-by: Cliff Hill <xlorep@darkhelm.org>
2025-11-04 12:40:53 -05:00