name: Security Scan on: push: branches: [main, dev] pull_request: branches: [main, dev] schedule: - cron: "0 6 * * 1" permissions: contents: read env: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" jobs: dependency-scan: runs-on: ubuntu-latest steps: - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 with: python-version: "3.13" # Upgrade pip first: pip-audit scans the whole environment, and the # runner's bundled pip (26.1.1) carries advisory PYSEC-2026-196 (fixed in # 26.1.2). Upgrading removes the vulnerable version outright rather than # suppressing it — and 26.1.2 also resolves CVE-2026-3219 / CVE-2026-6357, # which is why those two stale --ignore-vuln entries are no longer needed. - run: | python -m pip install --upgrade pip pip install pip-audit - run: pip install -e . - name: Pip audit run: pip-audit --skip-editable codeql: runs-on: ubuntu-latest permissions: contents: read actions: read security-events: write steps: - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - uses: github/codeql-action/init@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 with: languages: python - uses: github/codeql-action/analyze@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2