name: Security Scan on: push: branches: [main, dev] pull_request: branches: [main, dev] schedule: - cron: "0 6 * * 1" permissions: contents: read env: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" jobs: dependency-scan: runs-on: ubuntu-latest steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 with: python-version: "3.13" # Upgrade pip first: pip-audit scans the whole environment, and the # runner's bundled pip (26.1.1) carries advisory PYSEC-2026-196 (fixed in # 26.1.2). Upgrading removes the vulnerable version outright rather than # suppressing it — and 26.1.2 also resolves CVE-2026-3219 / CVE-2026-6357, # which is why those two stale --ignore-vuln entries are no longer needed. - run: | python -m pip install --upgrade pip pip install pip-audit - run: pip install -e . - name: Pip audit run: pip-audit --skip-editable codeql: runs-on: ubuntu-latest permissions: contents: read actions: read security-events: write steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - uses: github/codeql-action/init@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0 with: languages: python - uses: github/codeql-action/analyze@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0