name: Security Scan on: push: branches: [main, dev] pull_request: branches: [main, dev] schedule: - cron: "0 6 * * 1" permissions: contents: read env: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" jobs: dependency-scan: runs-on: ubuntu-latest steps: - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 with: python-version: "3.13" # Upgrade pip first: pip-audit scans the whole environment, and the # runner's bundled pip (26.1.1) carries advisory PYSEC-2026-196 (fixed in # 26.1.2). Upgrading removes the vulnerable version outright rather than # suppressing it — and 26.1.2 also resolves CVE-2026-3219 / CVE-2026-6357, # which is why those two stale --ignore-vuln entries are no longer needed. - run: | python -m pip install --upgrade pip pip install pip-audit - run: pip install -e . - name: Pip audit run: pip-audit --skip-editable codeql: runs-on: ubuntu-latest permissions: contents: read actions: read security-events: write steps: - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 - uses: github/codeql-action/init@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0 with: languages: python - uses: github/codeql-action/analyze@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0