name: Security Audit on: push: branches: - main schedule: - cron: "41 2 * * 2" workflow_dispatch: jobs: security-audit: runs-on: ubuntu-latest env: SECURITY_AUDIT_MODE: full SECURITY_AUDIT_SCOPE: govoplan SECURITY_AUDIT_FAIL_ON_FINDINGS: "0" SECURITY_AUDIT_REQUIRE_TOOLS: "1" steps: - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 with: path: govoplan - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 with: python-version: "3.12" - name: Use anonymous HTTPS for public GovOPlaN repositories run: | git config --global --add url."https://git.add-ideas.de/GovOPlaN/govoplan".insteadOf "git@git.add-ideas.de:GovOPlaN/govoplan" git config --global --add url."https://git.add-ideas.de/GovOPlaN/govoplan".insteadOf "ssh://git@git.add-ideas.de/GovOPlaN/govoplan" - name: Bootstrap GovOPlaN repositories working-directory: govoplan run: python tools/repo/bootstrap-repositories.py --parent .. --transport public-https - name: Run whole-system security audit working-directory: govoplan run: tools/checks/security-audit/run.sh --mode "$SECURITY_AUDIT_MODE" --scope "$SECURITY_AUDIT_SCOPE" --reports-dir audit-reports - name: Upload audit reports if: always() uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 with: name: security-audit-reports path: govoplan/audit-reports