Skip to content

Security Scanning

GitHub Actions provides robust mechanisms to integrate security scanning into CI/CD pipelines, ensuring vulnerabilities, secrets, and code quality issues are detected early. This section covers dependency scanning, secret scanning, and code quality checks, along with practical examples for implementation.


Dependency Scanning

Dependency scanning identifies vulnerabilities in third-party libraries and packages. GitHub Actions supports tools like Dependabot (built-in) and Snyk, which can be configured to audit dependencies during builds.

Example: Dependabot Integration

Dependabot automatically creates pull requests for dependency updates. To enable it:

# .github/workflows/dependabot.yml
name: Dependabot
on:
  schedule:
    - cron: '0 1 * * *'  # Daily check

jobs:
  dependabot:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout code
        uses: actions/checkout@v4
      - name: Dependabot audit
        uses: dependabot/audit@v2

Example: Snyk Dependency Scan

Snyk provides detailed vulnerability reports. Configure it with a token stored as a secret:

# .github/workflows/snyk.yml
name: Snyk Scan
on:
  push
  pull_request

jobs:
  snyk:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout code
        uses: actions/checkout@v4
      - name: Snyk Scan
        uses: snyk/actions/scan@v1
        with:
          token: ${{ secrets.SNYK_TOKEN }}
          packageManager: npm  # or yarn, pip, etc.

Best Practices:
- Schedule regular scans (e.g., daily or weekly).
- Prioritize critical vulnerabilities in your dependency graph.
- Integrate with vulnerability databases like CVE or NVD.


Secret Scanning

Secret scanning detects hardcoded credentials, API keys, and other sensitive data in code. GitHub provides built-in secret scanning that alerts on suspicious patterns. For advanced use cases, tools like GitGuardian or TruffleHog can be integrated.

Example: GitHub Secret Scanning

Enable secret scanning in your repository settings (Repository > Security > Secret Scanning). GitHub automatically scans for patterns like API_KEY=... or TOKEN=....

Example: GitGuardian Integration

Use GitGuardian’s GitHub Action to scan for secrets:

# .github/workflows/gitguardian.yml
name: GitGuardian Scan
on:
  push
  pull_request

jobs:
  gitguardian:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout code
        uses: actions/checkout@v4
      - name: GitGuard, scan
        uses: gitguardian/gg-action@v1
        with:
          token: ${{ secrets.GITGUARDIAN_TOKEN }}

Best Practices:
- Store secrets in environment variables or encrypted secrets, not hardcoded.
- Regularly review secret scanning alerts and disable false positives.
- Combine with GitHub’s built-in secret scanning for comprehensive coverage.


Code Quality Checks

Code quality tools like ESLint, RuboCop, or Pylint enforce coding standards and detect bugs. Integrate these tools into workflows to fail builds on critical issues.

Example: ESLint for JavaScript

# .github/workflows/eslint.yml
name: ESLint
on:
  push
  pull_request

jobs:
  eslint:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout code
        uses: actions/checkout@v4
      - name: Install dependencies
        run: npm install
      - name: Run ESLint
        run: npx eslint . --max-warnings 0

Example: RuboCop for Ruby

# .github/workflows/rubocop.yml
name: RuboCop
on:
  push
  pull_request

jobs:
  rubocop:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout code
        uses: actions/checkout@v4
      - name: Install dependencies
        run: bundle install
      - name: Run RuboCop
        run: bundle exec rubocop --fail-on-cops

Best Practices:
- Configure severity levels to fail builds on critical issues.
- Automate formatting tools (e.g., Prettier, Black) alongside linters.
- Use static analysis tools tailored to your language/stack.


Key takeaways

  • Dependency scanning tools like Dependabot and Snyk help identify vulnerable packages.
  • Secret scanning (built-in or via GitGuardian) prevents accidental exposure of credentials.
  • Code quality checks with ESLint, RuboCop, or Pylint enforce standards and reduce bugs.
  • Combine these scans with CI/CD steps to enforce security and compliance automatically.
  • Regularly update tools and review alerts to stay ahead of emerging threats.