Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
47 changes: 47 additions & 0 deletions .config/mise.dev.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 2 additions & 0 deletions .config/mise.dev.toml
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,8 @@ direnv = "latest"

"github:peterldowns/localias" = "latest"
"github:gitleaks/gitleaks" = "latest"
# filesystem vulnerabilities, misconfigurations, and secrets (`just dev_lint`)
trivy = "latest"
"jq" = "latest"
"mprocs" = "latest"
"fd" = "latest"
Expand Down
44 changes: 44 additions & 0 deletions .config/trivy.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
# https://trivy.dev/docs/latest/guide/references/configuration/config-file/
# Passed to `trivy fs` from `just dev_lint` via `--config`.

# Fail the lint when a reported finding matches the severity filter below.
exit-code: 1

# Drop progress and scanner logs so `just dev_lint` prints the report.
quiet: true

# Gate on HIGH and CRITICAL.
severity:
- HIGH
- CRITICAL

scan:
# mise owns upgrades; skip the extra version-check request on every lint.
skip-version-check: true
disable-telemetry: true
scanners:
- vuln
- misconfig
# gitleaks covers git history. Trivy covers the working tree with a different ruleset.
- secret
skip-dirs:
- tmp
- .git
- .venv
- .terraform
# vendored mise tool lockfiles, not this project's dependencies
- .config/mise/locks
- "**/node_modules"

misconfiguration:
terraform:
# Lint this repo's modules, not third-party modules Terraform downloads.
exclude-downloaded-modules: true

vulnerability:
# Advisories without a fix are not actionable in a lint gate.
ignore-unfixed: true

pkg:
# CI installs dev dependencies, so they belong in the scan.
include-dev-deps: true
7 changes: 7 additions & 0 deletions .github/workflows/build_and_publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -61,6 +61,13 @@ jobs:
fetch-depth: 0
- uses: ./.github/actions/common-setup
timeout-minutes: 3
- name: Cache Trivy databases
uses: actions/cache@v6
with:
path: ~/.cache/trivy
key: ${{ runner.os }}-trivy-${{ hashFiles('.config/mise.dev.lock') }}
restore-keys: |
${{ runner.os }}-trivy-
- run: just dev_lint
- uses: iloveitaly/github-action-localias@master
with:
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -410,7 +410,7 @@ There are top-level commands for many of these (`clean`, `setup`, `dev`, etc) wh

The more linting tools the better, as long as they are well maintained, useful, and add value. I think of linters as helpful teammates that let me know when I missed something.

This project implements many linting tools (including DB SQL linting!). This could cause developer friction at some point, but we'll see how this scales as the codebase complexity grows.
This project implements many linting tools (including DB SQL linting and Trivy filesystem scans for vulnerabilities, misconfigurations, and secrets). This could cause developer friction at some point, but we'll see how this scales as the codebase complexity grows.

### Test Database Cleaning

Expand Down
1 change: 1 addition & 0 deletions infra/azure/deployment_state.tf
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,7 @@ resource "azurerm_resource_group" "tfstate" {
# IMPORTANT: (2) when bootstrapping a new azure account, this must be done second!
# by default, tf stores state in the local filesystem. We use remote storage state to sync between
# multiple devs and eliminate dependency on a single machine.
# trivy:ignore:AZU-0012 developers and CI read this account; default-deny without an IP allowlist blocks bootstrap
resource "azurerm_storage_account" "tfstate" {
name = local.tfstate.storage_account
resource_group_name = azurerm_resource_group.tfstate.name
Expand Down
9 changes: 6 additions & 3 deletions infra/azure/dokku_vm.tf
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,8 @@ resource "azurerm_network_security_group" "vm" {
location = local.location
resource_group_name = azurerm_resource_group.main.name

# Allow SSH
# Allow SSH. Open to the internet so a fresh template VM is reachable; restrict this prefix before production use.
# trivy:ignore:AZU-0047 trivy:ignore:AZU-0050
security_rule {
name = "SSH"
priority = 1001
Expand All @@ -52,7 +53,8 @@ resource "azurerm_network_security_group" "vm" {
destination_address_prefix = "*"
}

# Allow HTTP
# Allow HTTP. Public ingress is required for the web app.
# trivy:ignore:AZU-0047
security_rule {
name = "HTTP"
priority = 1002
Expand All @@ -65,7 +67,8 @@ resource "azurerm_network_security_group" "vm" {
destination_address_prefix = "*"
}

# Allow HTTPS
# Allow HTTPS. Public ingress is required for the web app.
# trivy:ignore:AZU-0047
security_rule {
name = "HTTPS"
priority = 1003
Expand Down
3 changes: 3 additions & 0 deletions just/dev.just
Original file line number Diff line number Diff line change
Expand Up @@ -12,13 +12,16 @@ GENERATED_HOST_ENV := "env/host.sh"
# we don't guard against _dev_only since this needs to be run to bootstrap the application
dev_generate: _not_production dev_generate_hosts dev_generate_localias

# gitleaks (git history) and trivy (working tree). Policy for trivy lives in .config/trivy.yaml.
dev_lint:
# `--log-level=debug` for debugging
# will report 0 commits scanned since it just outputs a massive diff and doesn't scan commits
GIT_CONFIG_GLOBAL=/dev/null gitleaks git --report-path=- --report-format json --redact=20 --no-banner
# TODO link justfiles too
# GIT_CONFIG_GLOBAL=/dev/null gitleaks git --report-format json --report-path - | jq -r '.[].Fingerprint' | sort -t ':' -k2 > .gitleaksignore

trivy fs --config .config/trivy.yaml .

# start all of the services you need for development in a single terminal
[script]
[arg("open", long, help="open the development site in the browser", flag)]
Expand Down
60 changes: 30 additions & 30 deletions web/pnpm-lock.yaml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

9 changes: 9 additions & 0 deletions web/pnpm-workspace.yaml
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
# Pin transitive versions Trivy reports as HIGH with a fixed release.
overrides:
brace-expansion@1.1.14: 1.1.20
brace-expansion@2.1.0: 2.1.6
brace-expansion@5.0.6: 5.0.11
js-yaml@4.1.1: 4.3.2
js-yaml@4.2.0: 4.3.2
shell-quote@1.8.4: 1.9.0

allowBuilds:
'@clerk/shared': true
'@sentry/cli': true
Expand Down
Loading