Skip to content
Merged
Show file tree
Hide file tree
Changes from 44 commits
Commits
Show all changes
52 commits
Select commit Hold shift + click to select a range
ba9693e
feat: implement Google SSO routing and secure HttpOnly cookies
pk-cybersec Aug 2, 2026
630eb0f
chore: bump CI/CD action versions to resolve Git 128 and Node depreca…
pk-cybersec Aug 2, 2026
af4c1bc
fix: enable CORS credentials for cookies and silence v7 linters
pk-cybersec Aug 2, 2026
826a1eb
fix: add CodeQL build-mode none for python analysis
pk-cybersec Aug 2, 2026
ecccd69
fix: finalize backend CI/CD workflow and resolve type mismatches
pk-cybersec Aug 2, 2026
29f61a1
fix: set CodeQL build-mode to none for Python analysis
pk-cybersec Aug 2, 2026
4af51e0
fix: streamline backend security analysis to use Bandit exclusively
pk-cybersec Aug 2, 2026
aa611b4
fix(frontend): update api client to include credentials for secure co…
pk-cybersec Aug 8, 2026
d1c5a49
feat(api): implement prometheus instrumentator middleware and /metric…
pk-cybersec Aug 8, 2026
47c1f01
fix: align frontend with HttpOnly cookie auth and repair stale tests
pk-cybersec Sep 2, 2026
ab7ffc5
fix(security): resolve Bandit B105 hardcoded-password finding in init…
pk-cybersec Sep 2, 2026
06fb5c2
fix(security): resolve Bandit B110 try-except-pass finding in evidenc…
pk-cybersec Sep 2, 2026
8377629
fix(mypy): add missing __init__.py to app/core to stop it shadowing s…
pk-cybersec Sep 2, 2026
149cda9
fix(mypy): add type annotation for SCAN_MEM in evidence_ui app
pk-cybersec Sep 2, 2026
3b146b0
ci: disable ts-standard linter (project uses oxlint, not eslint/stand…
pk-cybersec Sep 2, 2026
0ad2341
style(frontend): apply prettier formatting to api client files
pk-cybersec Sep 2, 2026
31b7784
ci: disable jscpd and ts-standard in legacy security workflow (same f…
pk-cybersec Sep 2, 2026
f7bd0c1
fix(security): stop printing admin password in clear text during db s…
pk-cybersec Sep 5, 2026
85d721a
Merge remote-tracking branch 'origin/main' into feature/google-sso-auth
pk-cybersec Sep 5, 2026
887e4d4
fix(backend-api): resolve duplicate Alembic migration heads from main…
pk-cybersec Sep 5, 2026
84952a1
fix(backend-api): stop update_users_me/change_password opening a seco…
pk-cybersec Sep 5, 2026
5300d68
test(backend-api): add pytest+httpx integration suite for auth endpoints
pk-cybersec Sep 5, 2026
9e9d48a
test(backend-api): extend integration suite to scan and evidence endp…
pk-cybersec Sep 5, 2026
beeee95
ci(backend-api): run the pytest integration suite on every PR
pk-cybersec Sep 5, 2026
51f3813
fix(backend-api): suppress Bandit false positives in the test suite
pk-cybersec Sep 5, 2026
915b0c9
fix: resolve pre-existing mypy errors newly surfaced by real app imports
pk-cybersec Sep 5, 2026
a0b489a
fix: resolve remaining mypy no-redef and arg-type errors
pk-cybersec Sep 5, 2026
9bcb227
fix: resolve mypy module-identity collision and alembic op false posi…
pk-cybersec Sep 5, 2026
596b920
test(backend-api): add create_scan happy-path coverage
pk-cybersec Sep 5, 2026
a729d71
feat(engine): add E8-UAH-2.1 Office child-process blocking control
pk-cybersec Sep 5, 2026
8d9096a
fix(ci): reformat metadata.json for Prettier; exclude JSCPD/TS_STANDA…
pk-cybersec Sep 5, 2026
b949f08
feat(engine): automate CIS 5.2.2.2, 5.2.2.9, 5.2.2.12 (MFA, managed d…
pk-cybersec Sep 5, 2026
59c99c5
Merge branch 'main' into feature/google-sso-auth
s225645819 Sep 7, 2026
a13556c
Fix CI: use uv dependency group for dev deps, complete PR comment try…
s225645819 Sep 7, 2026
269d211
Fix remaining CI failures: duplicate migration head, pylint, missing …
s225645819 Sep 7, 2026
25fd214
Fix Pytest job missing database, restore /readiness endpoint lost in …
s225645819 Sep 7, 2026
9b6b325
Fix RBAC test failures: elevate test user to Auditor for scan create/…
s225645819 Sep 7, 2026
1a4e0e5
Merge branch 'main' into feature/google-sso-auth
s225645819 Sep 8, 2026
cce021b
Merge alembic heads k1l2m3n4o567 and l1m2n3o4p567
s225645819 Sep 8, 2026
8b4a8a6
Fix lint and mypy errors in alembic merge migration
s225645819 Sep 8, 2026
65626cd
Merge branch 'main' into feature/google-sso-auth
s225645819 Sep 12, 2026
c1f444e
Fix post-merge CI failures: regenerate uv.lock and format metadata.json
s225645819 Sep 12, 2026
751691d
Fix remaining post-merge CI failures
s225645819 Sep 12, 2026
4c1fb00
Add missing Postgres service to the coverage job
s225645819 Sep 12, 2026
667e13e
Merge branch 'main' into feature/google-sso-auth
s225645819 Sep 13, 2026
9757700
Fix CI checks broken by the main merge
s225645819 Sep 13, 2026
bad0c69
Fix CORS to use FRONTEND_URL instead of a hardcoded localhost origin
s225645819 Sep 13, 2026
d295119
Fix cross-tool false positives from regenerated security baselines
s225645819 Sep 13, 2026
0b5304a
Restrict /metrics to superusers
s225645819 Sep 14, 2026
9279506
fix(frontend): gate dashboard data loading on isAuthenticated, not token
s225645819 Sep 14, 2026
11a1185
fix(backend): clear OAuth state cookie on every Google callback failu…
s225645819 Sep 14, 2026
53cf10f
test(frontend): add regression coverage for dashboard auth gating
s225645819 Sep 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions .github/linters/.mypy.ini
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
[mypy]
# Files across backend-api/ and its tests import each other as "app.*" /
# "tests.*" (e.g. tests/conftest.py does `from app.main import app`), but
# backend-api/app has no __init__.py, so plain mypy can't decide whether a
# file like backend-api/app/main.py should be identified as module "main"
# or "app.main". When super-linter passes several changed files to mypy in
# one invocation, that ambiguity surfaces as:
# error: Source file found twice under different module names
# explicit_package_bases + mypy_path pins module identity relative to
# backend-api, so it is always resolved consistently as "app.main".
mypy_path = backend-api
explicit_package_bases = True
ignore_missing_imports = True
119 changes: 112 additions & 7 deletions .github/workflows/ci.backend-api.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ permissions:
jobs:
analyze:
name: Security Analysis on (${{ matrix.language }})
runs-on: ${{ (matrix.language == 'swift' && 'macos-latest') || 'ubuntu-latest' }}
runs-on: ubuntu-latest
permissions:
security-events: write
packages: read
Expand Down Expand Up @@ -79,7 +79,7 @@ jobs:
fetch-depth: 0

- name: Lint Code Base
uses: github/super-linter@454ba4482ce2cd0c505bc592e83c06e1e37ade61 # v4
uses: github/super-linter@v7
env:
VALIDATE_ALL_CODEBASE: false
DEFAULT_BRANCH: "main"
Expand All @@ -92,41 +92,143 @@ jobs:
VALIDATE_PYTHON_FLAKE8: false
VALIDATE_PYTHON_ISORT: false
VALIDATE_JAVASCRIPT_STANDARD: false
VALIDATE_TYPESCRIPT_STANDARD: false
VALIDATE_HTML: false
VALIDATE_MARKDOWN: false
VALIDATE_MARKDOWN_PRETTIER: false
VALIDATE_NATURAL_LANGUAGE: false
VALIDATE_PYTHON_PYLINT: false
VALIDATE_PYTHON_RUFF: false
VALIDATE_PYTHON_PYINK: false
VALIDATE_JSCPD: false
VALIDATE_CHECKOV: false
VALIDATE_YAML_PRETTIER: false

backend-tests:
name: Integration Tests (pytest)
runs-on: ubuntu-latest
services:
postgres:
image: postgres:16
env:
POSTGRES_USER: autoaudit
POSTGRES_PASSWORD: autoaudit_dev_password
POSTGRES_DB: autoaudit_test
ports:
- 5432:5432
options: >-
--health-cmd pg_isready
--health-interval 10s
--health-timeout 5s
--health-retries 5

steps:
- name: Checkout repository
uses: actions/checkout@v4
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed

- name: Install system dependencies (Tesseract for evidence OCR)
run: |
sudo apt-get update
sudo apt-get install -y --no-install-recommends tesseract-ocr libtesseract-dev

- name: Set up Python
uses: actions/setup-python@v5
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
with:
python-version: '3.11'

- name: Install uv
uses: astral-sh/setup-uv@v4
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed

- name: Install dependencies
working-directory: backend-api
run: uv sync --frozen --extra evidence

- name: Run integration test suite
working-directory: backend-api
# DATABASE_URL etc. are intentionally left unset here: tests/conftest.py
# sets matching defaults (os.environ.setdefault) that point at this same
# postgres service (db autoaudit_test, user/password autoaudit), and
# runs `alembic upgrade head` itself before any test executes -- so a
# separate migration step isn't needed, this just has to be the same
# entrypoint a developer runs locally.
run: uv run pytest -v

test:
name: Pytest
runs-on: ubuntu-latest
services:
postgres:
image: postgres:16
env:
POSTGRES_USER: autoaudit
POSTGRES_PASSWORD: autoaudit_dev_password
POSTGRES_DB: autoaudit_test
ports:
- 5432:5432
options: >-
--health-cmd pg_isready
--health-interval 10s
--health-timeout 5s
--health-retries 5
steps:
- name: Checkout repository
uses: actions/checkout@v4

- name: Install system dependencies (Tesseract for evidence OCR)
run: |
sudo apt-get update
sudo apt-get install -y --no-install-recommends tesseract-ocr libtesseract-dev

- name: Set up uv
uses: astral-sh/setup-uv@v4

- name: Install and run pytest
working-directory: backend-api
# DATABASE_URL etc. are intentionally left unset here: tests/conftest.py
# sets matching defaults (os.environ.setdefault) that point at this same
# postgres service, and runs `alembic upgrade head` itself before any
# test executes (see backend-tests job above for the same setup).
run: |
uv sync --extra dev --extra evidence
uv sync --group dev --extra evidence
uv run pytest tests/ -q

coverage:
name: Pytest coverage
runs-on: ubuntu-latest
services:
postgres:
image: postgres:16
env:
POSTGRES_USER: autoaudit
POSTGRES_PASSWORD: autoaudit_dev_password
POSTGRES_DB: autoaudit_test
ports:
- 5432:5432
options: >-
--health-cmd pg_isready
--health-interval 10s
--health-timeout 5s
--health-retries 5
steps:
- name: Checkout repository
uses: actions/checkout@v4

- name: Install system dependencies (Tesseract for evidence OCR)
run: |
sudo apt-get update
sudo apt-get install -y --no-install-recommends tesseract-ocr libtesseract-dev

- name: Set up uv
uses: astral-sh/setup-uv@v4

- name: Install and run coverage
working-directory: backend-api
# DATABASE_URL etc. are intentionally left unset here: tests/conftest.py
# sets matching defaults (os.environ.setdefault) that point at this same
# postgres service, and runs `alembic upgrade head` itself before any
# test executes (see the test job above for the same setup).
run: |
uv sync --extra dev
uv sync --group dev --extra evidence
uv run pytest tests/ \
--cov=app \
--cov-report=term-missing \
Expand All @@ -152,7 +254,8 @@ jobs:

report:
name: Report PR status
needs: [analyze, run-lint, test, coverage]

needs: [analyze, run-lint, backend-tests, test, coverage]
if: always() && github.event_name == 'pull_request'
runs-on: ubuntu-latest
permissions:
Expand All @@ -177,11 +280,12 @@ jobs:

const analyze = '${{ needs.analyze.result }}';
const lint = '${{ needs.run-lint.result }}';
const integration = '${{ needs.backend-tests.result }}';
const test = '${{ needs.test.result }}';
const coverage = '${{ needs.coverage.result }}';

const icon = r => ({ success: '✅', failure: '❌', cancelled: '🚫', skipped: '⏭️' }[r] ?? '❓');
const allPassed = [analyze, lint, test, coverage].every(r => ['success', 'skipped'].includes(r));
const allPassed = [analyze, lint, integration, test, coverage].every(r => ['success', 'skipped'].includes(r));
const runUrl = `https://github.com/${context.repo.owner}/${context.repo.repo}/actions/runs/${context.runId}`;

const body = [
Expand All @@ -192,6 +296,7 @@ jobs:
`|---|---|`,
`| Security analysis (CodeQL + Bandit) | ${icon(analyze)} \`${analyze}\` |`,
`| Lint | ${icon(lint)} \`${lint}\` |`,
`| Integration tests (pytest) | ${icon(integration)} \`${integration}\` |`,
`| Pytest | ${icon(test)} \`${test}\` |`,
`| Pytest coverage | ${icon(coverage)} \`${coverage}\` |`,
``,
Expand All @@ -206,4 +311,4 @@ jobs:
uses: ./.github/actions/pr-status-comment
with:
marker: '<!-- ci-report-backend-api -->'
body: ${{ steps.build.outputs.body }}
body: ${{ steps.build.outputs.body }}
7 changes: 7 additions & 0 deletions .github/workflows/ci.engine.yml
Original file line number Diff line number Diff line change
Expand Up @@ -70,6 +70,13 @@ jobs:
VALIDATE_MARKDOWN: false
VALIDATE_NATURAL_LANGUAGE: false
VALIDATE_MARKDOWN_PRETTIER: false
# Matches ci.backend-api.yml: JSCPD and TS_STANDARD are not enforced
# in this repo. Without these, super-linter's PR-diff mode (VALIDATE_ALL_CODEBASE:
# false) also re-lints frontend/ files changed earlier in the same PR whenever
# this engine/**-triggered workflow runs, even though this job only exists to
# gate engine/ changes.
VALIDATE_JSCPD: false
VALIDATE_TYPESCRIPT_STANDARD: false

test:
name: Run Engine Tests
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/ci.frontend.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ jobs:
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4

- name: Initialize CodeQL
uses: github/codeql-action/init@6f5948dfacef28e207b48d0905cf90c03365536d # v3
uses: github/codeql-action/init@v4 # <-- Change this one to v4
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
Expand All @@ -49,7 +49,7 @@ jobs:
exit 1

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@6f5948dfacef28e207b48d0905cf90c03365536d # v3
uses: github/codeql-action/analyze@v4 # <-- Change this one to v4
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
with:
category: "/language:${{matrix.language}}"

Expand All @@ -68,7 +68,7 @@ jobs:
- name: Setup Node.js
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
with:
node-version: 20
node-version: 22 # <-- Change from 20 to 22
cache: npm
cache-dependency-path: frontend/package-lock.json

Expand All @@ -93,7 +93,7 @@ jobs:
- name: Setup Node.js
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
with:
node-version: 20
node-version: 22 # <-- Change from 20 to 22
cache: npm
cache-dependency-path: frontend/package-lock.json

Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/ci.security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -72,6 +72,8 @@ jobs:
VALIDATE_PYTHON_FLAKE8: false
VALIDATE_PYTHON_ISORT: false
VALIDATE_JAVASCRIPT_STANDARD: false
VALIDATE_TYPESCRIPT_STANDARD: false
VALIDATE_JSCPD: false
VALIDATE_HTML: false
VALIDATE_MARKDOWN: false
VALIDATE_NATURAL_LANGUAGE: false
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
"""merge k1l2m3n4o567 and l1m2n3o4p567 heads

Revision ID: e5f6a7b8c9d0
Revises: k1l2m3n4o567, l1m2n3o4p567
Create Date: 2026-09-08 00:00:00.000000

"""
from typing import Sequence, Union


# revision identifiers, used by Alembic.
revision: str = 'e5f6a7b8c9d0'
down_revision: Union[str, Sequence[str], None] = ('k1l2m3n4o567', 'l1m2n3o4p567')
branch_labels: Union[str, Sequence[str], None] = None
depends_on: Union[str, Sequence[str], None] = None


def upgrade() -> None:
"""Upgrade schema. No-op merge revision; reconciles the two heads."""


def downgrade() -> None:
"""Downgrade schema. No-op merge revision; reconciles the two heads."""
Loading
Loading