Skip to content

ci: add SAST (Semgrep + Gitleaks) - #63

Merged
jessie-coco merged 1 commit into
mainfrom
ci/sast-setup
May 9, 2026
Merged

jessie-coco merged 1 commit into
mainfrom
ci/sast-setup

Conversation

@owen0x6f

@owen0x6f owen0x6f commented May 9, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Add Semgrep SAST scanning for security vulnerabilities
  • Add Gitleaks secret detection to prevent credential leaks
  • SOC 2 compliance requirement (SA-1-6)

Test plan

  • Semgrep scan passes on this PR
  • Gitleaks scan passes on this PR

🤖 Generated with Claude Code

SOC 2 compliance: enable static application security testing
for all pull requests. Hugo deploy workflow already exists.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@jessie-coco jessie-coco left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — standard SAST workflow (Semgrep + Gitleaks), CI green. Merging.

@jessie-coco
jessie-coco merged commit 7c9244c into main May 9, 2026
2 checks passed
@jessie-coco
jessie-coco deleted the ci/sast-setup branch May 9, 2026 09:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants