ci: run code scan only when dependency files change - #498
yaroslavmokflmg wants to merge 6 commits into
Conversation
🦩 Flamingo Code Review1 finding(s) — 1 action required · 0 recommended · 0 informational Mode: advisory · 1 defect(s) outside any rule Inline comments: 1 new Change set
Need another pass? Commits pushed after this review are not reviewed automatically.
Prefer typing? Comment React 👍/👎 on inline comments to teach the reviewer. Started 2026-09-28 08:25 UTC · updated 2026-09-28 08:26 UTC · workflow run |
| - name: Check if scan should run | ||
| id: should_run | ||
| uses: dorny/paths-filter@v4.0.2 | ||
| with: | ||
| filters: | | ||
| deps: | ||
| - '**/pom.xml' | ||
| - '.mvn/**' | ||
| - '**/package.json' | ||
| - '**/package-lock.json' | ||
| - '**/yarn.lock' | ||
| - '**/pnpm-lock.yaml' | ||
| - '**/go.mod' | ||
| - '**/go.sum' | ||
| - '**/Cargo.toml' | ||
| - '**/Cargo.lock' | ||
| - '**/Dockerfile*' | ||
| - '.trivyignore' | ||
| - '.github/steps/trivy/**' |
There was a problem hiding this comment.
🦩 🔴 [warn/action_required] Trivy code scan is skipped entirely when path filter does not match, defeating its security purpose
The new paths-filter gate makes the 'Checkout' and 'Scan code' steps conditional on steps.should_run.outputs.deps == 'true', where deps only triggers on manifest/lockfile/Dockerfile changes (pom.xml, package.json, go.mod, Cargo.toml, Dockerfile*, etc.). Trivy's scan: code step normally performs source code security scanning (SAST-style, e.g. secret/code vulnerability scanning), not just dependency scanning. By gating the whole scan job on dependency-manifest changes only, any PR that changes application source code (e.g. .ts/.tsx files) without touching a lockfile will silently skip the scan entirely, and the job step reports as skipped/success. This weakens security coverage for the majority of code-only PRs to this frontend repo, since most changes here are TypeScript/TSX source, not dependency manifests. Either widen the filter to include source file globs relevant to this repo's languages (js/ts/tsx) or split the code-scan and dependency-scan steps so an actual code scan still runs on source changes.
Evidence
- name: Check if scan should run
id: should_run
uses: dorny/paths-filter@v4.0.2
with:
filters: |
deps:
- '**/pom.xml'
- '.mvn/**'
- '**/package.json'
- '**/package-lock.json'
- '**/yarn.lock'
- '**/pnpm-lock.yaml'
🤖 Prompt for AI agents
In .github/workflows/test.yml around lines 35-53, address this code-review finding: Trivy code scan is skipped entirely when path filter does not match, defeating its security purpose.
The new `paths-filter` gate makes the 'Checkout' and 'Scan code' steps conditional on `steps.should_run.outputs.deps == 'true'`, where `deps` only triggers on manifest/lockfile/Dockerfile changes (pom.xml, package.json, go.mod, Cargo.toml, Dockerfile*, etc.). Trivy's `scan: code` step normally performs source code security scanning (SAST-style, e.g. secret/code vulnerability scanning), not just dependency scanning. By gating the whole scan job on dependency-manifest changes only, any PR that changes application source code (e.g. .ts/.tsx files) without touching a lockfile will silently skip the scan entirely, and the job step reports as skipped/success. This weakens security coverage for the majority of code-only PRs to this frontend repo, since most changes here are TypeScript/TSX source, not dependency manifests. Either widen the filter to include source file globs relevant to this repo's languages (js/ts/tsx) or split the code-scan and dependency-scan steps so an actual code scan still runs on source changes.
The flagged code:
```
- name: Check if scan should run
id: should_run
uses: dorny/paths-filter@v4.0.2
with:
filters: |
deps:
- '**/pom.xml'
- '.mvn/**'
- '**/package.json'
- '**/package-lock.json'
- '**/yarn.lock'
- '**/pnpm-lock.yaml'
- '**/go.mod'
- '**/go.sum'
- '**/Cargo.toml'
- '**/Cargo.lock'
- '**/Dockerfile*'
- '.trivyignore'
- '.github/steps/trivy/**'
```
Make the minimal change that resolves the finding; do not refactor unrelated code.
confidence: 45 — react 👍/👎 to teach the reviewer
The trivy action now checks (dorny/paths-filter) whether the PR touched anything under the scan path, minus skip-dirs, or the root pom.xml, .trivyignore or the action itself; otherwise the scan is skipped. Same action in every repo, workflows only grant pull-requests: read.
Change-Set: hotfix-conditional-code-scan
Change set
flamingo-stack/fleetmdm#219: these pull requests are one change, reviewed together.Merge order: flamingo-stack/fleetmdm#219 → flamingo-stack/meshcentral#213 → #498 → flamingo-stack/openframe-oss-tenant#2379
Linked by the
Depends-On/Change-Setlines in these descriptions; this block is maintained by the hub.