Skip to content

ci: run code scan only when dependency files change - #498

Open
yaroslavmokflmg wants to merge 6 commits into
mainfrom
hotfix/conditional-code-scan
Open

yaroslavmokflmg wants to merge 6 commits into
mainfrom
hotfix/conditional-code-scan

Conversation

@yaroslavmokflmg

@yaroslavmokflmg yaroslavmokflmg commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

The trivy action now checks (dorny/paths-filter) whether the PR touched anything under the scan path, minus skip-dirs, or the root pom.xml, .trivyignore or the action itself; otherwise the scan is skipped. Same action in every repo, workflows only grant pull-requests: read.

Change-Set: hotfix-conditional-code-scan

Change set flamingo-stack/fleetmdm#219: these pull requests are one change, reviewed together.

Merge order: flamingo-stack/fleetmdm#219 → flamingo-stack/meshcentral#213 → #498 → flamingo-stack/openframe-oss-tenant#2379

Linked by the Depends-On / Change-Set lines in these descriptions; this block is maintained by the hub.

@yaroslavmokflmg
yaroslavmokflmg requested review from a team as code owners September 28, 2026 08:24
@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

🦩 Flamingo Code Review

1 finding(s) — 1 action required · 0 recommended · 0 informational

Mode: advisory · 1 defect(s) outside any rule

Inline comments: 1 new

Change set

  • Not linked to flamingo-stack/openframe-oss-tenant#2379, flamingo-stack/fleetmdm#219, flamingo-stack/meshcentral#213, flamingo-stack/openframe-oss-lib#2408 (open, same branch name). If this pull request needs one of them merged first, add a line to this pull request's description:
  • Depends-On: https://github.com/flamingo-stack/openframe-oss-tenant/pull/2379
  • Depends-On: https://github.com/flamingo-stack/fleetmdm/pull/219
  • Depends-On: https://github.com/flamingo-stack/meshcentral/pull/213
  • Depends-On: https://github.com/flamingo-stack/openframe-oss-lib/pull/2408
  • The Flamingo reviewer then checks imports and consumers against that pull request’s branch and states the merge order.

Need another pass? Commits pushed after this review are not reviewed automatically.

  • Review the new commits — the commits added since this review
  • Review the whole diff again — ignoring what was already reviewed

Prefer typing? Comment @flamingo-review, or @flamingo-review full. To review every push on this pull request, add the flamingo-review-always label.

React 👍/👎 on inline comments to teach the reviewer.

Started 2026-09-28 08:25 UTC · updated 2026-09-28 08:26 UTC · workflow run

Comment thread .github/workflows/test.yml Outdated
Comment on lines +35 to +53
- name: Check if scan should run
id: should_run
uses: dorny/paths-filter@v4.0.2
with:
filters: |
deps:
- '**/pom.xml'
- '.mvn/**'
- '**/package.json'
- '**/package-lock.json'
- '**/yarn.lock'
- '**/pnpm-lock.yaml'
- '**/go.mod'
- '**/go.sum'
- '**/Cargo.toml'
- '**/Cargo.lock'
- '**/Dockerfile*'
- '.trivyignore'
- '.github/steps/trivy/**'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🦩 🔴 [warn/action_required] Trivy code scan is skipped entirely when path filter does not match, defeating its security purpose

The new paths-filter gate makes the 'Checkout' and 'Scan code' steps conditional on steps.should_run.outputs.deps == 'true', where deps only triggers on manifest/lockfile/Dockerfile changes (pom.xml, package.json, go.mod, Cargo.toml, Dockerfile*, etc.). Trivy's scan: code step normally performs source code security scanning (SAST-style, e.g. secret/code vulnerability scanning), not just dependency scanning. By gating the whole scan job on dependency-manifest changes only, any PR that changes application source code (e.g. .ts/.tsx files) without touching a lockfile will silently skip the scan entirely, and the job step reports as skipped/success. This weakens security coverage for the majority of code-only PRs to this frontend repo, since most changes here are TypeScript/TSX source, not dependency manifests. Either widen the filter to include source file globs relevant to this repo's languages (js/ts/tsx) or split the code-scan and dependency-scan steps so an actual code scan still runs on source changes.

Evidence
      - name: Check if scan should run
        id: should_run
        uses: dorny/paths-filter@v4.0.2
        with:
          filters: |
            deps:
              - '**/pom.xml'
              - '.mvn/**'
              - '**/package.json'
              - '**/package-lock.json'
              - '**/yarn.lock'
              - '**/pnpm-lock.yaml'
🤖 Prompt for AI agents
In .github/workflows/test.yml around lines 35-53, address this code-review finding: Trivy code scan is skipped entirely when path filter does not match, defeating its security purpose.
The new `paths-filter` gate makes the 'Checkout' and 'Scan code' steps conditional on `steps.should_run.outputs.deps == 'true'`, where `deps` only triggers on manifest/lockfile/Dockerfile changes (pom.xml, package.json, go.mod, Cargo.toml, Dockerfile*, etc.). Trivy's `scan: code` step normally performs source code security scanning (SAST-style, e.g. secret/code vulnerability scanning), not just dependency scanning. By gating the whole scan job on dependency-manifest changes only, any PR that changes application source code (e.g. .ts/.tsx files) without touching a lockfile will silently skip the scan entirely, and the job step reports as skipped/success. This weakens security coverage for the majority of code-only PRs to this frontend repo, since most changes here are TypeScript/TSX source, not dependency manifests. Either widen the filter to include source file globs relevant to this repo's languages (js/ts/tsx) or split the code-scan and dependency-scan steps so an actual code scan still runs on source changes.
The flagged code:
```
      - name: Check if scan should run
        id: should_run
        uses: dorny/paths-filter@v4.0.2
        with:
          filters: |
            deps:
              - '**/pom.xml'
              - '.mvn/**'
              - '**/package.json'
              - '**/package-lock.json'
              - '**/yarn.lock'
              - '**/pnpm-lock.yaml'
              - '**/go.mod'
              - '**/go.sum'
              - '**/Cargo.toml'
              - '**/Cargo.lock'
              - '**/Dockerfile*'
              - '.trivyignore'
              - '.github/steps/trivy/**'
```
Make the minimal change that resolves the finding; do not refactor unrelated code.

confidence: 45 — react 👍/👎 to teach the reviewer

@yaroslavmokflmg yaroslavmokflmg changed the title ci: run code scan only when dependency manifests change ci: run code scan only when the scanned path changes Sep 28, 2026
@yaroslavmokflmg yaroslavmokflmg changed the title ci: run code scan only when the scanned path changes ci: run code scan only when dependency files change Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant