All writeups
DevOps

Adding Security Checks to a GitHub Actions Pipeline

Dependency audit, static analysis and secret scanning on every pull request, without slowing the team down.

Aug 14, 2026 · 6 min read

Security checks that run once a quarter find problems long after they are cheap to fix. Moving them into the pull request means the person who introduced the issue sees it while the change is still fresh.

Three checks worth having first

  • Dependency audit: fail on known high-severity vulnerabilities in packages.
  • Static analysis: catch injection, unsafe deserialization and similar patterns in your own code.
  • Secret scanning: stop API keys and tokens before they reach the main branch.

The workflow

yaml
name: security
on: [pull_request]

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0

      - name: Dependency audit
        run: npm audit --audit-level=high

      - name: Static analysis
        run: |
          pipx install semgrep
          semgrep scan --config auto --error

      - name: Secret scan
        uses: gitleaks/gitleaks-action@v2

Keeping it usable

A pipeline that fails on every pull request gets ignored or bypassed. Start by failing only on high severity, record the existing findings as a baseline, and tighten the threshold once the backlog is cleared.

GitHub ActionsSemgrepGitleaksDevSecOps