Security checks that run once a quarter find problems long after they are cheap to fix. Moving them into the pull request means the person who introduced the issue sees it while the change is still fresh.
Three checks worth having first
- Dependency audit: fail on known high-severity vulnerabilities in packages.
- Static analysis: catch injection, unsafe deserialization and similar patterns in your own code.
- Secret scanning: stop API keys and tokens before they reach the main branch.
The workflow
name: security
on: [pull_request]
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Dependency audit
run: npm audit --audit-level=high
- name: Static analysis
run: |
pipx install semgrep
semgrep scan --config auto --error
- name: Secret scan
uses: gitleaks/gitleaks-action@v2Keeping it usable
A pipeline that fails on every pull request gets ignored or bypassed. Start by failing only on high severity, record the existing findings as a baseline, and tighten the threshold once the backlog is cleared.