Skip to content

feat: 利用Github Action进行代码安全扫描,并生成报告#68

Closed
nap0o wants to merge 0 commit intoshuaiplus:mainfrom
nap0o:main
Closed

feat: 利用Github Action进行代码安全扫描,并生成报告#68
nap0o wants to merge 0 commit intoshuaiplus:mainfrom
nap0o:main

Conversation

@nap0o
Copy link
Contributor

@nap0o nap0o commented Mar 9, 2026

NodeWarden 是对安全性要求很高的项目,用github action在每次push时自动扫描代码安全漏洞

  • 用Gitleaks检测检查代码中的敏感信息
  • 用Snyk检查依赖包漏洞(需要配置 SNYK_TOKEN 秘钥)
  • 用CodeQL静态代码安全分析

大佬代码写的很好,只有几个warning
https://github.com/nap0o/nodewarden/tree/security-audit

ps:我也在折腾一个2FA的项目: 2FAuth Worker ,向大佬学习。

@shuaiplus
Copy link
Owner

谢谢,我这几天出差,过几天仔细研究一下再合并

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants