Add Level 0 + Level 1 + Level 2 security scanning #16

Merged
testclient-admin merged 3 commits from add-security-scanning into main 2026-08-25 04:03:04 +00:00
Owner

Level 0: semgrep + gitleaks (на каждый PR). Level 1: headless AI PR review, coder-fast (на каждый PR). Level 2: Deep Security Audit, coder-think, 6 доменных агентов + верификатор (по запросу, workflow_dispatch на security.yml). Находки — в security-analysis/, комментарии и статусы — от имени <проект>-security-bot.

Level 0: semgrep + gitleaks (на каждый PR). Level 1: headless AI PR review, coder-fast (на каждый PR). Level 2: Deep Security Audit, coder-think, 6 доменных агентов + верификатор (по запросу, workflow_dispatch на security.yml). Находки — в security-analysis/, комментарии и статусы — от имени <проект>-security-bot.
testclient-admin added 3 commits 2026-08-25 03:08:10 +00:00
Level 0: security scanning for pull requests
security/scan 3 findings, 3 blocking
security / scan (pull_request) Failing after 56s
security/review 0 findings, 0 blocking
security / review (pull_request) Successful in 1m27s
security / deep-audit (pull_request) Skipped
d9d1da21ed
testclient-admin added 1 commit 2026-08-25 03:08:10 +00:00
Level 0: security scanning for pull requests
security/scan 3 findings, 3 blocking
security / scan (pull_request) Failing after 56s
security/review 0 findings, 0 blocking
security / review (pull_request) Successful in 1m27s
security / deep-audit (pull_request) Skipped
d9d1da21ed
Collaborator

Security scan (Level 0)

  • HIGH: 3

HIGH README.md:27 — Potential secret: curl-auth-header (gitleaks)

HIGH README.md:36 — Potential secret: curl-auth-header (gitleaks)

HIGH README.md:52 — Potential secret: curl-auth-header (gitleaks)

🔴 Merge заблокирован — есть находки выше порога security-analysis/policy.yml.

## Security scan (Level 0) - **HIGH**: 3 **HIGH** `README.md:27` — Potential secret: curl-auth-header (gitleaks) **HIGH** `README.md:36` — Potential secret: curl-auth-header (gitleaks) **HIGH** `README.md:52` — Potential secret: curl-auth-header (gitleaks) 🔴 **Merge заблокирован** — есть находки выше порога `security-analysis/policy.yml`.
Collaborator

AI Security Review (Level 1)

Находок нет.
Порог не превышен.

## AI Security Review (Level 1) Находок нет. ✅ Порог не превышен.
Collaborator

Security scan (Level 0)

  • HIGH: 3

HIGH README.md:27 — Potential secret: curl-auth-header (gitleaks)

HIGH README.md:36 — Potential secret: curl-auth-header (gitleaks)

HIGH README.md:52 — Potential secret: curl-auth-header (gitleaks)

🔴 Merge заблокирован — есть находки выше порога security-analysis/policy.yml.

## Security scan (Level 0) - **HIGH**: 3 **HIGH** `README.md:27` — Potential secret: curl-auth-header (gitleaks) **HIGH** `README.md:36` — Potential secret: curl-auth-header (gitleaks) **HIGH** `README.md:52` — Potential secret: curl-auth-header (gitleaks) 🔴 **Merge заблокирован** — есть находки выше порога `security-analysis/policy.yml`.
Collaborator

AI Security Review (Level 1)

Находок нет.
Порог не превышен.

## AI Security Review (Level 1) Находок нет. ✅ Порог не превышен.
testclient-admin merged commit 789aa6adaa into main 2026-08-25 04:03:04 +00:00
Sign in to join this conversation.
No Reviewers
No labels
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: i.kologriv/playground#16