JS Security Testing in GitHub Actions

This ad is not shown to multipass and full ticket holders
React Advanced
React Advanced 2026
October 23 - 26, 2026
London, UK & Online
Upcoming event
React Advanced 2026
React Advanced 2026
October 23 - 26, 2026. London, UK & Online
Bookmark
Rate this content

This workshop will focus on automating software composition analysis, static application security testing and dynamic application security testing using GitHub Actions. After a brief introduction covering the different types of application security and the importance of finding security vulnerabilities before they hit production, we'll dive into a hands-on session where users will add three different security testing tool to their build pipelines.

This workshop has been presented at DevOps.js Conf 2022, check out the latest edition of this JavaScript Conference.

FAQ

GitHub Actions is a CI/CD platform built into GitHub that allows you to automate software development workflows, including building, testing, and deploying code directly from GitHub. It can be triggered by various events like push, pull requests, merges, etc.

You can run security tests on a JavaScript Node app using GitHub Actions by setting up workflows that include steps for dependency scanning (SCA), static application security testing (SAST), and dynamic application security testing (DAST). This can be done using tools like Dependabot, CodeQL, and StackHawk.

The prerequisites for setting up GitHub Actions for a Node.js application include a GitHub account, a Node.js application repository, and access to GitHub Actions. Optionally, you may also need tools like Dependabot, CodeQL, and StackHawk for comprehensive security testing.

Dependabot is a GitHub tool used for Software Composition Analysis (SCA). It scans your application's dependencies for known vulnerabilities and can automatically issue pull requests to update dependencies to secure versions.

CodeQL helps in detecting vulnerabilities by performing Static Application Security Testing (SAST) on your code. It scans your codebase for patterns that match known vulnerabilities and alerts you to potential security issues.

StackHawk is a dynamic application security testing (DAST) tool that scans your running application for vulnerabilities. It integrates with GitHub Actions by using an action that can be added to your workflow, enabling automated security scans of your live code.

To configure Dependabot, navigate to the 'Settings' tab of your GitHub repository, go to 'Code security and analysis,' and enable 'Dependency graph,' 'Dependabot alerts,' and 'Dependabot security updates.' Dependabot will then start scanning your dependencies for vulnerabilities.

To set up CodeQL analysis, go to the 'Security' tab in your GitHub repository, click on 'Set up code scanning,' and follow the prompts to configure CodeQL. This will add a YAML file to your repository that defines the CodeQL analysis workflow.

If your GitHub Actions workflows are running slowly or not starting, you can try committing a small change to your repository to trigger the workflow again. If the issue persists, check GitHub's status page for any ongoing incidents or delays with GitHub Actions.

To use StackHawk for dynamic application security testing, sign up for a free StackHawk account, configure your StackHawk YAML file with your application details, and add the StackHawk action to your GitHub Actions workflow. This will enable automated security scans of your running application.

Nick Teets
Nick Teets
29 Mar, 2022
Video transcription, chapters and summary will be available after the recording is published.