Currently supported versions for security updates:
| Version | Supported |
|---|---|
| 1.x.x | ✅ |
| < 1.0 | ❌ |
To report a security vulnerability:
- DO NOT open a public issue
- Email security concerns to: rick.cogley@esolia.co.jp
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
Response time:
- Acknowledgment: Within 48 hours
- Initial assessment: Within 7 days
- Fix timeline: Based on severity
Nagare validates inputs in several areas:
- File paths are checked for valid patterns
- Version strings are validated against semver
- Git commands use Deno's Command API (not shell execution)
- Configuration files are type-checked
- GitHub authentication is delegated to the
ghCLI tool - No credentials are stored or managed by Nagare
- Uses GitHub's OAuth flow through
gh auth login
- Operates under Deno's permission model
- Requires explicit
--allow-read,--allow-write,--allow-runpermissions - File operations are limited to project directory
- Uses safe regex patterns for file updates
Nagare minimizes dependencies:
@std/semver: Deno standard library for version handlingvento: Template engine with no known vulnerabilities
All dependencies are:
- Fetched from JSR (Deno's secure registry)
- Version-pinned with integrity checking
- Regularly updated for security patches
Nagare leverages GitHub's comprehensive security platform to maintain code quality and prevent vulnerabilities:
-
CodeQL Analysis: Advanced semantic code analysis that automatically scans for security vulnerabilities
- Detects: SQL injection, XSS, path traversal, insecure data flow, and more
- Runs: On every push, pull request, and weekly deep scans
- Results: Appear in GitHub Security tab with detailed remediation guidance
-
DevSkim: Microsoft's lightweight security linter for real-time pattern detection
- Detects: Common security anti-patterns across multiple languages
- Runs: On every push and pull request
- Coverage: Regex-based pattern matching for quick security checks
- Complements: CodeQL's deep analysis with fast pattern-based scanning
-
Dependabot: Automated dependency management that keeps dependencies secure
- Monitors: All dependencies for known vulnerabilities
- Creates: Automatic pull requests to update vulnerable packages
- Groups: Related updates to reduce PR noise
- Supports: GitHub Actions and npm dependencies (Deno/JSR support pending)
-
Dependency Review: Pull request protection that prevents introducing vulnerable dependencies
- Blocks: PRs containing high-severity vulnerabilities
- Shows: License changes and vulnerability details
- Integrates: Directly into PR checks for immediate feedback
-
Secret Scanning: Detects and prevents accidental exposure of sensitive data
- Scans: All commits for API keys, tokens, and credentials
- Alerts: Repository admins when secrets are detected
- Push Protection: Can block commits containing secrets (optional)
- Partners: Works with service providers to revoke exposed credentials
All these features are free for public repositories and provide enterprise-grade security monitoring.
-
Custom Templates: Custom Vento templates can execute code. Review all custom templates before use. Key security notes:
- Templates with
autoescape: true(default) automatically escape HTML entities - Use
|> safefilter only when you trust the content source - Always validate template data before processing
- See CLAUDE.md for proper Vento usage
- Templates with
-
Command Execution: While we use Deno's secure Command API, always validate configuration inputs.
-
File Patterns: Custom file update patterns should be carefully reviewed to prevent unintended matches.
-
Minimal Permissions: Only grant required Deno permissions
deno run --allow-read=. --allow-write=. --allow-run=git,gh nagare-launcher.ts
-
Configuration Security:
- Review all file patterns in
nagare.config.ts - Don't commit sensitive data in version files
- Use environment variables for tokens
- Review all file patterns in
-
CI/CD Security:
- Use GitHub Secrets for
GITHUB_TOKEN - Limit workflow permissions
- Review workflow files for security
- Use GitHub Secrets for
-
Code Security:
- Validate all inputs
- Use type-safe operations
- Avoid shell command construction
- Follow OWASP guidelines
-
Dependencies:
- Minimize new dependencies
- Audit before adding
- Keep updated
-
Testing:
- Include security test cases
- Test with minimal permissions
- Verify error handling doesn't leak info
- Safe default configurations
- Type-safe interfaces
- Minimal dependency footprint
- Deno permission model integration
- Enhanced input validation layer (v1.3.0)
- Added comprehensive
security-utils.tsmodule - Git reference validation (
validateGitRef) - File path validation with traversal prevention (
validateFilePath) - Commit message sanitization (
sanitizeCommitMessage) - Version string validation (
validateVersion) - Error message sanitization (
sanitizeErrorMessage) - CLI argument validation (
validateCliArgs)
- Added comprehensive
- Security-focused logging (v1.3.0)
- Added
createSecurityLogfunction for audit trails - Automatic sanitization of sensitive data in logs
- Integrated audit logging in file handlers and template processor
- Added
- Template sandboxing options (v1.6.0)
- Added
SecurityConfiginterface with sandboxing levels - Implemented strict/moderate/disabled sandboxing modes
- Enhanced template validation with dangerous pattern detection
- Added template size limits to prevent DoS
- Added
- Automated security testing (v1.6.0)
- Created comprehensive security test suite
- Added GitHub Actions workflow for security tests
- Implemented pattern checking script
- Added command injection and path traversal tests
- Security documentation expansion (v1.6.0)
- Added comprehensive security section to README.md
- Documented all security features with examples
- Created security best practices guide
- Basic SAST (Static Application Security Testing) integration (v1.6.0)
- Integrated
deno lintfor static code analysis - Created pattern checking script to detect dangerous regex patterns
- Added checks for hardcoded secrets in CI/CD workflow
- Validates file permissions and security patterns
- Integrated
- GitHub Security Features integration (v1.6.0)
- CodeQL semantic code analysis for vulnerability detection
- Dependabot for automated dependency updates
- Dependency review action to block vulnerable dependencies in PRs
- Secret scanning (automatically enabled for public repos)
- Security insights configuration for transparency
- Professional security audit by third-party firm
- Advanced SAST/DAST tools integration (e.g., Snyk, SonarQube)
- Dependency vulnerability scanning (when Deno supports it)
- Security compliance certifications (SOC2, ISO 27001, etc.)
Nagare aims to comply with:
- OWASP Top 10 guidelines
- Security best practices for CLI tools
- Deno security model
For detailed OWASP compliance status, see the Security section in README.md.
Security updates are released as:
- Critical: Immediate patch release
- High: Within 7 days
- Medium: Within 30 days
- Low: Next regular release
Subscribe to releases on GitHub to get notified of security updates.