In progress / Case study (evidence pending)
Golden Security Scan
Reusable GitHub Action for frontend, backend, infrastructure, and container scanning.
Overview
A reusable security workflow that gives different repository types one consistent scanning entry point. This is Kaji Guard, the security scanner from Kaji Labs. Its own repository is private, but it follows the same labeled-PR workflow pattern as Kaji Labs' public PR Version Bot.
Problem
Security checks are often copied between repositories, drift over time, and produce inconsistent results.
My role
Action interface, scan orchestration, failure policy, and developer-facing output.
Stack
- GitHub Actions
- Node.js
- Docker
- Terraform
Architecture
Repository-aware scan orchestration
Repository inputs select relevant frontend, backend, infrastructure, and container checks before results are summarized.
01 Repository
Workflow caller
02 Golden action
Scan orchestration
03 Security scanners
Workload checks
04 Job summary
Actionable results
Key features
- • Repository-type inputs
- • Frontend, backend, IaC, and container scan stages
- • Consistent GitHub Actions summary
Deployment
The action is designed to be called from repository workflows with explicit inputs and permissions.
Security
The workflow uses least-privilege permissions, pins external actions where possible, and avoids printing secrets.
Challenges
- • Normalising results from different scanners
- • Balancing useful defaults with repository-specific control
What I learned
- • Security automation needs clear failure semantics
- • Reusable actions should minimise caller permissions
Proof and evidence
private
Action run evidence
Kaji Guard's own repository is private. Kaji Labs' PR Version Bot is public and uses the same labeled-PR GitHub Actions pattern this action is built on.