Skip to main content

In progress / Case study (evidence pending)

Golden Security Scan

Reusable GitHub Action for frontend, backend, infrastructure, and container scanning.

Overview

A reusable security workflow that gives different repository types one consistent scanning entry point. This is Kaji Guard, the security scanner from Kaji Labs. Its own repository is private, but it follows the same labeled-PR workflow pattern as Kaji Labs' public PR Version Bot.

Problem

Security checks are often copied between repositories, drift over time, and produce inconsistent results.

My role

Action interface, scan orchestration, failure policy, and developer-facing output.

Stack

  • GitHub Actions
  • Node.js
  • Docker
  • Terraform

Architecture

Repository-aware scan orchestration

Repository inputs select relevant frontend, backend, infrastructure, and container checks before results are summarized.

  1. 01 Repository

    Workflow caller

  2. 02 Golden action

    Scan orchestration

  3. 03 Security scanners

    Workload checks

  4. 04 Job summary

    Actionable results

Key features

  • • Repository-type inputs
  • • Frontend, backend, IaC, and container scan stages
  • • Consistent GitHub Actions summary

Deployment

The action is designed to be called from repository workflows with explicit inputs and permissions.

Security

The workflow uses least-privilege permissions, pins external actions where possible, and avoids printing secrets.

Challenges

  • • Normalising results from different scanners
  • • Balancing useful defaults with repository-specific control

What I learned

  • • Security automation needs clear failure semantics
  • • Reusable actions should minimise caller permissions

Proof and evidence

private

Action run evidence

Kaji Guard's own repository is private. Kaji Labs' PR Version Bot is public and uses the same labeled-PR GitHub Actions pattern this action is built on.

Links