This project includes automated security vulnerability analysis that runs on every repository push.
⚠️ Critical Issues Found: Weak random number generation⚠️ High Priority: Outdated dependencies (log4net, Newtonsoft.Json)⚠️ Medium Priority: Missing input validation
Run a local security scan before pushing:
Windows:
.\scripts\security-scan.ps1
Linux/macOS:
./scripts/security-scan.sh
- GitHub Actions workflow runs security scans on every push
- CodeQL static analysis for C# vulnerabilities
- Dependency vulnerability scanning
- Custom security rule validation
- Automated report generation
- Vulnerability Analysis Report - Detailed security findings
- Security Setup Guide - Complete setup instructions
- Security Configuration - Security scanning configuration