chore(ci): add compliance and security gates - #2408
Open
adriano-krauthein-azion wants to merge 1 commit into
Open
adriano-krauthein-azion wants to merge 1 commit into
adriano-krauthein-azion wants to merge 1 commit into
Conversation
Engineering standard (SO-4939): SECURITY.md, MAINTAINERS.md, CHANGELOG.md, OSS review on .github/ in CODEOWNERS, compliance and inline security workflows (gitleaks, semgrep, osv-scanner), Vitest integration tests for the content validator, and third-party actions pinned to SHAs at the same versions.
adriano-krauthein-azion
requested review from
a team,
bruno-andrade-azion,
isaque-bock-azion,
marcus-souza-azion and
pedro-ribeiro-azion
as code owners
October 2, 2026 12:23
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What & why
Related issue: SO-4939 (Azion engineering compliance standard). Per GOVERNANCE.md §4, the ticket is here and not in the title.
Pages affected: none. This PR changes no content and no site code.
This PR adds the Azion engineering compliance baseline (
Engineering ComplianceandSecurity Scanchecks) to this repository and keeps the change minimal.Type of change
chore): CI and repository governance only, no content mixed inPhase 1: Foundation
.github/CODEOWNERS: rules appended at the end. In a public repository,.github/andCODEOWNERSmust also be owned by@aziontech/oss-review..github/andCODEOWNERS,@aziontech/team-uxefor.github/workflows/.SECURITY.mdandci-security.ymlgo to@aziontech/security-office.MAINTAINERS.md: points to the existing roles in GOVERNANCE.md.SECURITY.md: private vulnerability reporting through GitHub Security Advisories.Phase 2: Supply chain
ci-compliance.yml:azion-action-compliance.ci-security.yml(jobSecurity Scan):--config auto, ERROR blocks) and osv-scanner (HIGH/CRITICAL block)azion-action-securityis private and cannot run herePhase 3: Code quality
pr-title.yml); it is only pinned.tests/vitest/+ci-tests.yml: integration tests for the content validator. They run the realtest-frontmatter.js(the last step of everypnpm build:*):pnpm install --ignore-workspace), so it does not install the site; the job takes under a minutePhase 4: Release
v1.0.0annotated tag was created on the currentmain(fef735d1) as the SemVer baseline. No workflow triggers on tags.CHANGELOG.mdis seeded withv1.0.0. The site keeps deploying frommainas today.Merge notes
mainrunsprod.ymlas any merge does. The deploy steps are unchanged, apart from the SHA pins at the same versions.Action required
aziontech/azion-action-complianceis private, and GitHub cannot resolve it from a public repository. This needs an org decision. Run locally, all 11 checks pass.@aziontech/security-office. Neither check is required on this repository, so they do not block merges.env/consts.*.tsandsrc/consts.ts: the Algolia search key and the analytics write key. These are client-side keys; confirm the Algolia key is search-only.detected-generic-api-key,detected-aws-access-key-id-value) on the same example values. No code findings.pnpm-lock.yaml(astro5.16,sharp,devalue,h3,minimatch,js-yamland others). The lockfile is not changed here, to avoid conflicts with refactor: Rebuild the docs on Astro 7, Tailwind 4 and @aziontech/webkit 4 #2328 (Astro 7 rebuild), which replaces most of these dependencies. Re-check after it merges.prod.ymlhas a pre-existing syntax error:workflow_dispatchis nested underpush, so manual runs are not available (actionlint). Left as is.@aziontech/oss-reviewis not visible through the API; please confirm the team exists.Validation
azion-action-compliancescripts, run locally: all checks pass exceptcommits, which is evaluated on the PR.--min-severity high, company config): no findings. actionlint: only the pre-existingprod.ymlissue.pnpm testintests/vitest: 8/8.