Skip to content

chore(ci): add compliance and security gates - #2408

Open
adriano-krauthein-azion wants to merge 1 commit into
mainfrom
chore/compliance-gate
Open

adriano-krauthein-azion wants to merge 1 commit into
mainfrom
chore/compliance-gate

Conversation

@adriano-krauthein-azion

@adriano-krauthein-azion adriano-krauthein-azion commented Oct 2, 2026 •

Copy link
Copy Markdown

What & why

Related issue: SO-4939 (Azion engineering compliance standard). Per GOVERNANCE.md §4, the ticket is here and not in the title.
Pages affected: none. This PR changes no content and no site code.

This PR adds the Azion engineering compliance baseline (Engineering Compliance and Security Scan checks) to this repository and keeps the change minimal.

Type of change

  • Platform / structure (chore): CI and repository governance only, no content mixed in

Phase 1: Foundation

  • .github/CODEOWNERS: rules appended at the end. In a public repository, .github/ and CODEOWNERS must also be owned by @aziontech/oss-review.
    • The existing owners are kept on those paths: DevRel for .github/ and CODEOWNERS, @aziontech/team-uxe for .github/workflows/.
    • SECURITY.md and ci-security.yml go to @aziontech/security-office.
  • MAINTAINERS.md: points to the existing roles in GOVERNANCE.md.
  • SECURITY.md: private vulnerability reporting through GitHub Security Advisories.

Phase 2: Supply chain

  • ci-compliance.yml: azion-action-compliance.
  • ci-security.yml (job Security Scan):
    • runs gitleaks (current tree plus new commits; full history weekly), semgrep (--config auto, ERROR blocks) and osv-scanner (HIGH/CRITICAL block)
    • all tools are pinned and checksum-verified, because azion-action-security is private and cannot run here
  • Existing workflows: the third-party actions are pinned to the commit SHA of the version already in use. Nothing else in them changes.

Phase 3: Code quality

  • PR title enforcement already exists (pr-title.yml); it is only pinned.
  • ESLint is already configured.
  • tests/vitest/ + ci-tests.yml: integration tests for the content validator. They run the real test-frontmatter.js (the last step of every pnpm build:*):
    • against the published content: namespaces and permalinks are present, valid and unique, and every page has a title
    • against small broken fixtures: a duplicate permalink, a duplicate namespace, invalid permalink characters and a missing namespace must each be rejected
    • the test package is standalone (pnpm install --ignore-workspace), so it does not install the site; the job takes under a minute
    • 8/8 pass, and they are mutation-checked: a duplicated permalink in a real page fails them

Phase 4: Release

  • A v1.0.0 annotated tag was created on the current main (fef735d1) as the SemVer baseline. No workflow triggers on tags.
  • CHANGELOG.md is seeded with v1.0.0. The site keeps deploying from main as today.

Merge notes

  • Merging to main runs prod.yml as any merge does. The deploy steps are unchanged, apart from the SHA pins at the same versions.

Action required

  • Engineering Compliance cannot run in public repositories: aziontech/azion-action-compliance is private, and GitHub cannot resolve it from a public repository. This needs an org decision. Run locally, all 11 checks pass.
  • Security Scan reports existing findings, for DevRel/UXE and @aziontech/security-office. Neither check is required on this repository, so they do not block merges.
    • gitleaks (164 hits in CI, current tree):
      • env/consts.*.ts and src/consts.ts: the Algolia search key and the analytics write key. These are client-side keys; confirm the Algolia key is search-only.
      • credential-shaped example values in guides: data stream connectors (Amazon S3, Datadog, BigQuery private key), reCAPTCHA, Object Storage cURL examples and the terms of service page. They look like placeholders, but they need triage. Nothing was suppressed.
    • semgrep: 10 ERROR results, all from the secret-detection rules (detected-generic-api-key, detected-aws-access-key-id-value) on the same example values. No code findings.
    • osv-scanner: HIGH advisories in pnpm-lock.yaml (astro 5.16, sharp, devalue, h3, minimatch, js-yaml and others). The lockfile is not changed here, to avoid conflicts with refactor: Rebuild the docs on Astro 7, Tailwind 4 and @aziontech/webkit 4 #2328 (Astro 7 rebuild), which replaces most of these dependencies. Re-check after it merges.
  • prod.yml has a pre-existing syntax error: workflow_dispatch is nested under push, so manual runs are not available (actionlint). Left as is.
  • @aziontech/oss-review is not visible through the API; please confirm the team exists.

Validation

  • The azion-action-compliance scripts, run locally: all checks pass except commits, which is evaluated on the PR.
  • zizmor (--min-severity high, company config): no findings. actionlint: only the pre-existing prod.yml issue.
  • pnpm test in tests/vitest: 8/8.

Engineering standard (SO-4939): SECURITY.md, MAINTAINERS.md, CHANGELOG.md,
OSS review on .github/ in CODEOWNERS, compliance and inline security
workflows (gitleaks, semgrep, osv-scanner), Vitest integration tests for
the content validator, and third-party actions pinned to SHAs at the same
versions.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant