Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 8 additions & 1 deletion .github/CODEOWNERS
Original file line number Diff line number Diff line change
Expand Up @@ -9,4 +9,11 @@ src/ @aziontech/team-uxe

# Published content + i18n
src/content/docs/ @aziontech/product-content
src/i18n/ @aziontech/product-content
src/i18n/ @aziontech/product-content
# Public repository: repository automation and ownership rules also require
# OSS review (Azion engineering standard, SO-4939). Kept last so they apply.
/.github/ @aziontech/oss-review @isaque-bock-azion @bruno-andrade-azion @marcus-souza-azion @pedro-ribeiro-azion
/.github/workflows/ @aziontech/oss-review @aziontech/team-uxe
/.github/CODEOWNERS @aziontech/oss-review @isaque-bock-azion @bruno-andrade-azion @marcus-souza-azion @pedro-ribeiro-azion
/SECURITY.md @aziontech/oss-review @aziontech/security-office
/.github/workflows/ci-security.yml @aziontech/oss-review @aziontech/security-office
25 changes: 25 additions & 0 deletions .github/workflows/ci-compliance.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
name: Compliance

on:
pull_request:
types: [opened, synchronize, reopened, edited]
schedule:
- cron: '4 6 * * 1'

permissions: {}

jobs:
compliance:
name: Engineering Compliance
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: write # PR comment with compliance report
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 0
fetch-tags: true
persist-credentials: false

- uses: aziontech/azion-action-compliance@v0
107 changes: 107 additions & 0 deletions .github/workflows/ci-security.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,107 @@
name: Security

# Public repository: aziontech/azion-action-security is private and cannot be
# used here, so the same capabilities run inline with pinned, checksum-verified
# tools.
# - secrets: gitleaks (tree + new commits; full history weekly)
# - SAST: semgrep (registry rules, ERROR severity blocks)
# - dependencies: osv-scanner over every manifest/lockfile (HIGH/CRITICAL block)

on:
push:
branches: [main]
pull_request:
types: [opened, synchronize, reopened]
schedule:
- cron: '24 4 * * 3'
workflow_dispatch:

permissions: {}

concurrency:
group: ci-security-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}

env:
GITLEAKS_VERSION: 8.30.1
GITLEAKS_SHA256: 551f6fc83ea457d62a0d98237cbad105af8d557003051f41f3e7ca7b3f2470eb
OSV_VERSION: v2.4.0
OSV_SHA256: 15314940c10d26af9c6649f150b8a47c1262e8fc7e17b1d1029b0e479e8ed8a0
SEMGREP_VERSION: 1.176.0

jobs:
security:
name: Security Scan
runs-on: ubuntu-latest
timeout-minutes: 20
permissions:
contents: read
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 0 # full history: secrets hide in old commits
persist-credentials: false

- name: Install pinned tools
run: |
mkdir -p "$RUNNER_TEMP/bin"
curl -sSLf -o "$RUNNER_TEMP/gitleaks.tar.gz" \
"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/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz"
echo "${GITLEAKS_SHA256} $RUNNER_TEMP/gitleaks.tar.gz" | sha256sum -c -
tar -xzf "$RUNNER_TEMP/gitleaks.tar.gz" -C "$RUNNER_TEMP/bin" gitleaks
curl -sSLf -o "$RUNNER_TEMP/bin/osv-scanner" \
"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/google/osv-scanner/releases/download/${OSV_VERSION}/osv-scanner_linux_amd64"
echo "${OSV_SHA256} $RUNNER_TEMP/bin/osv-scanner" | sha256sum -c -
chmod +x "$RUNNER_TEMP/bin/osv-scanner"
python3 -m pip install --quiet --disable-pip-version-check --user "semgrep==${SEMGREP_VERSION}"
echo "$RUNNER_TEMP/bin" >> "$GITHUB_PATH"
echo "$HOME/.local/bin" >> "$GITHUB_PATH"

- name: Secret scanning (gitleaks)
if: ${{ !cancelled() }}
env:
EVENT_NAME: ${{ github.event_name }}
PR_BASE: ${{ github.event.pull_request.base.sha }}
PR_HEAD: ${{ github.event.pull_request.head.sha }}
PUSH_BEFORE: ${{ github.event.before }}
run: |
# Current tree on every run; new commits on PRs and pushes; the full
# history on the weekly schedule and on manual runs.
status=0
gitleaks detect --source . --no-git --no-banner --redact --verbose || status=1
case "$EVENT_NAME" in
pull_request) range="${PR_BASE}..${PR_HEAD}" ;;
push) range="${PUSH_BEFORE}..${GITHUB_SHA}"
git cat-file -e "${PUSH_BEFORE}^{commit}" 2>/dev/null || range="${GITHUB_SHA}^!" ;;
*) range="" ;;
esac
if [ -n "$range" ]; then
gitleaks detect --source . --no-banner --redact --verbose --log-opts="$range" || status=1
else
gitleaks detect --source . --no-banner --redact --verbose || status=1
fi
exit "$status"

- name: SAST (semgrep)
if: ${{ !cancelled() }}
# `--config auto` selects registry rules for the detected languages and
# requires semgrep metrics to be enabled.
run: semgrep scan --config auto --disable-nosem --severity ERROR --error .

- name: Dependency scanning (osv-scanner)
if: ${{ !cancelled() }}
run: |
set +e
osv-scanner scan --config=/dev/null --recursive .
osv-scanner scan --config=/dev/null --recursive --format json --output "$RUNNER_TEMP/osv.json" . >/dev/null 2>&1
set -e
# Block on HIGH/CRITICAL (CVSS >= 7.0); lower severities are reported above.
high=$(jq -r '[.results[]?.packages[]? | .package as $p | .groups[]?
| select((.max_severity // "0" | tonumber? // 0) >= 7)
| "\($p.name)@\($p.version) \(.ids | join(","))"] | unique | .[]' "$RUNNER_TEMP/osv.json")
if [ -n "$high" ]; then
echo "::error::HIGH/CRITICAL vulnerabilities in dependencies:"
echo "$high"
exit 1
fi
echo "No HIGH/CRITICAL dependency vulnerabilities"
40 changes: 40 additions & 0 deletions .github/workflows/ci-tests.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
name: Tests

on:
pull_request:
branches: [main]
types: [opened, synchronize, reopened]

concurrency:
group: ci-tests-${{ github.event.pull_request.number }}
cancel-in-progress: true

permissions: {}

jobs:
integration:
name: Content validator (Vitest)
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: read
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false

- name: Set up pnpm
uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4.3.0

- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22.23.2

# The test package is standalone: it does not install the site.
- name: Install test dependencies
working-directory: tests/vitest
run: pnpm install --ignore-workspace --frozen-lockfile

- name: Run Vitest integration tests
working-directory: tests/vitest
run: pnpm test
10 changes: 5 additions & 5 deletions .github/workflows/dev.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: CHECKOUT project
uses: actions/checkout@v4
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
repository: aziontech/docs
ref: dev
Expand All @@ -18,9 +18,9 @@ jobs:
fetch-depth: '0'
lfs: 'false'
- name: SETTING pnpm
uses: pnpm/action-setup@v4
uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4.3.0
- name: SETTING Node and Github Packages
uses: actions/setup-node@v4
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: 22.23.2
cache: 'pnpm'
Expand All @@ -33,10 +33,10 @@ jobs:
export PUBLIC_GITHUB_TOKEN="${{ secrets.GH_PACKAGES_SECRET }}"
pnpm run build:dev
- name: 'AUTH Google Cloud'
uses: 'google-github-actions/auth@v2'
uses: google-github-actions/auth@c200f3691d83b41bf9bbd8638997a462592937ed # v2.1.13
with:
credentials_json: ${{ secrets.GCP_EXP_ENG }}
- uses: 'google-github-actions/setup-gcloud@v2'
- uses: google-github-actions/setup-gcloud@e427ad8a34f8676edf47cf7d7925499adf3eb74f # v2.2.1
with:
version: '>= 363.0.0'
- name: PUBLISHING
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/pr-checks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,12 +19,12 @@ jobs:
timeout-minutes: 30
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- name: Set up pnpm
uses: pnpm/action-setup@v4
uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4.3.0

- name: Set up Node
uses: actions/setup-node@v4
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: 22.23.2
cache: pnpm
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/pr-title.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ jobs:
timeout-minutes: 5
steps:
- name: Check type(scope) format
uses: amannn/action-semantic-pull-request@v5
uses: amannn/action-semantic-pull-request@e32d7e603df1aa1ba07e981f2a23455dee596825 # v5
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/prod.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,15 +18,15 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: CHECKOUT project
uses: actions/checkout@v4
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
fetch-depth: 0

- name: SETTING pnpm
uses: pnpm/action-setup@v4
uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4.3.0

- name: SETTING Node and Github Packages
uses: actions/setup-node@v4
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: 22.23.2
cache: 'pnpm'
Expand All @@ -46,11 +46,11 @@ jobs:
pnpm exec tsx cicd/algolia-reindex.ts app=${{ secrets.ALGOLIA_CONF_APP }} api=${{ secrets.ALGOLIA_CONF_API }}

- name: 'AUTH Google Cloud'
uses: 'google-github-actions/auth@v2'
uses: google-github-actions/auth@c200f3691d83b41bf9bbd8638997a462592937ed # v2.1.13
with:
credentials_json: ${{ secrets.GCP_EXP_ENG }}

- uses: 'google-github-actions/setup-gcloud@v2'
- uses: google-github-actions/setup-gcloud@e427ad8a34f8676edf47cf7d7925499adf3eb74f # v2.2.1
with:
version: '>= 363.0.0'

Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/stage.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: CHECKOUT project
uses: actions/checkout@v4
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
repository: aziontech/docs
ref: stage
Expand All @@ -18,9 +18,9 @@ jobs:
fetch-depth: '0'
lfs: 'false'
- name: SETTING pnpm
uses: pnpm/action-setup@v4
uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4.3.0
- name: SETTING Node and Github Packages
uses: actions/setup-node@v4
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: 22.23.2
cache: 'pnpm'
Expand All @@ -33,10 +33,10 @@ jobs:
export PUBLIC_GITHUB_TOKEN="${{ secrets.GH_PACKAGES_SECRET }}"
pnpm run build:stage
- name: 'AUTH Google Cloud'
uses: 'google-github-actions/auth@v2'
uses: google-github-actions/auth@c200f3691d83b41bf9bbd8638997a462592937ed # v2.1.13
with:
credentials_json: ${{ secrets.GCP_EXP_ENG }}
- uses: 'google-github-actions/setup-gcloud@v2'
- uses: google-github-actions/setup-gcloud@e427ad8a34f8676edf47cf7d7925499adf3eb74f # v2.2.1
with:
version: '>= 363.0.0'
- name: PUBLISHING
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/weekly-linkcheck.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,13 +15,13 @@ jobs:
timeout-minutes: 45
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0

- name: Set up pnpm
uses: pnpm/action-setup@v4
uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4.3.0

- name: Set up Node
uses: actions/setup-node@v4
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: 20.13.1
cache: pnpm
Expand All @@ -40,7 +40,7 @@ jobs:

- name: File an issue on breakage
if: steps.linkcheck.conclusion == 'failure'
uses: actions/github-script@v7
uses: actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7.1.0
with:
script: |
const label = 'broken-links';
Expand Down
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -39,3 +39,6 @@ sandbox.config.json
.kilocode
.kilo
.markdown-link-resolver/

# Vitest integration tests: temporary validator copies
tests/vitest/.run-*/
18 changes: 18 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# Changelog

Content changes are tracked through the pull request history of `main`; each
squash-merged PR title is the change record. This file records versioned
baselines of the documentation site and its tooling.

The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
and versions follow [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

## [Unreleased]

### Added
- Compliance and security workflows, and integration tests for the content validator (`tests/vitest/`)

## [v1.0.0] - 2026-10-01

### Added
- SemVer baseline of the documentation site as deployed to production from `main`
7 changes: 7 additions & 0 deletions MAINTAINERS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# Maintainers

Owning team: DevRel (the default owners in [.github/CODEOWNERS](.github/CODEOWNERS)), with @aziontech/team-uxe as technical steward for platform code. Roles and approvals are described in [.github/GOVERNANCE.md](.github/GOVERNANCE.md).

- @marcus-souza-azion
- @pedro-ribeiro-azion
- @bruno-andrade-azion
Loading
Loading