chore(compliance): security policy, release SBOM and provenance, licence check - #90
Conversation
…nce check - SECURITY.md: link the org policy; add the EU Cyber Resilience Act reporting and safe-harbour sections. - release: attach an SPDX JSON SBOM to each Release and attest build provenance for every installer listed in SHA256SUMS. Only the publish job gains id-token and attestations write. - dependency-licences: warn-only dependency-review licence check on pull requests. - Reword a private repository name in two comments to generic wording.
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ✅ Deployment successful! View logs |
get-resq-software | 88667ea | Sep 28 2026, 08:44 AM |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe pull request updates the release workflow with an SBOM and build provenance, adds dependency license review, revises security reporting guidance, pins ChangesRelease integrity
Changelog aggregator references
Dependency license review
Security reporting policy
Sharp dependency override
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Other Sequence Diagram(s)sequenceDiagram
participant ReleaseJob
participant CheckoutAction
participant GitHubRelease
participant SBOMAction
participant AttestationAction
ReleaseJob->>CheckoutAction: Check out the released commit
ReleaseJob->>GitHubRelease: Create or refresh the release
ReleaseJob->>SBOMAction: Generate SPDX JSON SBOM
ReleaseJob->>GitHubRelease: Upload SBOM with --clobber
ReleaseJob->>AttestationAction: Attest installer digests from SHA256SUMS
Merge Risk: ⚪ Minimal · up to The release commands remain authenticated, and installer provenance matches the published files. The reviewed changes present no actionable merge-blocking risk. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 2 systems. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
AI Auditor here 🤖. I have reviewed the changes in this pull request and found no security vulnerabilities, logic bugs, or performance issues. The changes improve the projects security posture by adding a dependency license check, generating an SBOM and build provenance on release, and adding a comprehensive security policy. This is a solid contribution to the projects security and compliance. 👍
|
miniflare pins sharp 0.35.2 exactly (a dev-only dependency via wrangler), which osv-scanner flags as high severity. An npm override moves it to the patched 0.35.4. A later wrangler bump that brings miniflare's own 0.35.4 can drop the override.
Fixes the compliance-lens findings for this repository, per control.
PUB-SEC-01: security policy
SECURITY.md. The repo had no policy of its own, so it links the org policy, restates the private reporting channels (private vulnerability reporting,security@resq.software), and adds the EU Cyber Resilience Act reporting and Safe harbour sections after the reporting section.PUB-SEC-02: SBOM and provenance on release
release.yml,publish releasejob:anchore/sbom-actionand attaches it to the Release assbom.spdx.json. It uses--clobber, so a re-run stays idempotent;actions/attest-build-provenancefor every installer listed inSHA256SUMS, by digest. Check one withgh attestation verify install.sh --repo resq-software/dev.id-token: writeandattestations: write. It already hadcontents: writefor the upload. The other jobs are unchanged.PUB-LIC-03: dependency-licence check
dependency-licencesworkflow. It is apull_requestjob runningactions/dependency-review-action(SHA-pinned, v5.0.0) withdeny-licenses: GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-only, GPL-3.0-or-later, AGPL-3.0-only, AGPL-3.0-or-later, SSPL-1.0andwarn-only: true.vulnerability-check: falseand doesn't repeat it.PUB-CNF-01: internal names
.github/release.yml(line 6) and.github/workflows/conventional-title-labeler.yml(line 7) named a private repository. Both now say "the org's changelog aggregator". Neither mention was functional.Left, and why
VERSIONchanges, so this PR's CI can't exercise the new steps.actionlintpasses locally.zizmorisn't installed locally; the security workflow runs it on this PR.Summary by CodeRabbit