Skip to content

chore(compliance): security policy, release SBOM and provenance, licence check - #90

Merged
WomB0ComB0 merged 3 commits into
mainfrom
chore/compliance-remediation
Sep 28, 2026
Merged

WomB0ComB0 merged 3 commits into
mainfrom
chore/compliance-remediation

Conversation

@WomB0ComB0

@WomB0ComB0 WomB0ComB0 commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Fixes the compliance-lens findings for this repository, per control.

PUB-SEC-01: security policy

  • Changed: added a root SECURITY.md. The repo had no policy of its own, so it links the org policy, restates the private reporting channels (private vulnerability reporting, security@resq.software), and adds the EU Cyber Resilience Act reporting and Safe harbour sections after the reporting section.
  • It also points to the org policy's supported-versions table. Without it, a repo-level policy would drop the supported-versions statement the org default provided.

PUB-SEC-02: SBOM and provenance on release

  • Changed: release.yml, publish release job:
    • checks out the released commit;
    • generates an SPDX JSON SBOM with anchore/sbom-action and attaches it to the Release as sbom.spdx.json. It uses --clobber, so a re-run stays idempotent;
    • attests build provenance with actions/attest-build-provenance for every installer listed in SHA256SUMS, by digest. Check one with gh attestation verify install.sh --repo resq-software/dev.
  • Only this job gains id-token: write and attestations: write. It already had contents: write for the upload. The other jobs are unchanged.
  • Both actions are pinned to full commit SHAs with version comments.

PUB-LIC-03: dependency-licence check

  • Changed: new dependency-licences workflow. It is a pull_request job running actions/dependency-review-action (SHA-pinned, v5.0.0) with deny-licenses: GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-only, GPL-3.0-or-later, AGPL-3.0-only, AGPL-3.0-or-later, SSPL-1.0 and warn-only: true.
  • The existing dependency-review job comes from the org's reusable security-scan workflow. That workflow takes no licence inputs, so it can't be extended from this repo. The new job therefore sets vulnerability-check: false and doesn't repeat it.

PUB-CNF-01: internal names

  • Changed: .github/release.yml (line 6) and .github/workflows/conventional-title-labeler.yml (line 7) named a private repository. Both now say "the org's changelog aggregator". Neither mention was functional.

Left, and why

  • The release job runs only when VERSION changes, so this PR's CI can't exercise the new steps. actionlint passes locally. zizmor isn't installed locally; the security workflow runs it on this PR.

Summary by CodeRabbit

  • Security
    • Published releases now include a software bill of materials and provenance attestations for installer checksums.
    • Pull requests receive license checks for selected dependency licenses; findings are reported as warnings.
  • Documentation
    • Updated security guidance explains private vulnerability reporting, response timelines, supported versions, and applicable reporting requirements. It also outlines researcher safe-harbor conditions.

…nce check

- SECURITY.md: link the org policy; add the EU Cyber Resilience Act
  reporting and safe-harbour sections.
- release: attach an SPDX JSON SBOM to each Release and attest build
  provenance for every installer listed in SHA256SUMS. Only the publish
  job gains id-token and attestations write.
- dependency-licences: warn-only dependency-review licence check on pull
  requests.
- Reword a private repository name in two comments to generic wording.
@WomB0ComB0
WomB0ComB0 requested a review from a team as a code owner September 28, 2026 01:28
@github-actions github-actions Bot added the size/L PR size: large (100-499 lines changed) label Sep 28, 2026
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
get-resq-software 88667ea Sep 28 2026, 08:44 AM

@github-actions github-actions Bot added A-Release Release plumbing (VERSION, pins, stamp, release workflow) A-DevOps CI, workflows, actions, and repo infra (.github) C-Documentation Improvements or additions to documentation labels Sep 28, 2026
@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 54847937-2bac-4d98-97c6-3a814435db7e

📥 Commits

Reviewing files that changed from the base of the PR and between 4cc613c and 88667ea.

⛔ Files ignored due to path filters (1)
  • worker/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (2)
  • SECURITY.md
  • worker/package.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The pull request updates the release workflow with an SBOM and build provenance, adds dependency license review, revises security reporting guidance, pins sharp to version 0.35.4, and corrects two changelog aggregator comments.

Changes

Release integrity

Layer / File(s) Summary
Release job setup
.github/workflows/release.yml
The release job documents pinned actions, adds permissions for identity tokens and attestations, and checks out the released commit with credentials disabled.
SBOM and provenance
.github/workflows/release.yml
The workflow generates an SPDX JSON SBOM, uploads it to the release, and attests the installer digests in SHA256SUMS.

Changelog aggregator references

Layer / File(s) Summary
Aggregator comment references
.github/release.yml, .github/workflows/conventional-title-labeler.yml
Both comments now identify the changelog aggregator as belonging to the organization.

Dependency license review

Layer / File(s) Summary
Pull-request license check
.github/workflows/dependency-licences.yml
The workflow runs dependency review with read-only contents permission and warns on the listed GPL, AGPL, and SSPL licenses. Vulnerability checking is disabled and the check is warn-only.

Security reporting policy

Layer / File(s) Summary
Reporting policy and safe harbour
SECURITY.md
The policy describes supported versions, private reporting channels, requested report details, applicable Cyber Resilience Act deadlines, and safe-harbour terms for researchers.

Sharp dependency override

Layer / File(s) Summary
Pin sharp version
worker/package.json
The package manifest adds an npm override that pins sharp to version 0.35.4.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Other

Sequence Diagram(s)

sequenceDiagram
  participant ReleaseJob
  participant CheckoutAction
  participant GitHubRelease
  participant SBOMAction
  participant AttestationAction
  ReleaseJob->>CheckoutAction: Check out the released commit
  ReleaseJob->>GitHubRelease: Create or refresh the release
  ReleaseJob->>SBOMAction: Generate SPDX JSON SBOM
  ReleaseJob->>GitHubRelease: Upload SBOM with --clobber
  ReleaseJob->>AttestationAction: Attest installer digests from SHA256SUMS
Loading

Merge Risk: ⚪ Minimal · up to 88667

The release commands remain authenticated, and installer provenance matches the published files. The reviewed changes present no actionable merge-blocking risk.

Architecture Summary

Architecture risk: 🔵 Low · up to 88667

The change affects 2 systems.

Changed systems: SECURITY.md, worker

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — SECURITY.md (service) was modified; 1 changed file maps to changed impact.
  • observed — worker (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in SECURITY.md: Adds repository security-policy guidance: security fixes target the latest published version, while reports about older versions should identify the tested commit or release. Vulnerabilities must be reported privately through a GitHub draft advisory or email, with the affected revision, impact, and reproduction steps. Where the CRA applies, it states reporting deadlines of 24 hours, 72 hours, and 14 days for actively exploited vulnerabilities, and 24 hours, 72 hours, and one month for severe incidents. It also sets good-faith research conditions and limits safe harbour to ResQ’s own claims.
  • observed — Modified behavior in worker/package.json: Adds an npm override pinning sharp to version 0.35.4.
  • observed — Modified behavior in .github/release.yml: The comment now refers to the org’s changelog aggregator instead of resq-software/landing.
  • observed — Modified behavior in .github/workflows/conventional-title-labeler.yml: The comment now refers to the org’s changelog aggregator instead of resq-software/landing’s.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the primary compliance changes: the security policy, release SBOM and provenance, and license check workflow.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added C-Chore Chore: deps, tooling, or config with no public API change and removed C-Documentation Improvements or additions to documentation labels Sep 28, 2026
@github-actions

Copy link
Copy Markdown
Contributor

AI Auditor here 🤖. I have reviewed the changes in this pull request and found no security vulnerabilities, logic bugs, or performance issues. The changes improve the projects security posture by adding a dependency license check, generating an SBOM and build provenance on release, and adding a comprehensive security policy. This is a solid contribution to the projects security and compliance. 👍

Generated by ai-auditor for #90 · gem25pro · 27 AIC · ⌖ 2.63 AIC · ⊞ 12.7K · ◷

@github-actions github-actions Bot added the C-Documentation Improvements or additions to documentation label Sep 28, 2026
resq-sw
resq-sw previously approved these changes Sep 28, 2026
miniflare pins sharp 0.35.2 exactly (a dev-only dependency via wrangler), which
osv-scanner flags as high severity. An npm override moves it to the patched
0.35.4. A later wrangler bump that brings miniflare's own 0.35.4 can drop the
override.
@github-actions github-actions Bot added area:worker Changes under worker/ and removed C-Documentation Improvements or additions to documentation labels Sep 28, 2026
@WomB0ComB0
WomB0ComB0 merged commit ef66642 into main Sep 28, 2026
27 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

A-DevOps CI, workflows, actions, and repo infra (.github) A-Release Release plumbing (VERSION, pins, stamp, release workflow) area:worker Changes under worker/ C-Chore Chore: deps, tooling, or config with no public API change size/L PR size: large (100-499 lines changed)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants