chore(compliance): security policy, package SBOM and provenance, licence headers - #71
Conversation
…nce headers - SECURITY.md: link the org policy; add the EU Cyber Resilience Act reporting and safe-harbour sections. - ci: the NuGet publish job generates an SPDX JSON SBOM and attests build provenance for every package it pushes; the release job attaches the SBOM to the GitHub Release. Only those jobs gain the permissions they need. - dependency-licences: warn-only dependency-review licence check on pull requests. - SPDX-License-Identifier: Apache-2.0 in the library and sample C# files. - Reword a private repository name in three comments to generic wording.
|
Important Review skippedToo many files! This PR contains 139 files, which is 39 over the limit of 100. To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch. Upgrade to a paid plan to raise the limit. This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (139)
You can disable this status message by setting the Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…n re-runnable Build and attest the assets before the Release is created, so a failure there publishes nothing. Skip creation when the Release already exists, so a re-run after a failed upload can finish the job.
Fixes the compliance-lens findings for this repository, per control.
PUB-SEC-01: security policy
SECURITY.md. The repo had no policy of its own, so it links the org policy, restates the private reporting channels (private vulnerability reporting,security@resq.software), and adds the EU Cyber Resilience Act reporting and Safe harbour sections after the reporting section.PUB-SEC-02: SBOM and provenance on release
ci.yml, Publish to NuGet job:dotnet pack, generates an SPDX JSON SBOM ofsrc/withanchore/sbom-action. Each library's.deps.jsonlists the dependencies it ships with;actions/attest-build-provenancefor everyartifacts/*.nupkgand*.snupkgbefore they're pushed. Check one withgh attestation verify <file>.nupkg --repo resq-software/dotnet.attestations: write. Its existingid-token: writealready covers Sigstore signing, and it stays atcontents: read.sbom.spdx.jsonwith--clobber. Its existingcontents: writecovers the upload.upload-artifactuses the SHA this repo already uses.PUB-LIC-03: dependency-licence check
dependency-licencesworkflow. It is apull_requestjob runningactions/dependency-review-action(SHA-pinned, v5.0.0) withdeny-licenses: GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-only, GPL-3.0-or-later, AGPL-3.0-only, AGPL-3.0-or-later, SSPL-1.0andwarn-only: true.requiredworkflow. That workflow takes no licence inputs, so it can't be extended from here. The new job setsvulnerability-check: falseso it doesn't repeat it.PUB-LIC-02: SPDX headers
// SPDX-License-Identifier: Apache-2.0(matching the rootLICENSE) at the top of all 134 C# files undersrc/andsamples/. Locally,dotnet build -c Releaseis clean with warnings as errors, anddotnet format --verify-no-changespasses.templates/resq-service/. They are thedotnet newtemplate's output, so every service generated from the template would inherit an Apache-2.0 header on its own code. Whether generated services should carry one is for the maintainers to decide. Even without them, header coverage is 134 of 174 files.PUB-CNF-01: internal names
.github/release.yml(line 6),.github/workflows/ci.yml(line 205) and.github/workflows/conventional-title-labeler.yml(line 7) named a private repository in comments. All three now say "the org's changelog aggregator". None of the mentions was functional.Left, and why
v*tags or a manual dispatch, so this PR's CI can't exercise the new steps.actionlintpasses locally.zizmorisn't installed locally; the security scan runs it on this PR.