Skip to content

chore(compliance): security policy, package SBOM and provenance, licence headers - #71

Merged
WomB0ComB0 merged 3 commits into
mainfrom
chore/compliance-remediation
Sep 28, 2026
Merged

WomB0ComB0 merged 3 commits into
mainfrom
chore/compliance-remediation

Conversation

@WomB0ComB0

@WomB0ComB0 WomB0ComB0 commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Fixes the compliance-lens findings for this repository, per control.

PUB-SEC-01: security policy

  • Changed: added a root SECURITY.md. The repo had no policy of its own, so it links the org policy, restates the private reporting channels (private vulnerability reporting, security@resq.software), and adds the EU Cyber Resilience Act reporting and Safe harbour sections after the reporting section.
  • It also points to the org policy's supported-versions table. Without it, a repo-level policy would drop the supported-versions statement the org default provided.

PUB-SEC-02: SBOM and provenance on release

  • Changed: ci.yml, Publish to NuGet job:
    • after dotnet pack, generates an SPDX JSON SBOM of src/ with anchore/sbom-action. Each library's .deps.json lists the dependencies it ships with;
    • uploads the SBOM as a workflow artifact;
    • attests build provenance with actions/attest-build-provenance for every artifacts/*.nupkg and *.snupkg before they're pushed. Check one with gh attestation verify <file>.nupkg --repo resq-software/dotnet.
  • The job gains only attestations: write. Its existing id-token: write already covers Sigstore signing, and it stays at contents: read.
  • GitHub Release job: downloads the SBOM before creating the Release, skips creation if the Release already exists (so a re-run can finish the job), then attaches the SBOM as sbom.spdx.json with --clobber. Its existing contents: write covers the upload.
  • All actions are pinned to full commit SHAs with version comments. upload-artifact uses the SHA this repo already uses.

PUB-LIC-03: dependency-licence check

  • Changed: new dependency-licences workflow. It is a pull_request job running actions/dependency-review-action (SHA-pinned, v5.0.0) with deny-licenses: GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-only, GPL-3.0-or-later, AGPL-3.0-only, AGPL-3.0-or-later, SSPL-1.0 and warn-only: true.
  • The existing dependency-review job runs inside the org's reusable required workflow. That workflow takes no licence inputs, so it can't be extended from here. The new job sets vulnerability-check: false so it doesn't repeat it.

PUB-LIC-02: SPDX headers

  • Changed: added // SPDX-License-Identifier: Apache-2.0 (matching the root LICENSE) at the top of all 134 C# files under src/ and samples/. Locally, dotnet build -c Release is clean with warnings as errors, and dotnet format --verify-no-changes passes.
  • Left: the 40 C# files under templates/resq-service/. They are the dotnet new template's output, so every service generated from the template would inherit an Apache-2.0 header on its own code. Whether generated services should carry one is for the maintainers to decide. Even without them, header coverage is 134 of 174 files.

PUB-CNF-01: internal names

  • Changed: .github/release.yml (line 6), .github/workflows/ci.yml (line 205) and .github/workflows/conventional-title-labeler.yml (line 7) named a private repository in comments. All three now say "the org's changelog aggregator". None of the mentions was functional.

Left, and why

  • The publish and release jobs run only on v* tags or a manual dispatch, so this PR's CI can't exercise the new steps. actionlint passes locally. zizmor isn't installed locally; the security scan runs it on this PR.
  • The template headers, as described above.

…nce headers

- SECURITY.md: link the org policy; add the EU Cyber Resilience Act
  reporting and safe-harbour sections.
- ci: the NuGet publish job generates an SPDX JSON SBOM and attests
  build provenance for every package it pushes; the release job attaches
  the SBOM to the GitHub Release. Only those jobs gain the permissions
  they need.
- dependency-licences: warn-only dependency-review licence check on pull
  requests.
- SPDX-License-Identifier: Apache-2.0 in the library and sample C# files.
- Reword a private repository name in three comments to generic wording.
@github-actions github-actions Bot added size/L C-Chore Chore: deps, tooling, or config with no public API change labels Sep 28, 2026
@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Too many files!

This PR contains 139 files, which is 39 over the limit of 100.

To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch.

Upgrade to a paid plan to raise the limit.

This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 0cd4d651-bbea-42d5-b377-bb6253d97003

📥 Commits

Reviewing files that changed from the base of the PR and between b6270cd and 49ae95e.

📒 Files selected for processing (139)
  • .github/release.yml
  • .github/workflows/ci.yml
  • .github/workflows/conventional-title-labeler.yml
  • .github/workflows/dependency-licences.yml
  • SECURITY.md
  • samples/Widgets/src/Widgets.Api/Contracts/CreateWidgetRequest.cs
  • samples/Widgets/src/Widgets.Api/Contracts/CreateWidgetRequestValidator.cs
  • samples/Widgets/src/Widgets.Api/Endpoints/WidgetEndpoints.cs
  • samples/Widgets/src/Widgets.Api/Program.cs
  • samples/Widgets/src/Widgets.Api/Responses/PagedResponse.cs
  • samples/Widgets/src/Widgets.Api/Responses/WidgetResponse.cs
  • samples/Widgets/src/Widgets.Application/Abstractions/IWidgetRepository.cs
  • samples/Widgets/src/Widgets.Application/Contracts/WidgetDto.cs
  • samples/Widgets/src/Widgets.Application/DomainEventHandlers/WidgetCreatedHandler.cs
  • samples/Widgets/src/Widgets.Application/IntegrationEvents/WidgetCreatedIntegrationEvent.cs
  • samples/Widgets/src/Widgets.Application/Specifications/WidgetByIdSpec.cs
  • samples/Widgets/src/Widgets.Application/Specifications/WidgetsPageSpec.cs
  • samples/Widgets/src/Widgets.Application/Widgets/Create/CreateWidgetCommand.cs
  • samples/Widgets/src/Widgets.Application/Widgets/Create/CreateWidgetHandler.cs
  • samples/Widgets/src/Widgets.Application/Widgets/Create/CreateWidgetValidator.cs
  • samples/Widgets/src/Widgets.Application/Widgets/GetById/GetWidgetByIdHandler.cs
  • samples/Widgets/src/Widgets.Application/Widgets/GetById/GetWidgetByIdQuery.cs
  • samples/Widgets/src/Widgets.Application/Widgets/List/ListWidgetsHandler.cs
  • samples/Widgets/src/Widgets.Application/Widgets/List/ListWidgetsQuery.cs
  • samples/Widgets/src/Widgets.Application/Widgets/Rename/RenameWidgetCommand.cs
  • samples/Widgets/src/Widgets.Application/Widgets/Rename/RenameWidgetHandler.cs
  • samples/Widgets/src/Widgets.Application/Widgets/Rename/RenameWidgetValidator.cs
  • samples/Widgets/src/Widgets.Domain/Events/WidgetCreated.cs
  • samples/Widgets/src/Widgets.Domain/Events/WidgetRenamed.cs
  • samples/Widgets/src/Widgets.Domain/Events/WidgetRestocked.cs
  • samples/Widgets/src/Widgets.Domain/Widget.cs
  • samples/Widgets/src/Widgets.Domain/WidgetId.cs
  • samples/Widgets/src/Widgets.Infrastructure/DependencyInjection.cs
  • samples/Widgets/src/Widgets.Infrastructure/WidgetConfiguration.cs
  • samples/Widgets/src/Widgets.Infrastructure/WidgetRepository.cs
  • samples/Widgets/src/Widgets.Infrastructure/WidgetsDbContext.cs
  • samples/Widgets/tests/Widgets.ArchitectureTests/HexagonDependencyTests.cs
  • samples/Widgets/tests/Widgets.IntegrationTests/WidgetsApiTests.cs
  • samples/Widgets/tests/Widgets.UnitTests/Behaviors/ValidationBehaviorTests.cs
  • samples/Widgets/tests/Widgets.UnitTests/GlobalUsings.cs
  • samples/Widgets/tests/Widgets.UnitTests/Handlers/CreateWidgetHandlerTests.cs
  • samples/Widgets/tests/Widgets.UnitTests/Handlers/GetWidgetByIdHandlerTests.cs
  • samples/Widgets/tests/Widgets.UnitTests/Handlers/ListWidgetsHandlerTests.cs
  • samples/Widgets/tests/Widgets.UnitTests/Handlers/RenameWidgetHandlerTests.cs
  • samples/Widgets/tests/Widgets.UnitTests/Validators/CreateWidgetValidatorTests.cs
  • samples/Widgets/tests/Widgets.UnitTests/Validators/RenameWidgetValidatorTests.cs
  • src/ResQ.BuildingBlocks.Adapters.Messaging/Consumers/ConsumerOptions.cs
  • src/ResQ.BuildingBlocks.Adapters.Messaging/Consumers/DictionaryIntegrationEventTypeRegistry.cs
  • src/ResQ.BuildingBlocks.Adapters.Messaging/Consumers/IntegrationEventDispatcher.cs
  • src/ResQ.BuildingBlocks.Adapters.Messaging/Consumers/MessageConsumerService.cs
  • src/ResQ.BuildingBlocks.Adapters.Messaging/DependencyInjection/MessagingBuilder.cs
  • src/ResQ.BuildingBlocks.Adapters.Messaging/DependencyInjection/MessagingServiceCollectionExtensions.cs
  • src/ResQ.BuildingBlocks.Adapters.Messaging/Events/IIntegrationEventHandler.cs
  • src/ResQ.BuildingBlocks.Adapters.Messaging/Idempotency/NullIdempotencyStore.cs
  • src/ResQ.BuildingBlocks.Adapters.Messaging/InMemory/ChannelMessageBroker.cs
  • src/ResQ.BuildingBlocks.Adapters.Messaging/Null/NullIntegrationEventPublisher.cs
  • src/ResQ.BuildingBlocks.Adapters.Messaging/Reliability/IDeadLetterSink.cs
  • src/ResQ.BuildingBlocks.Adapters.Messaging/Reliability/RetryOptions.cs
  • src/ResQ.BuildingBlocks.Adapters.Messaging/Serialization/SystemTextJsonMessageSerializer.cs
  • src/ResQ.BuildingBlocks.Adapters.Messaging/Transport/IMessageSource.cs
  • src/ResQ.BuildingBlocks.Adapters.Messaging/Transport/MessageEnvelope.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/Conventions/ModelBuilderExtensions.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/DependencyInjection/PersistenceServiceCollectionExtensions.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/DependencyInjection/ResqPersistenceOptions.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/Idempotency/EfIdempotencyStore.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/Idempotency/InboxMessage.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/Idempotency/InboxMessageConfiguration.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/Interceptors/AuditInterceptor.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/Interceptors/IAuditable.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/Outbox/EfOutbox.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/Outbox/IOutbox.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/Outbox/OutboxMessage.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/Outbox/OutboxMessageConfiguration.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/Outbox/OutboxOptions.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/Outbox/OutboxRelay.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/Repositories/ReadRepository.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/Repositories/Repository.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/Specifications/SpecificationEvaluator.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/Uow/EfUnitOfWork.cs
  • src/ResQ.BuildingBlocks.Adapters.Persistence/Uow/TransactionBehavior.cs
  • src/ResQ.BuildingBlocks.Adapters.Web/Correlation/CorrelationMiddleware.cs
  • src/ResQ.BuildingBlocks.Adapters.Web/Cors/CorsExtensions.cs
  • src/ResQ.BuildingBlocks.Adapters.Web/DependencyInjection/WebServiceCollectionExtensions.cs
  • src/ResQ.BuildingBlocks.Adapters.Web/Endpoints/EndpointExtensions.cs
  • src/ResQ.BuildingBlocks.Adapters.Web/Endpoints/IEndpoint.cs
  • src/ResQ.BuildingBlocks.Adapters.Web/ErrorHandling/ProblemDetailsConfigurator.cs
  • src/ResQ.BuildingBlocks.Adapters.Web/ErrorHandling/ProblemDetailsExceptionHandler.cs
  • src/ResQ.BuildingBlocks.Adapters.Web/OpenApi/OpenApiExtensions.cs
  • src/ResQ.BuildingBlocks.Adapters.Web/Options/ResqWebOptions.cs
  • src/ResQ.BuildingBlocks.Adapters.Web/Pagination/CursorCodec.cs
  • src/ResQ.BuildingBlocks.Adapters.Web/Pagination/PageRequest.cs
  • src/ResQ.BuildingBlocks.Adapters.Web/Pagination/PaginationOptions.cs
  • src/ResQ.BuildingBlocks.Adapters.Web/Results/ProblemDetailsMapper.cs
  • src/ResQ.BuildingBlocks.Adapters.Web/Results/ResultExtensions.cs
  • src/ResQ.BuildingBlocks.Adapters.Web/Validation/ValidationEndpointFilter.cs
  • src/ResQ.BuildingBlocks.Adapters.Web/Validation/ValidationFilterExtensions.cs
  • src/ResQ.BuildingBlocks.Adapters.Web/Versioning/ApiVersioningExtensions.cs
  • src/ResQ.BuildingBlocks.Application/Abstractions.cs
  • src/ResQ.BuildingBlocks.Application/Behaviors.cs
  • src/ResQ.BuildingBlocks.Application/DependencyInjection/ApplicationServiceCollectionExtensions.cs
  • src/ResQ.BuildingBlocks.Application/Dispatch/CqrsRequest.cs
  • src/ResQ.BuildingBlocks.Application/Dispatch/ISender.cs
  • src/ResQ.BuildingBlocks.Application/Dispatch/Sender.cs
  • src/ResQ.BuildingBlocks.Application/Events/DomainEventDispatcher.cs
  • src/ResQ.BuildingBlocks.Application/Events/IDomainEventHandler.cs
  • src/ResQ.BuildingBlocks.Application/Integration/IIdempotencyStore.cs
  • src/ResQ.BuildingBlocks.Application/Integration/IIntegrationEventPublisher.cs
  • src/ResQ.BuildingBlocks.Application/Integration/IIntegrationEventTypeRegistry.cs
  • src/ResQ.BuildingBlocks.Application/Integration/IMessageSerializer.cs
  • src/ResQ.BuildingBlocks.Application/Integration/IntegrationEvent.cs
  • src/ResQ.BuildingBlocks.Application/Pagination/CursorPage.cs
  • src/ResQ.BuildingBlocks.Application/Pagination/OffsetPage.cs
  • src/ResQ.BuildingBlocks.Application/Persistence/IRepository.cs
  • src/ResQ.BuildingBlocks.Application/Persistence/ISpecification.cs
  • src/ResQ.BuildingBlocks.Application/Persistence/Specification.cs
  • src/ResQ.BuildingBlocks.Domain/Guard.cs
  • src/ResQ.BuildingBlocks.Domain/Primitives.cs
  • src/ResQ.BuildingBlocks.Domain/Results.cs
  • src/ResQ.BuildingBlocks.ServiceDefaults/Behaviors/MetricsBehavior.cs
  • src/ResQ.BuildingBlocks.ServiceDefaults/Behaviors/ObservabilityExtensions.cs
  • src/ResQ.BuildingBlocks.ServiceDefaults/Behaviors/TracingBehavior.cs
  • src/ResQ.BuildingBlocks.ServiceDefaults/Diagnostics/ResqDiagnostics.cs
  • src/ResQ.BuildingBlocks.ServiceDefaults/Options/OptionsRegistrationExtensions.cs
  • src/ResQ.BuildingBlocks.ServiceDefaults/Resilience/ResiliencePipelineExtensions.cs
  • src/ResQ.BuildingBlocks.ServiceDefaults/ServiceDefaultsExtensions.cs
  • src/ResQ.BuildingBlocks.ServiceDefaults/Time/SystemClock.cs
  • src/ResQ.BuildingBlocks.Testing.Integration/Fixtures/DatabaseCollection.cs
  • src/ResQ.BuildingBlocks.Testing.Integration/Fixtures/PostgresContainerFixture.cs
  • src/ResQ.BuildingBlocks.Testing.Integration/Web/ResqWebApplicationFactory.cs
  • src/ResQ.BuildingBlocks.Testing/Architecture/HexagonRules.cs
  • src/ResQ.BuildingBlocks.Testing/Builders/Builder.cs
  • src/ResQ.BuildingBlocks.Testing/DependencyInjection/TestDoublesExtensions.cs
  • src/ResQ.BuildingBlocks.Testing/Events/RecordingDomainEventDispatcher.cs
  • src/ResQ.BuildingBlocks.Testing/Events/RecordingIntegrationEventPublisher.cs
  • src/ResQ.BuildingBlocks.Testing/Logging/CapturingLoggerProvider.cs
  • src/ResQ.BuildingBlocks.Testing/Time/FakeClock.cs
  • src/ResQ.BuildingBlocks.Testing/Uow/FakeUnitOfWork.cs
  • src/ResQ.BuildingBlocks.Testing/Uow/NoopUnitOfWork.cs
  • src/ResQ.BuildingBlocks.Testing/Uow/ThrowingUnitOfWork.cs

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added A-Samples Sample applications under samples/ C-Documentation Improvements or additions to documentation pkg:domain Changes to ResQ.BuildingBlocks.Domain C-Testing Tests and test tooling pkg:application Changes to ResQ.BuildingBlocks.Application pkg:adapters-persistence Changes to ResQ.BuildingBlocks.Adapters.Persistence pkg:testing Changes to ResQ.BuildingBlocks.Testing A-DevOps CI/CD workflows, actions, git hooks, and devcontainer pkg:adapters-web Changes to ResQ.BuildingBlocks.Adapters.Web pkg:service-defaults Changes to ResQ.BuildingBlocks.ServiceDefaults pkg:testing-integration Changes to ResQ.BuildingBlocks.Testing.Integration pkg:adapters-messaging Changes to ResQ.BuildingBlocks.Adapters.Messaging labels Sep 28, 2026
…n re-runnable

Build and attest the assets before the Release is created, so a failure
there publishes nothing. Skip creation when the Release already exists, so
a re-run after a failed upload can finish the job.
@github-actions github-actions Bot removed the C-Chore Chore: deps, tooling, or config with no public API change label Sep 28, 2026
@github-actions github-actions Bot added C-Chore Chore: deps, tooling, or config with no public API change and removed C-Chore Chore: deps, tooling, or config with no public API change labels Sep 28, 2026
@WomB0ComB0
WomB0ComB0 merged commit 16d0525 into main Sep 28, 2026
34 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

A-DevOps CI/CD workflows, actions, git hooks, and devcontainer A-Samples Sample applications under samples/ C-Chore Chore: deps, tooling, or config with no public API change C-Documentation Improvements or additions to documentation C-Testing Tests and test tooling pkg:adapters-messaging Changes to ResQ.BuildingBlocks.Adapters.Messaging pkg:adapters-persistence Changes to ResQ.BuildingBlocks.Adapters.Persistence pkg:adapters-web Changes to ResQ.BuildingBlocks.Adapters.Web pkg:application Changes to ResQ.BuildingBlocks.Application pkg:domain Changes to ResQ.BuildingBlocks.Domain pkg:service-defaults Changes to ResQ.BuildingBlocks.ServiceDefaults pkg:testing Changes to ResQ.BuildingBlocks.Testing pkg:testing-integration Changes to ResQ.BuildingBlocks.Testing.Integration size/L

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant