Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
123 commits
Select commit Hold shift + click to select a range
3d18d86
Import complete Kars Bridge as an optional monorepo application
pallakatos Sep 11, 2026
cf7e0ed
Preserve standalone lockfile and artifact routes in Bridge checkout
pallakatos Sep 11, 2026
61a7f3f
Fix Bridge monorepo installation guide paths
pallakatos Sep 11, 2026
b3c1183
Keep source-stub gate linear for complete application imports
pallakatos Sep 11, 2026
69e4a73
Distinguish real UI field syntax from unfinished implementation markers
pallakatos Sep 11, 2026
5d78f11
Split Bridge task routes into cohesive bounded modules
pallakatos Sep 11, 2026
e7d489e
Enforce receipt anchor pins consistently and keep witness evidence ad…
pallakatos Sep 11, 2026
132e1be
Compose complete public credential harness repairs into Bridge candidate
pallakatos Sep 11, 2026
0995410
Register receipt trust regressions and remove unused task import
pallakatos Sep 11, 2026
67cf7c2
Split Bridge operator routes into bounded cohesive modules
pallakatos Sep 11, 2026
1ef457d
Add permanent core independence and Bridge contract CI gates
pallakatos Sep 11, 2026
9b9ea4f
Compose nullable CRD startup repair with permanent Bridge contract gates
pallakatos Sep 11, 2026
183eb5e
Split Bridge composition routes into bounded modules
pallakatos Sep 11, 2026
a0f4d1f
Use the public operator review workflow for native writer enrollment
pallakatos Sep 11, 2026
99c84c0
Expose secret-safe native operator failure stages
pallakatos Sep 11, 2026
871277e
Preserve manifest identity and honest remediation evidence
pallakatos Sep 11, 2026
d799abc
Name the native consumer execution-drift diagnostic
pallakatos Sep 11, 2026
ac3866c
Compose strict native activation and remediation identity repairs
pallakatos Sep 11, 2026
003735e
Extract bounded receipt verification module without changing evidence
pallakatos Sep 11, 2026
1778ebc
Retain mandatory review for all remediation identity versions
pallakatos Sep 11, 2026
f716b30
Retain the explicit no-merge wording in PR dedupe instructions
pallakatos Sep 11, 2026
2383ccd
Split Bridge Team routes into bounded modules
pallakatos Sep 11, 2026
66a07f0
Split the Bridge cluster adapter into bounded modules
pallakatos Sep 11, 2026
e573cea
Preserve statement tests' receipt framing helper access
pallakatos Sep 11, 2026
e89df61
Centralize standard content digests without changing public identities
pallakatos Sep 11, 2026
580b059
Make receipt fixture digests explicit after adapter extraction
pallakatos Sep 11, 2026
1289a68
Keep digest test modules after production items
pallakatos Sep 11, 2026
31cb027
Register the qualified digest adapter with exact-file boundaries
pallakatos Sep 11, 2026
a4d398d
Keep shared-qualification diagnostics within the safe source allowlist
pallakatos Sep 11, 2026
56b015b
Compose reviewed-qualification candidate for real multiworkspace acce…
pallakatos Sep 11, 2026
5e8f9fc
Require real single- and multi-workspace grant update continuity
pallakatos Sep 11, 2026
6f0b2a1
Route receipt primitives through a bounded standard verification adapter
pallakatos Sep 11, 2026
0c2944b
Report only fixed credential failure categories and scope booleans
pallakatos Sep 11, 2026
a201ade
Compose safe active-grant updates with their real native acceptance case
pallakatos Sep 11, 2026
d20645c
Integrate source-reviewed evaluator parity into the full Bridge candi…
pallakatos Sep 11, 2026
7d50e16
Remove receipt decoder imports superseded by the standard adapter
pallakatos Sep 11, 2026
a9a2d0d
Isolate the legacy credential review key without changing active tickets
pallakatos Sep 11, 2026
7e2df1e
Bound efficiency tests and credential integration modules
pallakatos Sep 11, 2026
8b05add
Require new audit records rather than reusing old scoped sign-offs
pallakatos Sep 11, 2026
ac8aa09
Split engineering intake into bounded behavior-preserving modules
pallakatos Sep 11, 2026
751c2ed
Use vetted tag comparison and register exact reviewed crypto boundaries
pallakatos Sep 11, 2026
b3760dc
Compose exact evaluator source approval without extending old audit s…
pallakatos Sep 11, 2026
b3d39d2
Split live capability options into bounded modules
pallakatos Sep 11, 2026
8f0232e
Split web DTOs by domain while preserving the public type surface
pallakatos Sep 11, 2026
b82a976
Keep gateway watcher wire types in a bounded type-only module
pallakatos Sep 11, 2026
47716ba
Bound server BFF client types without moving authentication or transport
pallakatos Sep 11, 2026
4ea3448
Qualify schema-first installation through the public core operator
pallakatos Sep 11, 2026
38318dc
Compose shared core schema lifecycle with complete Bridge qualification
pallakatos Sep 11, 2026
1b1f98c
Bound validation phases while retaining exact check ordering and outc…
pallakatos Sep 11, 2026
f6b7694
Extract the existing Copilot sign-in component from the provider wizard
pallakatos Sep 11, 2026
5679974
Keep governed credential failures actionable without exposing inner data
pallakatos Sep 11, 2026
5a2d08f
Split the agent graph without changing layout or interaction
pallakatos Sep 11, 2026
4608531
Enroll observer targets through the real reviewed private-scope workflow
pallakatos Sep 11, 2026
25a60e7
Split Team detail panels without moving server data or state
pallakatos Sep 12, 2026
a264ef2
Split intake presentation without introducing a new state boundary
pallakatos Sep 12, 2026
7421df3
Refresh the full Bridge candidate onto the qualified evaluator integr…
pallakatos Sep 12, 2026
3650c15
Separate Mission presentation while preserving server data flow
pallakatos Sep 12, 2026
6c5aadf
Bound Team composer review panels without moving state or handlers
pallakatos Sep 12, 2026
3f7a014
Retain fixed SRE staging failure phases in native diagnostics
pallakatos Sep 12, 2026
cced23c
Preserve secret-safe governed-service failure evidence before cleanup
pallakatos Sep 12, 2026
c54793f
Retire and requalify reviewed late observer runtime scopes
pallakatos Sep 12, 2026
6342d22
Require real retired-observer identity and old-key rejection in nativ…
pallakatos Sep 12, 2026
87813d5
Compose reviewed credential and observer runtime repairs for paired q…
pallakatos Sep 12, 2026
3c5a0b8
Snapshot the anchored v2 Task bundle in native observer enrollment
pallakatos Sep 12, 2026
76e1537
Compose canonical SRE migration with the paired runtime candidate
pallakatos Sep 12, 2026
cfd2f85
Keep migration profile fixtures distinct on evaluator-v2 source trees
pallakatos Sep 12, 2026
c3e8e91
Retain bounded late-observer preview failure locations
pallakatos Sep 12, 2026
9b99e6b
Use supported metadata-only kubectl projection for private credential…
pallakatos Sep 12, 2026
010fd77
Retain only strict late-preview readiness comparison facts
pallakatos Sep 12, 2026
38be138
Require coherent late-observer snapshots without rejecting RV-only re…
pallakatos Sep 12, 2026
0c6f5d3
Validate unchanged migration seeds against the early historical API gate
pallakatos Sep 12, 2026
2092844
Retain bounded migration seed reports in schema qualification artifacts
pallakatos Sep 12, 2026
06ba4a6
Test historical scalar action data and strict nested migration bounda…
pallakatos Sep 12, 2026
2c8f1e3
Preserve and converge Sandbox condition generation evidence
pallakatos Sep 12, 2026
620f692
Assert condition transition timestamps at their exact Kubernetes wire…
pallakatos Sep 12, 2026
ba5b92d
Keep wire timestamp fixture inside its transition test scope
pallakatos Sep 12, 2026
3d6f398
Preserve the exact writer-settling diagnostic leaf
pallakatos Sep 12, 2026
3ac4153
Settle witnessed Task credential transitions before late private enro…
pallakatos Sep 12, 2026
b1c9fe0
Validate unpersisted CRD previews without inventing storage revisions
pallakatos Sep 12, 2026
0643cdc
Project only fixed writer-recheck booleans from native CLI failures
pallakatos Sep 12, 2026
60b7258
Align Secret metadata printer views during witnessed writer settling
pallakatos Sep 12, 2026
52517e1
Probe the exact production Task schema SSA request before full migration
pallakatos Sep 12, 2026
a4cc748
Trace private observer target requests without exposing upstream cont…
pallakatos Sep 12, 2026
26a5284
Preserve verified Helm Apply ownership across controlled negative fix…
pallakatos Sep 12, 2026
3fc124d
Retain only closed private-command failure facts in native evidence
pallakatos Sep 12, 2026
39a1afe
Use a nonpersisting Pending proposal for the post-migration schema probe
pallakatos Sep 12, 2026
7fe7922
Report bounded private operator command and lifecycle failure facts
pallakatos Sep 12, 2026
048910d
Patch Bridge rendering and query parser dependencies
pallakatos Sep 12, 2026
e04eeee
Patch gateway Vitest without changing production dependencies
pallakatos Sep 12, 2026
cebeed6
Harden Bridge proxy, evidence link and Foundry transport boundaries
pallakatos Sep 12, 2026
ef4cf5b
Require the complete Bridge component qualification graph
pallakatos Sep 12, 2026
df643e9
fix(observer): normalize endpoint and expose bounded transport progress
pallakatos Sep 12, 2026
1ee16e4
test(router): initialize TLS provider in isolated observer regressions
pallakatos Sep 12, 2026
022c81f
test(bridge): retain private-safe enrollment template drift evidence
pallakatos Sep 12, 2026
f1f8776
fix(cli): recheck concurrent writer retirement snapshots
pallakatos Sep 12, 2026
2e89861
test(cli): harden wire qualification and expose restoration checks
pallakatos Sep 12, 2026
526597e
fix(cli): revalidate a conflicted reviewed sandbox pause
pallakatos Sep 14, 2026
7ebfbcc
test(bridge): collect bounded observer API packet evidence
pallakatos Sep 14, 2026
5dec504
test(ci): run native diagnostic contracts before cluster qualification
pallakatos Sep 14, 2026
49b78c8
test(bridge): select effective Cilium identities for observer diagnos…
pallakatos Sep 14, 2026
d526b63
fix(cli): observe retirement independently of Task status timing
pallakatos Sep 14, 2026
4f5d90d
fix(controller): allow enrolled observers to verify Kubernetes metadata
pallakatos Sep 14, 2026
2316d90
test(e2e): retain bounded port-forward failure details
pallakatos Sep 14, 2026
934d744
fix(controller): complete API namespace recheck and split regressions
pallakatos Sep 14, 2026
24c85cd
test(bridge): distinguish writer and private retirement baselines
pallakatos Sep 14, 2026
4929662
style(bridge): apply required Microsoft and MIT source headers
pallakatos Sep 14, 2026
5f634ae
fix(ci): verify bounded tool downloads before qualification
pallakatos Sep 14, 2026
191a320
chore(repo): enforce format-safe Microsoft MIT attribution
pallakatos Sep 14, 2026
4b301e0
fix(deps): require patched Rustls for RUSTSEC-2026-0285
pallakatos Sep 14, 2026
b516713
test(bridge): retain rotation failure state before controller restart
pallakatos Sep 14, 2026
1d0fc5c
fix(ci): preserve raw YAML and Helm document boundaries in headers
pallakatos Sep 14, 2026
5e9a1fe
test: make Cilium API-group equality explicit
pallakatos Sep 14, 2026
4b4b577
docs: record governed GitHub privacy source closure
pallakatos Sep 14, 2026
4804eec
test(ci): preserve historical audit scope during header updates
pallakatos Sep 14, 2026
89fef91
docs: attest scoped credential and GitHub integration review
pallakatos Sep 14, 2026
8f35353
fix(bridge): isolate artifact content and enforce signed admin authority
pallakatos Sep 14, 2026
f276558
test(ci): retain bounded public CRD readiness errors
pallakatos Sep 14, 2026
366f02c
fix(bridge): align gateway SDK calls and workspace authority
pallakatos Sep 14, 2026
aa40563
fix(bridge): renew maintenance work and preserve honest artifact attr…
pallakatos Sep 14, 2026
1f2c483
docs: attest reviewed Bridge integration and verified repair closure
pallakatos Sep 14, 2026
74d959b
Merge qualified credential integration into the Bridge candidate
pallakatos Sep 14, 2026
b967c1e
docs: bind Bridge source approval to completed native qualification
pallakatos Sep 14, 2026
f8f4a7f
test(e2e): observe coherent current-generation CR status
pallakatos Sep 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
254 changes: 254 additions & 0 deletions .github/workflows/bridge-ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,254 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

name: Bridge CI

on:
pull_request:
branches: [main, dev, kars-bridge]
push:
branches: [main, kars-bridge]
workflow_dispatch:

permissions:
contents: read

concurrency:
group: bridge-ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}

jobs:
bridge-required-gates:
name: Bridge component acceptance
needs: [addon, bff, dependencies, lockfiles, rust-dependencies, secrets, security, web]
if: always()
runs-on: ubuntu-22.04
env:
COMPONENT_RESULTS: ${{ toJSON(needs) }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- run: python3 ci/bridge_component_results.py

bff:
name: BFF build and test
runs-on: ubuntu-latest
defaults:
run:
working-directory: bridge/bff
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@631a55b12751854ce901bb631d5902ceb48146f7 # stable
with:
components: clippy, rustfmt
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
workspaces: bridge/bff
- run: cargo fmt --all -- --check
- run: cargo clippy --locked --all-targets -- -D warnings
- name: Require trust and authorization regression registration
run: |
cargo test --locked -- --list > /tmp/kars-bridge-bff-tests.txt
for name in \
routes::receipts::anchor::tests::pins_follow_the_controller_raw_key_fingerprint_contract \
routes::receipts::anchor::tests::copied_key_id_cannot_substitute_another_public_key \
routes::receipts::anchor::tests::malformed_empty_mismatched_or_missing_pins_fail_closed \
kars::receipt_log::tests::receipt_endpoint_still_requires_signed_payload_binding_and_full_overflow_inclusion \
providers::signing::tests::sha256_matches_standard_known_answers_without_normalizing_bytes \
kars::credential_review::digest_tests::review_digest_preserves_compact_sorted_json_and_full_hex_width \
kars::receipt_log::digest_tests::chain_hash_keeps_decimal_sequence_and_exact_pipe_framing \
routes::artifacts::digest_tests::artifact_addresses_keep_the_existing_sixteen_byte_short_form \
routes::github::tests::connection_names_keep_the_original_raw_subject_and_eight_byte_digest \
providers::receipt::tests::rfc8032_known_answer_and_malformed_signatures_keep_exact_verification_semantics \
providers::credential_review::tests::legacy_v1_key_preserves_domain_null_byte_and_raw_secret_encoding \
providers::credential_review::tests::tag_comparison_requires_equal_length_and_every_byte_without_normalization \
auth::admin_tests::admin_route_and_role_matrix_does_not_promote_operators_or_gate_reads \
auth::admin_tests::direct_bff_admin_mutations_deny_missing_forged_expired_and_non_admin_principals \
auth::admin_tests::budget_and_retention_handlers_require_admin_even_without_route_middleware \
auth::admin_tests::signed_admins_can_set_and_clear_each_budget_scope_and_retention \
auth::admin_tests::operator_reads_stay_available_while_user_and_auditor_console_reads_stay_denied \
routes::tasks::artifacts::tests::active_and_unknown_artifacts_download_unchanged_from_live_or_retained_tasks \
routes::tasks::artifacts::tests::passive_artifact_previews_keep_inline_viewing_without_mime_sniffing_or_byte_changes \
routes::tasks::artifacts::tests::artifact_head_has_the_same_protection_and_filename_is_header_safe \
routes::tasks::artifacts::tests::artifact_response_hardening_preserves_ownership_and_missing_file_denials \
routes::engineering::remediation::renewal_tests::current_producer_new_advisory_after_done_gets_followup_not_lost_or_replayed \
routes::engineering::remediation::renewal_tests::completed_source_ignores_poll_time_titles_and_pr_candidates_but_not_changed_fix_facts \
routes::engineering::remediation::renewal_tests::current_producer_pending_source_refreshes_without_spending_capacity_or_changing_identity \
routes::engineering::remediation::renewal_tests::active_approved_and_nonce_bound_pending_inputs_are_frozen_with_dependent_followups \
routes::engineering::remediation::renewal_tests::current_producer_aggregation_is_order_independent_and_removes_only_closed_pending_findings \
routes::engineering::remediation::renewal_tests::full_empty_snapshot_retires_unassigned_source_without_claiming_delivery_or_erasing_runs \
routes::engineering::remediation::renewal_tests::refreshed_followup_preserves_original_history_and_withdrawn_findings_are_not_reintroduced \
routes::engineering::remediation::renewal_tests::proven_legacy_history_remains_immutable_when_current_producer_finds_a_new_alert \
routes::engineering::remediation::renewal_tests::final_merge_rechecks_assignment_and_completion_after_admission \
routes::engineering::remediation::renewal_tests::direct_final_merge_aggregates_current_producer_and_preserves_completed_pr_evidence \
routes::engineering::remediation::renewal_tests::remediation_queue_cap_retries_new_followups_but_allows_unassigned_refreshes \
routes::engineering::remediation::renewal_tests::missing_v2_original_metadata_cannot_authorize_overwriting_a_completed_row \
routes::engineering::remediation::renewal_tests::legacy_retirement_cannot_rewrite_a_concurrently_assigned_pending_task \
routes::engineering::remediation::renewal_tests::duplicated_alert_pages_keep_latest_facts_and_all_pr_candidate_links_in_either_order \
routes::engineering::remediation::renewal_tests::partial_poll_refreshes_seen_alerts_without_discarding_unseen_pending_findings \
routes::engineering::remediation::renewal_tests::source_withdrawal_final_merge_does_not_change_a_newly_assigned_v2_task
do
grep -Fx "$name: test" /tmp/kars-bridge-bff-tests.txt
done
- run: cargo test --locked
- name: Check explicit credential review orchestration
run: PYTHONDONTWRITEBYTECODE=1 PYTHONPATH=../tests/native-credentials python3 -m unittest discover -s ../tests/native-credentials -p test_credential_review.py

web:
name: Web build and lint
runs-on: ubuntu-latest
defaults:
run:
working-directory: bridge/web
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: '22'
cache: npm
cache-dependency-path: bridge/web/package-lock.json
- run: npm ci
- run: npm run lint
- run: npx --no-install tsc --noEmit
- name: Check all web authorization, form, proxy and evidence contracts
run: node --experimental-strip-types --test tests/*.test.mjs
- name: Build the production web image without publishing
run: docker build --tag kars-bridge-web-qualification:latest .
- name: Start web with an immutable root filesystem
run: |
container=$(docker run --detach --read-only --cap-drop ALL \
--security-opt no-new-privileges \
--tmpfs /tmp:rw,noexec,nosuid,size=134217728,uid=10001,gid=10001 \
--tmpfs /app/.next/cache:rw,noexec,nosuid,size=268435456,uid=10001,gid=10001 \
--publish 127.0.0.1:3000:3000 --env HOSTNAME=0.0.0.0 \
kars-bridge-web-qualification:latest)
echo "WEB_CONTAINER_ID=$container" >> "$GITHUB_ENV"
curl --fail --retry 20 --retry-all-errors --retry-delay 1 \
--max-time 10 http://127.0.0.1:3000/api/health
docker exec "$container" node -e '
const fs = require("node:fs");
const assert = require("node:assert/strict");
fs.writeFileSync("/app/.next/cache/qualification", "cache works");
fs.writeFileSync("/tmp/qualification", "temporary writes work");
assert.throws(() => fs.writeFileSync("/app/qualification", "denied"),
error => error.code === "EROFS" || error.code === "EACCES");
'
docker exec "$container" node --input-type=module -e '
import assert from "node:assert/strict";
import sharp from "sharp";
const image = await sharp(Buffer.from([255, 0, 0, 255]),
{ raw: { width: 1, height: 1, channels: 4 } }).resize(2, 2).png().toBuffer();
const metadata = await sharp(image).metadata();
assert.equal(metadata.width, 2);
assert.equal(metadata.height, 2);
assert.equal(metadata.format, "png");
'
- name: Remove the qualification container
if: always()
run: |
if [ -n "${WEB_CONTAINER_ID:-}" ]; then
docker logs "$WEB_CONTAINER_ID"
docker rm --force "$WEB_CONTAINER_ID"
fi

addon:
name: Add-on install and uninstall
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: '22'
cache: npm
cache-dependency-path: bridge/teams-gateway/package-lock.json
- uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1
- run: npm ci
working-directory: bridge/teams-gateway
- run: npm run lint && npm run typecheck && npm run build && npm test
working-directory: bridge/teams-gateway
- run: helm lint bridge/deploy/helm/kars-bridge
- uses: helm/kind-action@ef37e7f390d99f746eb8b610417061a60e82a6cc # v1.14.0
with:
cluster_name: bridge-addon-lifecycle
kubeconfig: ${{ runner.temp }}/bridge-addon-kubeconfig
- name: Exercise real Helm removal in a disposable cluster
working-directory: bridge/teams-gateway
env:
BRIDGE_TEST_KIND_LIFECYCLE: '1'
BRIDGE_TEST_KUBECONFIG: ${{ runner.temp }}/bridge-addon-kubeconfig
run: npm test -- tests/chart-lifecycle.test.ts

dependencies:
name: Dependency audit (${{ matrix.project }})
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
project: [web, teams-gateway]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: '22'
- run: node ci/npm-audit-bulk.mjs bridge/${{ matrix.project }}/package-lock.json

rust-dependencies:
name: Rust dependency audit
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: taiki-e/install-action@ba47c86ac325773530516bb756137ac718732518 # v2.86.5
with:
tool: cargo-audit
- run: cargo audit --file bridge/bff/Cargo.lock

lockfiles:
name: Lockfile consistency (${{ matrix.project }})
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
project: [web, teams-gateway]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: '22'
- name: Resolve without installing packages or running dependency scripts
working-directory: bridge/${{ matrix.project }}
run: npm install --package-lock-only --ignore-scripts --no-audit
- name: Require the resolved lockfile to be committed
run: git diff --exit-code -- bridge/${{ matrix.project }}/package-lock.json
- name: Retain the generated lockfile for review
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v4
with:
name: proposed-lockfile-${{ matrix.project }}
path: bridge/${{ matrix.project }}/package-lock.json
if-no-files-found: error
retention-days: 7

security:
name: Source and configuration security
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
with:
scan-type: fs
scan-ref: bridge
scanners: misconfig,secret
severity: HIGH,CRITICAL
exit-code: '1'

secrets:
name: Secret scanning
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- uses: trufflesecurity/trufflehog@30d5bb91af1a771378349dbbb0c82129392acf70 # v3.95.6
with:
extra_args: --only-verified
Loading
Loading