ci(security): add secret scan and SBOM
This commit is contained in:
@@ -545,6 +545,8 @@ SEC-008 implements the same durable state machine with `<final>.uploading` and `
|
||||
|
||||
### P2-4 — Harden build provenance and secret scanning
|
||||
|
||||
**Status (2026-08-30): partially complete.** Exact .NET SDK selection, NuGet locks, hash-locked Python dependencies, npm lock enforcement, advisory gates, a no-value tracked-secret scanner with synthetic canaries, and deterministic multi-ecosystem CycloneDX generation now run in CI. Immutable action/image/installer identifiers, retained SBOM artifacts, container/licence scanning and the unresolved model-stack advisories still require verified upstream metadata or unavailable scanner/Docker runtime. See `docs/verification/jt-017-dotnet-provenance.md`, `docs/security/supply-chain-policy.md` and V-192/V-210.
|
||||
|
||||
- **Findings/scope:** JT-017/JT-020; action/image/installer pinning, SDK/locks/hashes, SBOM, container/secret scan, archive fixtures.
|
||||
- **Dependencies:** approved update cadence and scanner availability.
|
||||
- **Acceptance criteria:** immutable CI dependencies; reproducible documented toolchain; scans block policy-defined severity; no live credential patterns.
|
||||
|
||||
Reference in New Issue
Block a user