ci(security): add secret scan and SBOM
This commit is contained in:
@@ -0,0 +1,40 @@
|
||||
# Supply-chain and credential scanning policy
|
||||
|
||||
## Required repository gates
|
||||
|
||||
Pull requests and `main` builds must pass all of the following without silently excluding a project:
|
||||
|
||||
- locked NuGet restore for the API and test project;
|
||||
- `npm ci` plus the configured high-severity audit gate;
|
||||
- hash-required installation of the Linux Python lock;
|
||||
- the package-manager advisory checks recorded in CI;
|
||||
- `python3 scripts/supply-chain.py scan-secrets` over every Git-tracked file; and
|
||||
- `python3 scripts/supply-chain.py generate-sbom --output .artifacts/jobjakt.cdx.json`.
|
||||
|
||||
The generated CycloneDX 1.5 SBOM combines the committed npm, NuGet and Python lock files. It is a build artifact, not a replacement for the locks or an image scan. Its lock digest and deterministic component ordering make dependency changes reviewable without adding generated files to source control.
|
||||
|
||||
The built-in tracked-secret scanner is deliberately high confidence. It detects private-key headers and recognizable JWT, AWS, GitHub, Google, Slack and live Stripe credentials, skips binary files and files over 2 MiB, and reports only the credential class and file location. It never prints a matched value. This gate complements—not replaces—host secret management, history review and a dedicated scanner when one is approved.
|
||||
|
||||
## Dependency and advisory exceptions
|
||||
|
||||
High or critical reachable advisories block release. An exception must be a reviewed repository document containing the package and affected path, advisory identifiers, reachability evidence, compensating control, accountable owner, expiry date and removal condition. Expired or ownerless exceptions fail closed. A version pin alone is not an exception.
|
||||
|
||||
The outstanding Torch/Transformers findings are not accepted exceptions. Their model-loading path and production image remain blocked pending a compatible resolution or a bounded, reviewed isolation decision.
|
||||
|
||||
## Immutable inputs
|
||||
|
||||
Third-party workflow actions, container bases and downloaded installers must move only to identifiers verified from their authoritative upstream source. Do not guess a commit SHA, image digest or installer checksum. Updates are reviewed commits and retain the prior known-good identifier for rollback.
|
||||
|
||||
The current mutable action/image references and `dotnet-install.sh` download remain open until network-backed upstream metadata and a container scanner are available. The local SBOM and tracked-secret gates do not claim to close those items.
|
||||
|
||||
## Credential response
|
||||
|
||||
If the tracked scan or a reviewer finds a real credential:
|
||||
|
||||
1. stop the affected build and suppress the value from chat, tickets and logs;
|
||||
2. revoke or rotate it at the issuing system before treating source cleanup as sufficient;
|
||||
3. remove it from the current tree and add the narrow prevention rule or ignore boundary needed;
|
||||
4. assess reachable history and CI artifacts using filenames/commit IDs only; and
|
||||
5. coordinate any history rewrite separately because it disrupts clones and does not revoke a credential.
|
||||
|
||||
Never weaken a detector merely to make an unexplained finding pass.
|
||||
Reference in New Issue
Block a user