Skip to content

chore(ci-governance): adopt Node profile - #1178

Open
inditextechci-sync[bot] wants to merge 12 commits into
mainfrom
automated/ci-governance-sync
Open

inditextechci-sync[bot] wants to merge 12 commits into
mainfrom
automated/ci-governance-sync

Conversation

@inditextechci-sync

Copy link
Copy Markdown

CI governance adoption

This PR was generated by the PR-only controller. Review and merge it; the controller never pushes directly to the default branch.

Profile

  • node (Node)

Source revisions

  • base: ead1a050aef47a396fe6fe712bb82bd0c16b182a
  • node: 0c48f11970416cb5b49caec2e91313f2d7251cb8

Planned changes

  • add .github/ISSUE_TEMPLATE/1-bug.yml
  • add .github/ISSUE_TEMPLATE/2-feature.yml
  • add .github/ISSUE_TEMPLATE/3-other.yml
  • add .github/ISSUE_TEMPLATE/config.yml
  • add .github/PULL_REQUEST_TEMPLATE.md
  • add .github/inditextech-ci-node.json
  • add .github/inditextech-ci-sync-manifest.json
  • update .github/workflows/code-npm_node-PR_verify.yml
  • update .github/workflows/code-npm_node-publish-release-and-snapshot.yml
  • add .github/workflows/code-npm_node-release-core.yml
  • update .github/workflows/code-npm_node-sonarcloud-analysis.yml
  • update .github/workflows/code-release_preview.yml
  • update .github/workflows/codeql.yml
  • add .github/workflows/pr-verify.yml
  • add .github/workflows/push-verify.yml
  • update .github/workflows/scorecard-analysis.yml
  • add .sync-exclude

Preserved consumer files

  • preserved CODE_OF_CONDUCT.md
  • preserved CONTRIBUTING.md
  • preserved SECURITY.md
  • preserved repolinter.json

Governance-Provenance: hmac-sha256:95c194067917380ccfc8dcddd7405aca4cb9a4adaeb2d0716b29cc20a6c5b773
@inditextechci-sync
inditextechci-sync Bot requested a review from a team as a code owner September 28, 2026 08:37
@inditextechci-sync inditextechci-sync Bot added the skip-release Do not publish a release for this change. label Sep 28, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Release Preview

This pull request has the skip-release label and will not create an npm release.

Comment thread .github/workflows/code-npm_node-release-core.yml Dismissed
Comment thread .github/workflows/code-npm_node-release-core.yml Dismissed
Comment thread .github/workflows/code-npm_node-release-core.yml Dismissed
Comment thread .github/workflows/code-npm_node-release-core.yml Dismissed
Comment thread .github/workflows/code-npm_node-release-core.yml Dismissed
Comment thread .github/workflows/code-npm_node-release-core.yml Dismissed
The governed SonarCloud lane installs with npm ci --ignore-scripts
(security hardening), so the native canvas module used by Konva text
rendering lacks its binary during vitest. Add a product-owned pretest
step that rebuilds only canvas.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@signoff-validator

Copy link
Copy Markdown

Contribution License Agreement - Valid 🟢

All commits contain valid signoff. As a confirmation, remember that you are agreeing to our Contribution License Agreement.

@github-actions

Copy link
Copy Markdown
Contributor

Release Preview

This pull request has the skip-release label and will not create an npm release.

ivanasabi and others added 3 commits September 28, 2026 11:03
Create-only governance file required by Apache-2.0 notice policy
(repolinter notice-file-exists). Content matches the validated preflight
PR; REUSE.toml annotation updated to cover it.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Missing Copyright/License first-lines flagged by Repo Linter on the
product sources of both create-app CLIs. Header text matches the house
style used across workspace packages; shebang preserved on first line.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Exclude the create-*app generator templates from the license header
rule: they scaffold end-user projects and must not carry Inditex
copyright headers. Accept code/package.json for the JS package
metadata rule, matching the workspaces layout.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

Release Preview

This pull request has the skip-release label and will not create an npm release.

SonarCloud S8707 flags recursive template copy into a path derived
from CLI arguments. Validate that the resolved output directory stays
inside the current working directory before any file operation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

Release Preview

This pull request has the skip-release label and will not create an npm release.

SonarCloud S8707 tracks the rewritten destination path through the
recursive copy. Route every copy through a copier bound to the
resolved output root so each destination is validated before the
write.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

Release Preview

This pull request has the skip-release label and will not create an npm release.

Comment thread code/packages/create-backend-app/src/create-app.ts Fixed
Comment thread code/packages/create-backend-app/src/create-app.ts Fixed
Comment thread code/packages/create-backend-app/src/create-app.ts Fixed
Comment thread code/packages/create-frontend-app/src/create-app.ts Fixed
Comment thread code/packages/create-frontend-app/src/create-app.ts Fixed
Comment thread code/packages/create-frontend-app/src/create-app.ts Fixed
S8707 tracks the raw CLI argument into downstream file operations.
Split the argument into path segments, reject traversal and drive
segments, and derive every downstream path from the validated list.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

Release Preview

This pull request has the skip-release label and will not create an npm release.

The create-*app generators write into a user-specified directory by
design; the S8707 findings are documented false positives in
sonar-project.properties. Replace the last-segment index access with
Array.at per typescript:S7755.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

Release Preview

This pull request has the skip-release label and will not create an npm release.

The scanner keys components as code/packages/... so the ignore
resourceKey must be anchored accordingly; narrow to create-app
sources only.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

Release Preview

This pull request has the skip-release label and will not create an npm release.

ivanasabi and others added 2 commits September 28, 2026 11:49
The governed lane runs the scanner from the repository root, so the
pre-existing code/sonar-project.properties policy never applied.
Re-home it: documented S8707 false positive for the create-*app
generators (user-specified output is the product's purpose) and
coverage/duplication exclusions for generator sources without tests.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

Release Preview

This pull request has the skip-release label and will not create an npm release.

1 similar comment
@github-actions

Copy link
Copy Markdown
Contributor

Release Preview

This pull request has the skip-release label and will not create an npm release.

@sonarqubecloud

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-release Do not publish a release for this change.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants