Repository navigation
chore(ci-governance): adopt Node profile - #1178
inditextechci-sync[bot] wants to merge 12 commits into
Conversation
Governance-Provenance: hmac-sha256:95c194067917380ccfc8dcddd7405aca4cb9a4adaeb2d0716b29cc20a6c5b773
Release PreviewThis pull request has the |
The governed SonarCloud lane installs with npm ci --ignore-scripts (security hardening), so the native canvas module used by Konva text rendering lacks its binary during vitest. Add a product-owned pretest step that rebuilds only canvas. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Contribution License Agreement - Valid 🟢All commits contain valid signoff. As a confirmation, remember that you are agreeing to our Contribution License Agreement. |
Release PreviewThis pull request has the |
Create-only governance file required by Apache-2.0 notice policy (repolinter notice-file-exists). Content matches the validated preflight PR; REUSE.toml annotation updated to cover it. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Missing Copyright/License first-lines flagged by Repo Linter on the product sources of both create-app CLIs. Header text matches the house style used across workspace packages; shebang preserved on first line. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Exclude the create-*app generator templates from the license header rule: they scaffold end-user projects and must not carry Inditex copyright headers. Accept code/package.json for the JS package metadata rule, matching the workspaces layout. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Release PreviewThis pull request has the |
SonarCloud S8707 flags recursive template copy into a path derived from CLI arguments. Validate that the resolved output directory stays inside the current working directory before any file operation. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Release PreviewThis pull request has the |
SonarCloud S8707 tracks the rewritten destination path through the recursive copy. Route every copy through a copier bound to the resolved output root so each destination is validated before the write. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Release PreviewThis pull request has the |
S8707 tracks the raw CLI argument into downstream file operations. Split the argument into path segments, reject traversal and drive segments, and derive every downstream path from the validated list. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Release PreviewThis pull request has the |
The create-*app generators write into a user-specified directory by design; the S8707 findings are documented false positives in sonar-project.properties. Replace the last-segment index access with Array.at per typescript:S7755. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Release PreviewThis pull request has the |
The scanner keys components as code/packages/... so the ignore resourceKey must be anchored accordingly; narrow to create-app sources only. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Release PreviewThis pull request has the |
The governed lane runs the scanner from the repository root, so the pre-existing code/sonar-project.properties policy never applied. Re-home it: documented S8707 false positive for the create-*app generators (user-specified output is the product's purpose) and coverage/duplication exclusions for generator sources without tests. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Release PreviewThis pull request has the |
1 similar comment
Release PreviewThis pull request has the |
|



CI governance adoption
This PR was generated by the PR-only controller. Review and merge it; the controller never pushes directly to the default branch.
Profile
node(Node)Source revisions
base:ead1a050aef47a396fe6fe712bb82bd0c16b182anode:0c48f11970416cb5b49caec2e91313f2d7251cb8Planned changes
add.github/ISSUE_TEMPLATE/1-bug.ymladd.github/ISSUE_TEMPLATE/2-feature.ymladd.github/ISSUE_TEMPLATE/3-other.ymladd.github/ISSUE_TEMPLATE/config.ymladd.github/PULL_REQUEST_TEMPLATE.mdadd.github/inditextech-ci-node.jsonadd.github/inditextech-ci-sync-manifest.jsonupdate.github/workflows/code-npm_node-PR_verify.ymlupdate.github/workflows/code-npm_node-publish-release-and-snapshot.ymladd.github/workflows/code-npm_node-release-core.ymlupdate.github/workflows/code-npm_node-sonarcloud-analysis.ymlupdate.github/workflows/code-release_preview.ymlupdate.github/workflows/codeql.ymladd.github/workflows/pr-verify.ymladd.github/workflows/push-verify.ymlupdate.github/workflows/scorecard-analysis.ymladd.sync-excludePreserved consumer files
CODE_OF_CONDUCT.mdCONTRIBUTING.mdSECURITY.mdrepolinter.json