root - chore: defense - gate stage-publish on Aikido scan-release - #75
Conversation
Add a scan-release job that runs aikido-api-client scan-release and make the existing pack/stage job need it. Reconcile staged publishing as PR #74. Co-authored-by: Jared Wray <me@jaredwray.com>
Co-authored-by: Jared Wray <me@jaredwray.com>
There was a problem hiding this comment.
Code Review
This pull request updates the documentation in DEFENSE_IN_DEPTH.md and SECURITY.md to reflect that the release workflow now stages packed tarballs using pnpm stage publish. However, the actual workflow file changes (such as .github/workflows/release.yaml) are missing from the pull request and should be included.
| - The lockfile is committed and CI installs with `--frozen-lockfile`. There is no Dependabot config; dependency updates go through reviewed PRs. | ||
| - CI workflows default to read-only `contents: read` permissions; generated output is never committed back from CI; every action is pinned to a full commit SHA; Socket Firewall (`sfw`) wraps `pnpm install`; zizmor lints workflows on every PR; checkouts that do not push set `persist-credentials: false`. | ||
| - The release workflow disables `setup-node` package-manager caching. | ||
| - The release workflow disables `setup-node` package-manager caching and stages packed tarballs with `pnpm stage publish` instead of publishing live. |
There was a problem hiding this comment.
The pull request title and description state that this PR adds an Aikido scan-release job and gates the stage-publish job on it. However, the actual workflow file (e.g., .github/workflows/release.yaml) is missing from the changes in this PR. Only documentation files (DEFENSE_IN_DEPTH.md and SECURITY.md) are currently modified. Please include the workflow file changes in this PR.
There was a problem hiding this comment.
The workflow change is in this PR. .github/workflows/release.yaml is modified on the first commit (e544607): it adds the scan-release job and build now needs: [scan-release]. The second commit only updates DEFENSE_IN_DEPTH.md with the pending PR number, which is likely what this review looked at in isolation.
Files in the PR: .github/workflows/release.yaml, DEFENSE_IN_DEPTH.md, SECURITY.md.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #75 +/- ##
=========================================
Coverage 100.00% 100.00%
=========================================
Files 3 3
Lines 19 19
Branches 1 1
=========================================
Hits 19 19 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Please check if the PR fulfills these requirements
What kind of change does this PR introduce? (Bug fix, feature, docs update, ...)
CI / supply-chain hardening.
Summary
Adds an Aikido
scan-releasejob that the stage-publish jobneeds:(defense-in-depth § 6).Status update
DEFENSE_IN_DEPTH.md: Aikido scan-release gate → (PR #75 pending); stage publish → PR #74Changes
scan-releaserunningaikido-api-client scan-release(Socket Firewall,package-manager-cache: false, pinned@aikidosec/ci-api-client@1.0.17)build(pack +pnpm stage publish) nowneeds: [scan-release];id-token: writeis scoped to that jobMaintainer
AIKIDO_CLIENT_API_KEYfrom Aikido → Continuous Integration settings (no publish authority). The GitHub app check on PRs is not this key.NPM_TOKEN/NODE_AUTH_TOKEN.Verification
needs: [scan-release]name:omitted (kebab-case job idscan-release)releaseitself isworkflow_dispatch/releaseonly)Reference
defense-in-depth-nodejs § 6