refactor(governance): anonymize integration codenames & add warrants #267
security-scan.yml
on: pull_request
Python Dependency Vulnerability Scan (Universal — NIST RA-5/SI-2 reporting: US_FED only)
55s
Matrix: Container Image Vulnerability Scan — Trivy (Universal — NIST RA-5/CM-8 reporting: US_FED only)
Dependency Lockfile Validation (Universal — NIST SI-2/CM-8 reporting: US_FED only)
30s
OPA Rego Policy Lint and Test (Universal — NIST CM-6/SI-7 reporting: US_FED only)
9s
Secret Scanning (Gitleaks)
6s
Generate and Validate SBOM (Universal — NIST CM-8/POAM-006 reporting: US_FED only)
1m 20s
NIST SP 800-53 Compliance Gate (US_FED only)
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
dependency-snapshot
|
1.06 KB |
sha256:0a1cee1d48a37db2f67630e421a41a24f35d5f369e2489f8cb4b10c726d24742
|
|
|
pip-audit-results
|
7.1 KB |
sha256:cee8ed38e4e1f758d72d6abab387a30d83a6200518087691a0b8ff7f5017b701
|
|
|
sbom-0
|
13.3 KB |
sha256:37e572d7c20563b0dab255772c5b0cf12710182f0b5f74b8cd7d2c3ef08f3cf9
|
|
|
sbom-02cbdb7dd372cc543fb6f607519b766b313d2f71
|
59.9 KB |
sha256:5b15346727d79bb4bb265954b7ea8df6a7144bf2ba97292456d6af835900a152
|
|
|
sbom-1
|
13.3 KB |
sha256:8a08c69ea1166a698a5cd6e0dbb49c8a13173ef883da2e5cad0674b7352564b2
|
|
|
sbom-2
|
13.3 KB |
sha256:eb14db8cc338704fd4b124ac4905ed681db13c94cdb1c66794957d4d4b61737d
|
|