Skip to content

chore(security): add SCA scan workflow - #973

Open
nirmal-joishi-a0 wants to merge 1 commit into
5.xfrom
security/add-sca
Open

nirmal-joishi-a0 wants to merge 1 commit into
5.xfrom
security/add-sca

Conversation

@nirmal-joishi-a0

Copy link
Copy Markdown

✏️ Changes

This pull request adds a security hardening workflow. No functional changes are introduced.

🚧 Untested — automated PR. This workflow was added automatically and has not been run or validated in this repository's CI. Before merging, confirm the workflow actually triggers and passes on your default branch, and that a green result is not masking a skipped or silently-ignored scan. Do not merge solely because checks appear green.

If the run fails for anything specific to this repo — a missing secret, environment setup, or other config only this repo needs (which we, as external authors, have no visibility into) — fixing it before merging is the repo owner's responsibility.

SCA Scan

This PR adds .github/workflows/sca.yml. It uses the Okta-approved SCA workflow from auth0/devsecops-tooling: 'auth0/devsecops-tooling/.github/workflows/sca-scan.yml@e29f26478db18ff0bcbe4bc447a8fbd54fbeec9e'

⚠️ Before merging, review the added .github/workflows/sca.yml and make any adjustments your CI environment requires.

Required org secrets (must be present)

  • SNYK_TOKEN
  • SIGNAL_HANDLER_TOKEN
  • SIGNAL_HANDLER_DOMAIN

🛑 Declining this workflow

This is an organization-enforced security-hardening workflow, so closing this PR is not enough — the tool treats a plain close as a discard and opens a fresh replacement PR on its next run.

To permanently decline this category, a maintainer must close this PR and add one of these labels to it:

Label Use when
remediation: not-required The category is already handled another way for this repo.
remediation: not-applicable The category genuinely does not apply (e.g. there is no manifest to scan).

Applying a label requires write, triage, or admin access, so the label is a trusted maintainer signal. Once a closed PR carries one of these labels, the tool respects the decline and will not reopen a replacement.

🔮 Type of Change

  • Standard

🔗 References

This change applies a standard automated security-scanning workflow as part of routine repository hardening.

  • I explained why this change is needed.

📖 Documentation

No user-facing changes have been introduced.

  • I reflected this change in the (internal and/or user-facing) documentation, or added an explanation for why no documentation update is needed.

🎯 Testing

⚠️ This workflow has not been tested in this repository. It must be validated before merging — confirm it triggers, runs, and passes without silently ignoring failures.

  • The added workflow has been run and verified green in this repository's CI (not merged on an untriggered/empty result).

🚀 Deployment

  • This change can support multiple releases of the code serving traffic at the same time.

🔥 Rollback

Reverting this PR removes the added workflow file — no further action required.

  • I explained what the rollback for this change will look like.

@nirmal-joishi-a0
nirmal-joishi-a0 requested a review from a team as a code owner September 30, 2026 14:05
@nirmal-joishi-a0

Copy link
Copy Markdown
Author

@auth0/project-dx-sdks-engineer-codeowner please review the files in the PR. This automated security-hardening workflow is untested in this repo — before merging, confirm it triggers and passes (and is not silently ignoring failures); do not merge on a green result alone.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant