Skip to content

Fix org baseline audit drift#31

Draft
NWarila wants to merge 1 commit into
mainfrom
fix/audit-resolve-dotgithub
Draft

Fix org baseline audit drift#31
NWarila wants to merge 1 commit into
mainfrom
fix/audit-resolve-dotgithub

Conversation

@NWarila

@NWarila NWarila commented Jun 6, 2026

Copy link
Copy Markdown
Owner

Summary

  • Track ADR 0011 and the example Mermaid source through the deny-all allowlist and baseline manifests.
  • Harden reusable security gates by pinning zizmor 1.25.2, running the pedantic gate, removing advisory bypass inputs, and repairing the Scorecard full-SHA pin.
  • Add bounded retry handling to the repo-hygiene OPA download while keeping checksum verification.

Verification

  • python tools/check_baseline_manifest.py
  • python tools/check_docs_layout.py
  • python tools/check_adr_schema.py
  • opa test policies/opa
  • python tools/build_opa_input.py | opa eval --fail-defined --format pretty --stdin-input --data policies/opa 'data.repo_hygiene.deny[_]'
  • actionlint
  • zizmor --persona pedantic .github/workflows
  • markdownlint-cli2 **/*.md
  • relative Markdown link check
  • workflow SHA resolver: 11 external action pins resolved

@NWarila NWarila force-pushed the fix/audit-resolve-dotgithub branch from 72378ec to 16fc668 Compare June 6, 2026 19:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant