Skip to content

Enforce Production Security and Release Gates - #299

Merged
jonfairbanks merged 2 commits into
masterfrom
fix/enforce-production-security-gates
Sep 30, 2026
Merged

jonfairbanks merged 2 commits into
masterfrom
fix/enforce-production-security-gates

Conversation

@jonfairbanks

Copy link
Copy Markdown
Owner

Summary

  • Run Snyk for Dependabot and fail when SNYK_TOKEN is missing.
  • Require successful CI, Snyk, and CodeQL checks on the exact release commit before container or chart publishing.
  • Run fresh checks for manual publishing and reject unsupported branches, stale results, skipped scans, and newer failed reruns.
  • Add manual triggers to CI and security workflows so publishing can request fresh checks without bypassing them.

Actionlint, YAML parsing, shell syntax, and 12 release-gate cases pass. The gate requires results from GitHub Actions, checks the newest run for each context, and rechecks the branch head before releasing publishing jobs. It does not check out PR code or receive registry credentials.

Both branches now require PRs, their existing CI checks, Snyk, and CodeQL, with admin enforcement enabled. The Dependabot SNYK_TOKEN secret was added and its presence was verified.

This production patch also carries the Dependabot routing already merged into develop by #297. It removes the direct post-merge Dependabot publication dispatch, since Dependabot now targets develop and production releases must pass the shared gate.

@jonfairbanks
jonfairbanks merged commit 58d2a30 into master Sep 30, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant