ci: wire org governance gates#38
Merged
Merged
Conversation
Vendor the docs layout, ADR schema, and attribution residue gates from NWarila/.github. Pin repo-hygiene, CodeQL, and Scorecard reusables to NWarila/.github@5da716c. Skip Scorecard on pull_request; it runs on push, schedule, branch_protection_rule, and workflow_dispatch because it needs id-token and security-events scopes. Defer the baseline manifest gate until this repo owns baseline-manifest.json.
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PT-M4 - Governance CI wiring
Makes the template dogfood the org governance standard it is measured against.
A - Vendored doc/ADR gate tools + governance job
governancejob in template-ci.yml runs them (PR-base refs) + check_pin_parity.py.B - Org reusables (ADR-0007), SHA-pinned
C - Pin parity
Audited locally: vendored tools byte-identical; gate tools + pin-parity pass; reusables resolve at the real SHA with correct inputs/permissions. Note: CodeQL is actions-only by default (ruff S already covers bandit-class SAST); vendored-tool drift vs .github has no inbound sync yet (tracked follow-on).