fix(ci): stabilize security scan reporting and SEDR scan scope - #49
Merged
Arc-E-Tect merged 2 commits intoAug 8, 2026
Merged
Conversation
…efresh Vulnerability scanning now runs alongside the shared NVD cache refresh (Monday and Friday) for both hexagonal-spring-rules and sedr-library, matching the SoftwareEngineeringDoneRight-Gradle mechanism. Removes the standalone spring-rules-security-scan.yml schedule and drops the per-project Security-Scan job from the build/release workflows so releases no longer perform their own scans. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
What changed:\n- updated reusable security scan artifact upload path to dependency-check/dependency-check-report.html\n- aligned sedr-library dependencyCheck behavior with Option A by making failBuildOnCVSS conditional on FAIL_ON_FATAL\n- disabled Node analyzers for sedr-library (nodeAuditEnabled and nodeEnabled)\n\nWhy:\n- the failing release run could not upload the report from the old path\n- sedr-library scans were failing on npm toolchain transitive vulnerabilities unrelated to released Java artifacts\n\nHow:\n- changed the upload-artifact target in the reusable workflow to the actual generated report location\n- mirrored existing conditional CVSS gate pattern and analyzer settings used for Java-only scope\n\nOutcomes:\n- security report artifact path is now consistent with Dependency-Check output\n- sedr-library follows Option A scan scope and avoids Node lockfile-driven release failures\n- validated with actionlint on the modified workflow and a successful Gradle configuration run (./gradlew help)
Arc-E-Tect
deleted the
extract-vulnerability-scans-from-regular-workflows
branch
August 8, 2026 15:49
Arc-E-Tect
added a commit
that referenced
this pull request
Aug 8, 2026
## [0.5.1](v0.5.0...v0.5.1) (2026-08-08) ### 🐛 Bug Fixes * **examples:** remove mavenLocal now that dependencies are released ([#42](#42)) ([9b20913](9b20913)), closes [#42](#42) * **ci:** stabilize security scan reporting and SEDR scan scope ([#49](#49)) ([f5c7df2](f5c7df2)), closes [#49](#49) * **CI:** stop the NVD cache refresh from timing out on every cold sync ([#46](#46)) ([cbaebf3](cbaebf3)), closes [#46](#46) ### 📝 Documentation * **hexagonal-spring-rules:** update README version to 0.5.0 [skip ci] ([5c8b553](5c8b553)) ### 🔧 Misc * Change NVD cache refresh schedule to weekly ([#45](#45)) ([83c3552](83c3552)), closes [#45](#45) * dependency updates for Library projects ([#43](#43)) ([fa70e5e](fa70e5e)), closes [#43](#43) * dependency updates for Library projects ([#47](#47)) ([398933c](398933c)), closes [#47](#47) * dependency updates for Library projects ([#48](#48)) ([105111d](105111d)), closes [#48](#48) * **Sedr Library:** update npm packages ([#44](#44)) ([821da37](821da37)), closes [#44](#44)
Owner
Author
|
🎉 This PR is included in version 0.5.1 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
Owner
Author
|
🎉 This PR is included in version 1.0.0 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
Arc-E-Tect
added a commit
that referenced
this pull request
Aug 17, 2026
# [1.0.0](hexagonal-spring-rules-v0.5.0...hexagonal-spring-rules-v1.0.0) (2026-08-17) ### ✨ New and updated features * **api-detector-core:** add ContractProgressTableWriter for shared Progress Over Time reporting ([#59](#59)) ([dd4d36a](dd4d36a)), closes [#59](#59) * add geo-tracker-lens-pack library with independent release pipeline ([#60](#60)) ([1730931](1730931)), closes [#60](#60) * **api-detector-core:** add PathTemplates.stripBasePath and OpenApiEndpointCollector.firstServerBasePath ([#66](#66)) ([865e711](865e711)), closes [#66](#66) * **api-detector-core:** add published shared library for the SEDR API detector plugins ([#52](#52)) ([059ee4d](059ee4d)), closes [#52](#52) * **api-detector-core:** add ScanProgressReporter for visible long-scan progress ([#56](#56)) ([9357bc9](9357bc9)), closes [#56](#56) * **api-detector-core:** add shared contract-lifecycle progress history framework ([#53](#53)) ([0bb104e](0bb104e)), closes [#53](#53) * **api-detector-core:** separate real implementation evidence from stub evidence in contract history ([#64](#64)) ([0775933](0775933)), closes [#64](#64) * **api-detector-core:** write and tolerate a schema-version marker ([#65](#65)) ([e27d53f](e27d53f)), closes [#65](#65) ### 🐛 Bug Fixes * **ci:** detect first semantic release version in calculate workflow ([#61](#61)) ([3a80fe1](3a80fe1)), closes [#61](#61) * **workflow:** fix tag checking for project-specific tag formats ([#54](#54)) ([ce8f57e](ce8f57e)), closes [#54](#54) * **hexagonal-spring-rules:** give module its own semantic-release tag namespace ([#67](#67)) ([613a69a](613a69a)), closes [#67](#67) * **examples:** remove mavenLocal now that dependencies are released ([#42](#42)) ([9b20913](9b20913)), closes [#42](#42) * **ci:** stabilize security scan reporting and SEDR scan scope ([#49](#49)) ([f5c7df2](f5c7df2)), closes [#49](#49) * **CI:** stop the NVD cache refresh from timing out on every cold sync ([#46](#46)) ([cbaebf3](cbaebf3)), closes [#46](#46) * tag checking for project-specific tag formats in workflow ([#55](#55)) ([9e9255e](9e9255e)), closes [#55](#55) * **geo-tracker-lens-pack:** use https scm connection for Maven Central metadata ([#63](#63)) ([5bb98c0](5bb98c0)), closes [#63](#63) ### 📝 Documentation * **api-detector-core:** update README version to 0.1.0 [skip ci] ([14c5f16](14c5f16)) * **api-detector-core:** update README version to 0.2.0 [skip ci] ([2f68414](2f68414)) * **api-detector-core:** update README version to 0.3.0 [skip ci] ([9c63eac](9c63eac)) * **hexagonal-spring-rules:** update README version to 0.5.0 [skip ci] ([5c8b553](5c8b553)) * **sedr-library:** update README version to 0.5.1 [skip ci] ([bb4becf](bb4becf)) * **sedr-library:** update README version to 0.5.2 [skip ci] ([8320bb8](8320bb8)) * **api-detector-core:** update README version to 1.0.0 [skip ci] ([ebb1c5f](ebb1c5f)) * **geo-tracker-lens-pack:** update README version to 1.0.0 [skip ci] ([ab46583](ab46583)) * **geo-tracker-lens-pack:** update README version to 1.0.1 [skip ci] ([1ac70e4](1ac70e4)) * **api-detector-core:** update README version to 1.1.0 [skip ci] ([1680e7b](1680e7b)) * **api-detector-core:** update README version to 1.2.0 [skip ci] ([6656c7f](6656c7f)) ### 🔧 Misc * Change NVD cache refresh schedule to weekly ([#45](#45)) ([83c3552](83c3552)), closes [#45](#45) * dependency updates for Library projects ([#43](#43)) ([fa70e5e](fa70e5e)), closes [#43](#43) * dependency updates for Library projects ([#47](#47)) ([398933c](398933c)), closes [#47](#47) * dependency updates for Library projects ([#48](#48)) ([105111d](105111d)), closes [#48](#48) * dependency updates for Library projects ([#50](#50)) ([2d5d3ce](2d5d3ce)), closes [#50](#50) * dependency updates for Library projects ([#58](#58)) ([83dff89](83dff89)), closes [#58](#58) * Make workflow triggers more specific and add progress reporter ([#57](#57)) ([10c64dc](10c64dc)), closes [#57](#57) * **ci:** remove redundant Monday NVD cache refresh schedule ([#51](#51)) ([ffd937f](ffd937f)), closes [#51](#51) * **geo-tracker-lens-pack:** trigger release pipeline after CI fix ([b2440cc](b2440cc)) * **Sedr Library:** update npm packages ([#44](#44)) ([821da37](821da37)), closes [#44](#44) ### BREAKING CHANGE * **api-detector-core:** contractHistoryFile written by a previous version of this library (9 fields, no stubbedAt) is no longer readable by ContractHistoryStore.load() - it now throws LegacyContractHistoryFormatException instead of loading it under the old, now-ambiguous implementedAt semantics. Consumers must migrate existing history files (mirage-api-detector's new migrateContractHistory task) or start a fresh history file before upgrading.
Owner
Author
|
🎉 This PR is included in version 1.0.0 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the failing security scan path and applies Option A for sedr-library dependency-check by disabling Node analyzers and making CVSS failure conditional on FAIL_ON_FATAL. Validated with actionlint and a Gradle configuration run.