Repository navigation
docs: expand Security Gates with end-to-end CI/CD examples - #111
Merged
Ali-Yazdani merged 2 commits intoOct 4, 2026
Merged
Conversation
Supersedes OWASP#99, rebased onto current master as a single commit. Adds to 2-3-5-Security-Gates.md: - Pipeline placement diagram and severity-threshold table - Policy-as-code example (.security-gates.yaml) and gradual rollout guidance - End-to-end GitHub Actions and GitLab CI gate pipelines (secrets, SAST, SCA, container, IaC) with a single fail-closed summary gate - Sample gate output, exceptions-as-code, and an auditable emergency bypass - License gate with SPDX-aware matching - Additional tools, KPIs and references Keeps all V0.4 content and the edits from OWASP#110 (semgrep ci example, VEX link, scanner-pinning pitfall, updated references). Third-party actions in the examples are pinned to release tags. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
5 tasks done
Contributor
Author
|
@Ali-Yazdani please review this one. |
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Several pipeline examples are incomplete or fail under documented configurations, including the Checkov report, GitLab secret scan, and omitted GitLab gates.
Review effort: Balanced
Findings: 2
Open (5)
What changed in this PR
Expands security-gate guidance with practical policy, CI/CD, exception, and operational examples.
Changes:
- Adds threshold, rollout, and policy-as-code guidance.
- Provides GitHub Actions and GitLab CI pipeline examples.
- Documents exception handling, emergency bypasses, tools, and KPIs.
| File | Description |
|---|---|
current-version/2-Process/2-3-Build/2-3-5-Security-Gates.md |
Expands end-to-end security-gate documentation and examples. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…, add GitLab SCA/IaC jobs, full-depth secrets scan, exception ticket Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Ali-Yazdani
approved these changes
Oct 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Supersedes #99, recreated from current
masteras a single clean commit per @Ali-Yazdani's suggestion.What this adds to
2-3-5-Security-Gates.md.security-gates.yaml) and gradual rollout guidanceNotes
semgrep ciexample, VEX link, scanner-pinning pitfall, updated references).pre-commit run --all-filespasses locally.