Skip to content

docs: expand Security Gates with end-to-end CI/CD examples - #111

Merged
Ali-Yazdani merged 2 commits into
OWASP:masterfrom
farhanashrafdev:docs/security-gates-ci-examples
Oct 4, 2026
Merged

Ali-Yazdani merged 2 commits into
OWASP:masterfrom
farhanashrafdev:docs/security-gates-ci-examples

Conversation

@farhanashrafdev

Copy link
Copy Markdown
Contributor

Supersedes #99, recreated from current master as a single clean commit per @Ali-Yazdani's suggestion.

What this adds to 2-3-5-Security-Gates.md

  • Pipeline placement diagram and severity-threshold table
  • Policy-as-code example (.security-gates.yaml) and gradual rollout guidance
  • End-to-end GitHub Actions and GitLab CI gate pipelines (secrets, SAST, SCA, container, IaC) with a single fail-closed summary gate
  • Sample gate output, exceptions-as-code, and an auditable emergency bypass
  • License gate with SPDX-aware matching
  • Additional tools, KPIs and references

Notes

Supersedes OWASP#99, rebased onto current master as a single commit.

Adds to 2-3-5-Security-Gates.md:
- Pipeline placement diagram and severity-threshold table
- Policy-as-code example (.security-gates.yaml) and gradual rollout guidance
- End-to-end GitHub Actions and GitLab CI gate pipelines (secrets, SAST, SCA,
  container, IaC) with a single fail-closed summary gate
- Sample gate output, exceptions-as-code, and an auditable emergency bypass
- License gate with SPDX-aware matching
- Additional tools, KPIs and references

Keeps all V0.4 content and the edits from OWASP#110 (semgrep ci example, VEX link,
scanner-pinning pitfall, updated references). Third-party actions in the
examples are pinned to release tags.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@farhanashrafdev

Copy link
Copy Markdown
Contributor Author

@Ali-Yazdani please review this one.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Several pipeline examples are incomplete or fail under documented configurations, including the Checkov report, GitLab secret scan, and omitted GitLab gates.

Review effort: Balanced
Findings: 2 High severity · 2 Medium severity · 1 Low severity

Open (5)
What changed in this PR

Expands security-gate guidance with practical policy, CI/CD, exception, and operational examples.

Changes:

  • Adds threshold, rollout, and policy-as-code guidance.
  • Provides GitHub Actions and GitLab CI pipeline examples.
  • Documents exception handling, emergency bypasses, tools, and KPIs.
File Description
current-version/​2-Process/​2-3-Build/​2-3-5-Security-Gates.md Expands end-to-end security-gate documentation and examples.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread current-version/2-Process/2-3-Build/2-3-5-Security-Gates.md Outdated
Comment thread current-version/2-Process/2-3-Build/2-3-5-Security-Gates.md
Comment thread current-version/2-Process/2-3-Build/2-3-5-Security-Gates.md Outdated
Comment thread current-version/2-Process/2-3-Build/2-3-5-Security-Gates.md
Comment thread current-version/2-Process/2-3-Build/2-3-5-Security-Gates.md
…, add GitLab SCA/IaC jobs, full-depth secrets scan, exception ticket

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@Ali-Yazdani
Ali-Yazdani merged commit d6c780e into OWASP:master Oct 4, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants