Skip to content

ci: add SSDLC gate (qfg-66ko.1) - #2

Merged
jdwyah merged 1 commit into
mainfrom
ssdlc-sanity-gate
Oct 9, 2026
Merged

jdwyah merged 1 commit into
mainfrom
ssdlc-sanity-gate

Conversation

@jdwyah

@jdwyah jdwyah commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Part of qfg-66ko.1 (SOC 2 SSDLC controls).

  • Adds .github/workflows/ssdlc.yml, the thin caller copied from quonfig/ci/templates/ssdlc.yml (secrets: inherit with its reasoned nosemgrep). Checks: ssdlc / sanity, ssdlc / secrets, ssdlc / deps, ssdlc / sast.
  • Adds .github/claude-sanity-prompt.md, the repo-owned prompt for the cheap AI sanity check, tuned to this provider (public API and semver breakage, leaked keys in examples, release safety).
  • The hotfix label overrides the gate and posts a comment asking for a justification and a follow-up bead.

CI-only change. There is no version bump, so a merge to main publishes nothing.

🤖 Generated with Claude Code

Thin caller for the quonfig/ci reusable ssdlc workflow (sanity, secrets,
deps, sast; hotfix-label override) plus a sanity prompt tuned to this
provider's public API, semver and secrets-in-examples risks.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

SSDLC sanity check: PASS

Looking at the diff, this PR adds two configuration files:

  1. .github/claude-sanity-prompt.md — documentation of the PR sanity check process
  2. .github/workflows/ssdlc.yml — a GitHub Actions workflow for SSDLC security gates

Analysis:

  • No API changes: These are configuration/documentation only; no breaking changes to the Python package.
  • Secrets handling: The workflow uses secrets: inherit to pass ANTHROPIC_API_KEY to the shared quonfig/ci workflow. This is explicitly documented in the comment and has a nosemgrep exception, indicating it's an intentional pattern documented in the quonfig/ci README.
  • Permissions: Appropriate minimal permissions set (contents: read, pull-requests: write, issues: write, checks: read).
  • No debug code or version issues: No accidental commits or unmatched version bumps.

The PR is straightforward configuration for a security scanning gate. No obvious issues detected.

VERDICT: PASS

Model: claude-haiku-4-5-20251001, commit a216a81. Only BLOCK fails this check. Add the hotfix label to override.

@jdwyah
jdwyah merged commit f60ed45 into main Oct 9, 2026
7 checks passed
@jdwyah
jdwyah deleted the ssdlc-sanity-gate branch October 9, 2026 19:37
jdwyah added a commit that referenced this pull request Oct 9, 2026
* origin/main:
  ci: add SSDLC gate caller and repo sanity prompt (qfg-66ko.1) (#2)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant