Skip to content

DATAGO-142436: onboard FOSSA SCA scanning + manifest updates - #1

Open
mustafaal-sakkaf wants to merge 2 commits into
mainfrom
DATAGO-142436-fossa-guardian-onboarding
Open

DATAGO-142436: onboard FOSSA SCA scanning + manifest updates#1
mustafaal-sakkaf wants to merge 2 commits into
mainfrom
DATAGO-142436-fossa-guardian-onboarding

Conversation

@mustafaal-sakkaf

@mustafaal-sakkaf mustafaal-sakkaf commented Jul 27, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Adds .fossa.yml with SolaceLabs_<repo> locator for consistent FOSSA project identification.
  • Adds .github/workflow-config.json with both licensing and vulnerability gates in REPORT mode.
  • Adds .github/workflows/sca-scan-and-guard.yml — triggers on push to `main`, runs FOSSA scan via the `SolaceDev/solace-public-workflows` reusable workflow, then updates the `solace-cloud-manifest` DynamoDB `dev` entry (squad: `ebp`).

Jira: DATAGO-142436

Test plan

  • Verify workflow runs on merge to `main`
  • Confirm FOSSA project is populated with a scan
  • Confirm `solace-cloud-manifest` DynamoDB `dev` entry is updated
  • Flip gates to BLOCK once REPORT mode is stable

🤖 Generated with Claude Code

mustafaal-sakkaf and others added 2 commits July 26, 2026 19:52
Adds .fossa.yml, .github/workflows/sca-scan-and-guard.yml, and
.github/workflow-config.json to onboard this repo to FOSSA scanning
on merge to default branch per DATAGO-142436.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant