19 lines
789 B
Markdown
19 lines
789 B
Markdown
# Build and supply-chain gate
|
|
|
|
Merge and release controls:
|
|
|
|
- frozen `pnpm-lock.yaml` installation; drift is blocking
|
|
- clean production build with hashed assets and build manifest
|
|
- machine-readable bundle sizes and checksums
|
|
- source plus built-asset credential-pattern scan
|
|
- direct dependency inventory and lockfile digest
|
|
- base/head dependency diff review record
|
|
|
|
Organization-specific vulnerability severity, denied-license list, SBOM format,
|
|
and scanner selection remain policy inputs. An approved suppression must record
|
|
reason, owner, expiry, affected package, and compensating control. Expired
|
|
suppressions are blocking.
|
|
|
|
`artifacts/security/dependency-diff.json` is a local baseline. CI replaces it
|
|
with the actual base/head direct and transitive lockfile diff before release.
|