From cce384b1eb8027dc189a4fa14f02da72c743e003 Mon Sep 17 00:00:00 2001 From: Aman Riat Date: Fri, 4 Sep 2026 17:03:11 -0400 Subject: [PATCH 1/6] chore(cra): onboard client-cli to FOSSA SCA scanning Adds the shared SCA scan and the solace-cloud-manifest write. Listed in the CRA Compliance product inventory (Annex A.12, Professional Services) as needing Guardian onboarding. squad is prof-services, not cto: A.12 is the Professional Services inventory, and cto would route findings into cto_vulnerabilities and file CTO Jiras. Dependencies come from: pom.xml. Scanning is read-only -- no publish, release or image step is added. Co-Authored-By: Claude Opus 5 (1M context) --- .fossa.yml | 25 +++++++++ .github/workflow-config.json | 8 +++ .github/workflows/sca-scan-and-guard.yml | 65 ++++++++++++++++++++++++ 3 files changed, 98 insertions(+) create mode 100644 .fossa.yml create mode 100644 .github/workflow-config.json create mode 100644 .github/workflows/sca-scan-and-guard.yml diff --git a/.fossa.yml b/.fossa.yml new file mode 100644 index 0000000..c6f4ffd --- /dev/null +++ b/.fossa.yml @@ -0,0 +1,25 @@ +version: 3 + +project: + locator: solaceservices_client-cli + id: solaceservices_client-cli + name: client-cli + teams: [] + labels: + - java + +vendoredDependencies: + forceRescans: false + scanMethod: CLILicenseScan + licenseScanPathFilters: + exclude: + - "./.git" + - "./.github" + +paths: + exclude: + - ./.git + - ./.github + +telemetry: + scope: full diff --git a/.github/workflow-config.json b/.github/workflow-config.json new file mode 100644 index 0000000..cacb8de --- /dev/null +++ b/.github/workflow-config.json @@ -0,0 +1,8 @@ +{ + "sca_scanning": { + "fossa": { + "policy": { "mode": "REPORT" }, + "vulnerability": { "mode": "REPORT" } + } + } +} diff --git a/.github/workflows/sca-scan-and-guard.yml b/.github/workflows/sca-scan-and-guard.yml new file mode 100644 index 0000000..43d9343 --- /dev/null +++ b/.github/workflows/sca-scan-and-guard.yml @@ -0,0 +1,65 @@ +name: SCA Scan +on: + pull_request: + branches: [master] + push: + branches: [master] + # Allows the scan to be re-run against trunk without waiting for a push, which + # matters when a merge commit carries [skip ci] and produces no run at all. + workflow_dispatch: + +permissions: + contents: read + id-token: write + packages: read + actions: read + statuses: write + checks: write + pull-requests: write + +jobs: + sca_scan: + uses: SolaceDev/solace-public-workflows/.github/workflows/sca-scan-and-guard.yaml@main + with: + setup_actions: '["setup-java"]' + secrets: + FOSSA_API_KEY: ${{ secrets.FOSSA_API_KEY }} + + update_manifest: + needs: sca_scan + # The manifest records what landed on the default branch, so it must never be + # written from a PR run -- the scan still runs, the write does not. + # workflow_dispatch is accepted so a [skip ci] merge can be registered after + # the fact; the default-branch check still gates the write. + if: >- + needs.sca_scan.result == 'success' + && (github.event_name == 'push' || github.event_name == 'workflow_dispatch') + && github.ref_name == github.event.repository.default_branch + runs-on: ubuntu-latest + permissions: + id-token: write + contents: read + packages: read + steps: + - name: Configure AWS credentials + uses: aws-actions/configure-aws-credentials@7474bc4690e29a8392af63c5b98e7449536d5c3a # v4 + with: + role-to-assume: ${{ secrets.MANIFEST_AWS_ROLE }} + aws-region: us-east-1 + + - name: Update solace-cloud-manifest + uses: SolaceDev/solace-public-workflows/.github/actions/cicd-helper@main + with: + rc_step: add_item_from_json_to_dynamodb_table + ddb_table_name: solace-cloud-manifest + ddb_partition_key: squad + ddb_sort_key: repository + ddb_item_to_be_added: | + { + "squad": "prof-services", + "repository": "${{ github.event.repository.name }}", + "dev": { + "sha": "${{ github.sha }}", + "version": "${{ github.ref_name }}" + } + } From 427ff0c2691136fdaa7588d2a45cea7f8fe64515 Mon Sep 17 00:00:00 2001 From: Aman Riat Date: Tue, 8 Sep 2026 11:44:49 -0400 Subject: [PATCH 2/6] fix(cra): pass java_distribution explicitly The shared SCA workflow forwards java_distribution to actions/setup-java but defaults it to an empty string, so Setup SCA Dependencies fails with "Input required and not supplied: distribution". Passing it here unblocks the scan without waiting on a fix to the shared workflow. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/sca-scan-and-guard.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/sca-scan-and-guard.yml b/.github/workflows/sca-scan-and-guard.yml index 43d9343..c588ed5 100644 --- a/.github/workflows/sca-scan-and-guard.yml +++ b/.github/workflows/sca-scan-and-guard.yml @@ -22,6 +22,9 @@ jobs: uses: SolaceDev/solace-public-workflows/.github/workflows/sca-scan-and-guard.yaml@main with: setup_actions: '["setup-java"]' + # Required: the shared workflow forwards this to actions/setup-java and its own + # default is empty, which fails with "Input required and not supplied: distribution". + java_distribution: temurin secrets: FOSSA_API_KEY: ${{ secrets.FOSSA_API_KEY }} From a07054384607102b52980ddb5e5cf08628f9c0fc Mon Sep 17 00:00:00 2001 From: Aman Riat Date: Tue, 8 Sep 2026 14:19:50 -0400 Subject: [PATCH 3/6] test(cra): temporary push trigger to land a Guardian-usable FOSSA scan A pull_request run records the scan under FOSSA branch "PR" with the branch name as the revision. Guardian looks up refs[]= and requires a hex SHA, so it cannot match those. A push to this branch has no PR number, so it takes the workflow's Manual path and registers under the default branch with the commit SHA. Temporary -- reverted once the scan has landed. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/sca-scan-and-guard.yml | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/.github/workflows/sca-scan-and-guard.yml b/.github/workflows/sca-scan-and-guard.yml index c588ed5..7e109f5 100644 --- a/.github/workflows/sca-scan-and-guard.yml +++ b/.github/workflows/sca-scan-and-guard.yml @@ -3,7 +3,15 @@ on: pull_request: branches: [master] push: - branches: [master] + branches: + - master + # TEMPORARY: a push here runs with no PR number, which takes the workflow's + # Manual path -- registering the scan in FOSSA under the repo's default branch + # with the commit SHA as the revision. The pull_request path instead records + # branch "PR" and the branch name as the revision, which Guardian cannot match + # (it looks up refs[]= and requires a hex SHA). Remove once the + # scan has landed. + - cra-onboard-sca-scan # Allows the scan to be re-run against trunk without waiting for a push, which # matters when a merge commit carries [skip ci] and produces no run at all. workflow_dispatch: From d85bad216f6197165b949e4a7f9151fb7c3f1357 Mon Sep 17 00:00:00 2001 From: Aman Riat Date: Tue, 8 Sep 2026 14:59:01 -0400 Subject: [PATCH 4/6] refactor(cra): use the shared update-manifest workflow Replaces the inline manifest job with the reusable workflow now on main, and drops the temporary push trigger that was added to land a Guardian-usable FOSSA scan from this branch. The previous job ran a container pulled from this org's registry namespace, which does not exist here -- so the manifest write could not have succeeded. The reusable workflow needs no image. It also owns the default-branch check, so the caller no longer hand-writes that condition. java_distribution is no longer passed: the shared workflow's default was fixed to temurin, so an explicit value is redundant. packages: read stays -- the SCA workflow declares it, and a called workflow cannot be granted a permission the caller lacks. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/sca-scan-and-guard.yml | 71 ++++++++---------------- 1 file changed, 23 insertions(+), 48 deletions(-) diff --git a/.github/workflows/sca-scan-and-guard.yml b/.github/workflows/sca-scan-and-guard.yml index 7e109f5..117c5cc 100644 --- a/.github/workflows/sca-scan-and-guard.yml +++ b/.github/workflows/sca-scan-and-guard.yml @@ -3,15 +3,7 @@ on: pull_request: branches: [master] push: - branches: - - master - # TEMPORARY: a push here runs with no PR number, which takes the workflow's - # Manual path -- registering the scan in FOSSA under the repo's default branch - # with the commit SHA as the revision. The pull_request path instead records - # branch "PR" and the branch name as the revision, which Guardian cannot match - # (it looks up refs[]= and requires a hex SHA). Remove once the - # scan has landed. - - cra-onboard-sca-scan + branches: [master] # Allows the scan to be re-run against trunk without waiting for a push, which # matters when a merge commit carries [skip ci] and produces no run at all. workflow_dispatch: @@ -19,6 +11,9 @@ on: permissions: contents: read id-token: write + # Required by the shared SCA workflow, which declares it. A called workflow + # cannot be granted a permission the caller lacks, so removing this fails the + # whole run at startup with zero jobs and no annotation. packages: read actions: read statuses: write @@ -30,47 +25,27 @@ jobs: uses: SolaceDev/solace-public-workflows/.github/workflows/sca-scan-and-guard.yaml@main with: setup_actions: '["setup-java"]' - # Required: the shared workflow forwards this to actions/setup-java and its own - # default is empty, which fails with "Input required and not supplied: distribution". - java_distribution: temurin secrets: FOSSA_API_KEY: ${{ secrets.FOSSA_API_KEY }} + # The reusable workflow owns the default-branch check, so a pull request run + # scans without writing and a run on trunk writes. squad is prof-services: + # this repo is in the Professional Services inventory, and "cto" would route + # its findings into the wrong collection and file Jiras in the wrong project. update_manifest: needs: sca_scan - # The manifest records what landed on the default branch, so it must never be - # written from a PR run -- the scan still runs, the write does not. - # workflow_dispatch is accepted so a [skip ci] merge can be registered after - # the fact; the default-branch check still gates the write. - if: >- - needs.sca_scan.result == 'success' - && (github.event_name == 'push' || github.event_name == 'workflow_dispatch') - && github.ref_name == github.event.repository.default_branch - runs-on: ubuntu-latest - permissions: - id-token: write - contents: read - packages: read - steps: - - name: Configure AWS credentials - uses: aws-actions/configure-aws-credentials@7474bc4690e29a8392af63c5b98e7449536d5c3a # v4 - with: - role-to-assume: ${{ secrets.MANIFEST_AWS_ROLE }} - aws-region: us-east-1 - - - name: Update solace-cloud-manifest - uses: SolaceDev/solace-public-workflows/.github/actions/cicd-helper@main - with: - rc_step: add_item_from_json_to_dynamodb_table - ddb_table_name: solace-cloud-manifest - ddb_partition_key: squad - ddb_sort_key: repository - ddb_item_to_be_added: | - { - "squad": "prof-services", - "repository": "${{ github.event.repository.name }}", - "dev": { - "sha": "${{ github.sha }}", - "version": "${{ github.ref_name }}" - } - } + if: needs.sca_scan.result == 'success' + uses: SolaceDev/solace-public-workflows/.github/workflows/update-manifest.yaml@main + with: + table_name: solace-cloud-manifest + item: | + { + "squad": "prof-services", + "repository": "${{ github.event.repository.name }}", + "dev": { + "sha": "${{ github.sha }}", + "version": "${{ github.ref_name }}" + } + } + secrets: + MANIFEST_AWS_ROLE: ${{ secrets.MANIFEST_AWS_ROLE }} From e7f5ad7d186d66781943a409fb61857b4b139625 Mon Sep 17 00:00:00 2001 From: Aman Riat Date: Wed, 16 Sep 2026 16:11:14 -0400 Subject: [PATCH 5/6] refactor(cra): move .fossa.yml under .github/workflows and pin toolchain versions The FOSSA CLI only reads .fossa.yml from the scan root, so relocating it requires passing fossa.config explicitly via additional_scan_params -- without that the CLI silently falls back to defaults and registers the scan under a different project. Toolchain versions are now pinned rather than inherited: the shared workflow still defaults to node 20, which reached end-of-life in 2026. Co-Authored-By: Claude Opus 5 --- .fossa.yml => .github/workflows/.fossa.yml | 0 .github/workflows/sca-scan-and-guard.yml | 3 +++ 2 files changed, 3 insertions(+) rename .fossa.yml => .github/workflows/.fossa.yml (100%) diff --git a/.fossa.yml b/.github/workflows/.fossa.yml similarity index 100% rename from .fossa.yml rename to .github/workflows/.fossa.yml diff --git a/.github/workflows/sca-scan-and-guard.yml b/.github/workflows/sca-scan-and-guard.yml index 117c5cc..fddca98 100644 --- a/.github/workflows/sca-scan-and-guard.yml +++ b/.github/workflows/sca-scan-and-guard.yml @@ -24,6 +24,9 @@ jobs: sca_scan: uses: SolaceDev/solace-public-workflows/.github/workflows/sca-scan-and-guard.yaml@main with: + additional_scan_params: | + fossa.config=.github/workflows/.fossa.yml + java_version: "21" setup_actions: '["setup-java"]' secrets: FOSSA_API_KEY: ${{ secrets.FOSSA_API_KEY }} From b77a22917eb20328783bd9fd539fe0a584b0e303 Mon Sep 17 00:00:00 2001 From: Aman Riat Date: Tue, 22 Sep 2026 15:53:36 -0400 Subject: [PATCH 6/6] fix(cra): move .fossa.yml out of .github/workflows GitHub Actions parses every .yml under .github/workflows as a workflow definition, so the FOSSA config was being registered as a workflow and failing on every push. It now sits in .github/ alongside workflow-config.json, which keeps it out of the repo root without Actions trying to execute it. Co-Authored-By: Claude Opus 5 --- .github/{workflows => }/.fossa.yml | 0 .github/workflows/sca-scan-and-guard.yml | 2 +- 2 files changed, 1 insertion(+), 1 deletion(-) rename .github/{workflows => }/.fossa.yml (100%) diff --git a/.github/workflows/.fossa.yml b/.github/.fossa.yml similarity index 100% rename from .github/workflows/.fossa.yml rename to .github/.fossa.yml diff --git a/.github/workflows/sca-scan-and-guard.yml b/.github/workflows/sca-scan-and-guard.yml index fddca98..c7de587 100644 --- a/.github/workflows/sca-scan-and-guard.yml +++ b/.github/workflows/sca-scan-and-guard.yml @@ -25,7 +25,7 @@ jobs: uses: SolaceDev/solace-public-workflows/.github/workflows/sca-scan-and-guard.yaml@main with: additional_scan_params: | - fossa.config=.github/workflows/.fossa.yml + fossa.config=.github/.fossa.yml java_version: "21" setup_actions: '["setup-java"]' secrets: