Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
42 commits
Select commit Hold shift + click to select a range
9bb5534
OSPS-Baseline (#5)
SeeWhatsOn Mar 31, 2026
a901a35
Osps baseline (#6)
SeeWhatsOn Mar 31, 2026
e926aca
Change OSPS action to use v1.0.0
SeeWhatsOn Mar 31, 2026
36a58bf
Update OSPS action version in workflow
SeeWhatsOn Mar 31, 2026
051ceac
Update OSPS action version in workflow
SeeWhatsOn Mar 31, 2026
31b96c3
Update OSPS action to use new repository
SeeWhatsOn Mar 31, 2026
bdf0111
Update OSPS action version in workflow
SeeWhatsOn Mar 31, 2026
cf4a410
Update OSPS action to use 'fixes' tag
SeeWhatsOn Apr 1, 2026
74ce6d9
Update OSPS action version in workflow
SeeWhatsOn Apr 1, 2026
bebf0f4
Update OSPS action version in workflow
SeeWhatsOn Apr 1, 2026
559da98
Update OSPS action version in workflow
SeeWhatsOn Apr 1, 2026
6989c0a
Update OSPS.yml
SeeWhatsOn Apr 1, 2026
718e5b8
Update OSPS action version in workflow
SeeWhatsOn Apr 1, 2026
b8c13b2
Update OSPS action to use sarif-fix version
SeeWhatsOn Apr 1, 2026
41f85ba
Update OSPS workflow for version changes and formatting
SeeWhatsOn Apr 2, 2026
3cc0587
Update checkout action version to v6
SeeWhatsOn Apr 2, 2026
64c9ef9
Update OSPS workflow to use latest action versions
SeeWhatsOn Apr 2, 2026
a5095b0
Update OSPS action version to 1.2.0
SeeWhatsOn Apr 2, 2026
ad93a57
Update OSPS action version to 1.3.2
SeeWhatsOn Apr 2, 2026
126a101
Downgrade OSPS action version from v1.3.2 to v1.3.1
SeeWhatsOn Apr 2, 2026
9a7be5b
Downgrade OSPS action version to v1.3.0
SeeWhatsOn Apr 2, 2026
f0ba67a
Update OSPS.yml
SeeWhatsOn Apr 2, 2026
c18adc4
Downgrade OSPS action version to v1.1.0
SeeWhatsOn Apr 2, 2026
c30cf47
Update OSPS action to use seewhatson version
SeeWhatsOn Apr 2, 2026
aeb6376
Enable building OSPS scanner from source
SeeWhatsOn Apr 2, 2026
0308c3d
Update OSPS scanner source reference to v0.17.0
SeeWhatsOn Apr 2, 2026
0407b0b
Update scanner-source-ref to version 0.20.0
SeeWhatsOn Apr 2, 2026
69cdca9
Update scanner-source-ref to v0.22.1
SeeWhatsOn Apr 2, 2026
0133385
Update scanner-source-ref to version 0.22.0
SeeWhatsOn Apr 2, 2026
75e43c9
Update scanner-source-ref to v0.21.0
SeeWhatsOn Apr 2, 2026
19e2b55
Update scanner-source-ref to v0.21.1
SeeWhatsOn Apr 2, 2026
f4496e0
Update scanner-source-ref to version 0.22.1
SeeWhatsOn Apr 2, 2026
7358b5c
Update OSPS workflow catalog and upload settings
SeeWhatsOn Apr 5, 2026
77d50a0
Update OSPS action to use new repository version
SeeWhatsOn Apr 5, 2026
2243c75
Comment out scanner-build-from-source in OSPS.yml
SeeWhatsOn Apr 5, 2026
40d98f8
Change upload-sarif value to string in OSPS.yml
SeeWhatsOn Apr 5, 2026
38c8436
Update catalog name in OSPS workflow
SeeWhatsOn Apr 5, 2026
6457778
Update catalog name in OSPS workflow
SeeWhatsOn Apr 5, 2026
7008937
Update GitHub Actions to use latest versions
SeeWhatsOn Apr 5, 2026
26ebc6c
Refactor OSPS workflow for clarity and consistency
SeeWhatsOn Apr 5, 2026
5dfe8f3
Enhance README and add new GitHub workflows
SeeWhatsOn Apr 8, 2026
f69a084
Update OSPS workflow to use specific action versions and modify catal…
SeeWhatsOn Apr 22, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 35 additions & 0 deletions .github/workflows/OSPS.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
name: OSPS Security Assessment

on:
schedule:
- cron: "0 9 * * 1" # Weekly on Mondays at 9 AM UTC
workflow_dispatch: # Allow manual triggering

jobs:
osps-assessment:
runs-on: ubuntu-latest

permissions:
contents: read
security-events: write # Required for SARIF upload

steps:
- name: Checkout repository
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0

- name: Open Source Project Security Baseline Scanner
uses: revanite-io/osps-baseline-action@3bf988fa8e4b59568dcfac138a1854df87c15aff # v1.3.2
with:
owner: ${{ github.repository_owner }}
repo: ${{ github.event.repository.name }}
token: ${{ secrets.PVTR_GITHUB_TOKEN }}
catalog: "osps-baseline"
upload-sarif: "true"

- name: Upload Assessment Results
if: always()
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
with:
name: osps-assessment-results-${{ github.run_number }}
path: evaluation_results/
retention-days: 30
23 changes: 23 additions & 0 deletions .github/workflows/dependency-review.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
# Flags new vulnerable dependencies introduced on the PR diff (GitHub Advisory DB).
# See https://github.com/actions/dependency-review-action
name: Dependency Review

on:
pull_request:
branches: [main]
paths:
- "**/package.json"
- "**/package-lock.json"
- "pnpm-lock.yaml"
- "yarn.lock"
- ".github/workflows/dependency-review.yml"

permissions:
contents: read

jobs:
dependency-review:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/dependency-review-action@v4
28 changes: 22 additions & 6 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,17 +2,33 @@
<img height="300" src="./packages/web/images/logo_bg_white_2x.png" alt="FDC3 Sail Icon">
</p>

<h1 align="center">FDC3 Sail</h3>
<h1 align="center">FDC3 Sail</h1>

<h3 align="center">Develop easier. &nbsp; Build faster. &nbsp; Integrate quicker.</h3>

<br />

<p align="center">
<a href="https://finosfoundation.atlassian.net/wiki/display/FINOS/Incubating"><img src="https://cdn.jsdelivr.net/gh/finos/contrib-toolbox@master/images/badge-incubating.svg"></a>
<a href="https://bestpractices.coreinfrastructure.org/projects/6303"><img src="https://bestpractices.coreinfrastructure.org/projects/6303/badge"></a>
<a href="https://github.com/finos/fdc3-sail/blob/main/LICENSE"><img src="https://img.shields.io/github/license/finos/fdc3-sail"></a>
</p>
---

<div align="center">

[![FINOS Incubating](https://cdn.jsdelivr.net/gh/finos/contrib-toolbox@master/images/badge-incubating.svg)](https://finosfoundation.atlassian.net/wiki/display/FINOS/Incubating)
[![License](https://img.shields.io/github/license/finos/fdc3-sail)](https://github.com/finos/fdc3-sail/blob/main/LICENSE)
![GitHub Release](https://img.shields.io/github/v/release/finos/fdc3-sail)
[![GitHub Repo stars](https://img.shields.io/github/stars/finos/fdc3-sail?style=social)](https://github.com/finos/fdc3-sail)

<br />

[![CI](https://github.com/finos/FDC3-Sail/actions/workflows/ci.yml/badge.svg?branch=main)](https://github.com/finos/FDC3-Sail/actions/workflows/ci.yml)
[![OpenSSF Best Practices](https://bestpractices.coreinfrastructure.org/projects/12272/badge)](https://bestpractices.coreinfrastructure.org/projects/12272)
[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/finos/FDC3-Sail/badge)](https://scorecard.dev/viewer/?uri=github.com/finos/FDC3-Sail)
[![Semgrep](https://github.com/finos/FDC3-Sail/actions/workflows/semgrep.yml/badge.svg?branch=main)](https://github.com/finos/FDC3-Sail/actions/workflows/semgrep.yml)
[![CodeQL](https://github.com/finos/FDC3-Sail/actions/workflows/ql.yml/badge.svg?branch=main)](https://github.com/finos/FDC3-Sail/actions/workflows/ql.yml)
[![Node.js CVE scanning](https://github.com/finos/FDC3-Sail/actions/workflows/cve-scanning.yml/badge.svg?branch=main)](https://github.com/finos/FDC3-Sail/actions/workflows/cve-scanning.yml)

</div>

---

## What is FDC3 Sail?

Expand Down
Loading