Skip to content

ci: enforce security and release gates - #6

Merged
mertushka merged 2 commits into
mainfrom
security/codeql-release-gates
Jun 11, 2026
Merged

mertushka merged 2 commits into
mainfrom
security/codeql-release-gates

Conversation

@mertushka

@mertushka mertushka commented Jun 11, 2026 •

Copy link
Copy Markdown
Member

Purpose

Enforce the repository's security and release policy without changing the public WebRTC implementation.

Changes

  • add independent CodeQL analysis for JavaScript/TypeScript and a manually built C++ addon database
  • add a stable CI required aggregate check for branch protection
  • block npm publication until the matching version-tag Conformance workflow completes successfully
  • enable and document private vulnerability reporting and update durable agent/maintainer guidance
  • protect main with pull requests, resolved conversations, admin enforcement, and the three stable required checks
  • add local integration assertions so the required automation cannot be removed silently

Behavior impact

No runtime, API, SDP, ICE, data-channel, native ABI, or package-content behavior changes. Release runs may wait up to 100 minutes for strict tag conformance before npm publication.

Native and WPT impact

CodeQL now compiles the real Node-API addon on Ubuntu using the existing native setup action. WPT selection and classifications are unchanged. Full selected WPT is not run by this PR; workflow changes trigger the existing CI matrix, Chrome E2E, and WPT smoke jobs.

Browser impact

No browser-facing behavior changes. Existing Chrome E2E remains part of the aggregate CI gate when applicable.

Validation

  • npm run check
  • npm run native:check
  • npm run types:check
  • npm run pack:check
  • actionlint 1.7.12 with verified release checksum
  • live GitHub API lookup of the successful v0.1.5 Conformance run
  • aggregate CI gate success and failure path checks
  • full PR CI matrix, Chrome E2E, WPT smoke, package isolation, and both CodeQL analyses
  • private vulnerability reporting and main branch protection verified enabled
  • no open CodeQL alerts

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@mertushka
mertushka marked this pull request as ready for review June 11, 2026 16:26
@mertushka
mertushka merged commit fd84bf3 into main Jun 11, 2026
19 checks passed
@mertushka
mertushka deleted the security/codeql-release-gates branch June 11, 2026 16:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants