Repository navigation
feat(docs): rework policy UX — dedicated policy-in-force page, fix landing buttons #36
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: self-audit | |
| # zava-agent-config eats its own dog food: every push and PR runs apm install, | |
| # apm audit --ci, and apm pack to prove the marketplace builds reproducibly | |
| # and the package complies with org policy. | |
| # | |
| # This is the lib equivalent of the reusable apm-audit.yml that consumers call. | |
| # If this fails, downstream consumers cannot trust the v* tag we publish. | |
| # | |
| # Note (v2.0.0+): this repo is a marketplace, not a primitives bag. | |
| # - `apm install` is a no-op (zero deps) but still runs to catch CLI regressions. | |
| # - `apm pack --offline` validates that the marketplace block compiles to a | |
| # well-formed .claude-plugin/marketplace.json and every plugin source resolves. | |
| # - We commit .claude-plugin/marketplace.json so downstream tooling and | |
| # reviewers can diff it without invoking the CLI. | |
| # | |
| # v5.0.1+: CLI install via microsoft/apm-action@v1 (setup-only mode). | |
| # We still call `apm pack --offline` directly because apm-action's pack mode | |
| # emits a single bundle, not a marketplace.json — the publisher-side drift | |
| # check is unique to this repo. Also smoke-tests per-plugin pack so a tag | |
| # push (release.yml) is guaranteed to succeed. | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| permissions: | |
| contents: read | |
| pull-requests: write | |
| jobs: | |
| self-audit: | |
| name: Self-audit (install + audit + pack) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| - name: Setup APM CLI | |
| uses: microsoft/apm-action@v1 | |
| with: | |
| setup-only: 'true' | |
| - name: Verify APM CLI | |
| run: apm --version | |
| - name: APM install (no-op for marketplace repo, catches CLI regressions) | |
| run: | | |
| echo "::group::apm install" | |
| apm install | |
| echo "::endgroup::" | |
| # Publisher exemption: this repo PUBLISHES secure-baseline, which the org | |
| # policy (DevExpGbb/.github/apm-policy.yml v2.0.0) lists in | |
| # `required_packages`. Pinning ourselves would be a circular dependency, | |
| # so we audit supply-chain drift but skip org-policy enforcement here. | |
| # Consumers still get full `apm audit --ci --policy org` via apm-audit.yml. | |
| - name: APM audit (CI mode — supply chain only, publisher exempt from org policy) | |
| run: | | |
| echo "::group::apm audit --ci --no-policy" | |
| apm audit --ci --no-policy -f sarif -o apm-audit.sarif | |
| echo "::endgroup::" | |
| - name: APM pack (validate marketplace builds + drift check) | |
| run: | | |
| echo "::group::apm pack --offline" | |
| apm pack --offline | |
| echo "::endgroup::" | |
| if git diff --exit-code -- .claude-plugin/marketplace.json; then | |
| echo "Committed marketplace.json matches build output." | |
| else | |
| echo "::error::Drift between committed .claude-plugin/marketplace.json and apm pack output. Run 'apm pack --offline' locally and commit the result." | |
| git diff -- .claude-plugin/marketplace.json | |
| exit 1 | |
| fi | |
| - name: Per-plugin pack smoke test (validates release.yml inputs) | |
| run: | | |
| echo "::group::per-plugin apm pack" | |
| mkdir -p build/plugins | |
| for kit_dir in plugins/*/; do | |
| kit_name=$(basename "$kit_dir") | |
| echo "::group::pack $kit_name" | |
| ( cd "$kit_dir" && apm pack --offline --archive -o "$GITHUB_WORKSPACE/build/plugins" ) | |
| echo "::endgroup::" | |
| done | |
| echo "::endgroup::" | |
| echo "Built tarballs:" | |
| ls -la build/plugins/ | |
| - name: Upload audit report as artifact | |
| if: always() | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: apm-self-audit-sarif | |
| path: apm-audit.sarif | |
| if-no-files-found: warn | |
| - name: Step summary | |
| if: always() | |
| run: | | |
| { | |
| echo "## APM self-audit" | |
| echo "" | |
| echo "- **Lib**: \`zava-agent-config\` (marketplace)" | |
| echo "- **Commit**: \`${GITHUB_SHA::7}\`" | |
| echo "- **Marketplace**: \`.claude-plugin/marketplace.json\` (6 plugins)" | |
| echo "- **Audit report**: \`apm-audit.sarif\` (artifact)" | |
| echo "- **Per-plugin pack**: smoke-tested (validates release.yml will succeed)" | |
| } >> "$GITHUB_STEP_SUMMARY" |