Skip to content

feat(docs): rework policy UX — dedicated policy-in-force page, fix landing buttons #36

feat(docs): rework policy UX — dedicated policy-in-force page, fix landing buttons

feat(docs): rework policy UX — dedicated policy-in-force page, fix landing buttons #36

Workflow file for this run

name: self-audit
# zava-agent-config eats its own dog food: every push and PR runs apm install,
# apm audit --ci, and apm pack to prove the marketplace builds reproducibly
# and the package complies with org policy.
#
# This is the lib equivalent of the reusable apm-audit.yml that consumers call.
# If this fails, downstream consumers cannot trust the v* tag we publish.
#
# Note (v2.0.0+): this repo is a marketplace, not a primitives bag.
# - `apm install` is a no-op (zero deps) but still runs to catch CLI regressions.
# - `apm pack --offline` validates that the marketplace block compiles to a
# well-formed .claude-plugin/marketplace.json and every plugin source resolves.
# - We commit .claude-plugin/marketplace.json so downstream tooling and
# reviewers can diff it without invoking the CLI.
#
# v5.0.1+: CLI install via microsoft/apm-action@v1 (setup-only mode).
# We still call `apm pack --offline` directly because apm-action's pack mode
# emits a single bundle, not a marketplace.json — the publisher-side drift
# check is unique to this repo. Also smoke-tests per-plugin pack so a tag
# push (release.yml) is guaranteed to succeed.
on:
push:
branches: [main]
pull_request:
branches: [main]
permissions:
contents: read
pull-requests: write
jobs:
self-audit:
name: Self-audit (install + audit + pack)
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Setup APM CLI
uses: microsoft/apm-action@v1
with:
setup-only: 'true'
- name: Verify APM CLI
run: apm --version
- name: APM install (no-op for marketplace repo, catches CLI regressions)
run: |
echo "::group::apm install"
apm install
echo "::endgroup::"
# Publisher exemption: this repo PUBLISHES secure-baseline, which the org
# policy (DevExpGbb/.github/apm-policy.yml v2.0.0) lists in
# `required_packages`. Pinning ourselves would be a circular dependency,
# so we audit supply-chain drift but skip org-policy enforcement here.
# Consumers still get full `apm audit --ci --policy org` via apm-audit.yml.
- name: APM audit (CI mode — supply chain only, publisher exempt from org policy)
run: |
echo "::group::apm audit --ci --no-policy"
apm audit --ci --no-policy -f sarif -o apm-audit.sarif
echo "::endgroup::"
- name: APM pack (validate marketplace builds + drift check)
run: |
echo "::group::apm pack --offline"
apm pack --offline
echo "::endgroup::"
if git diff --exit-code -- .claude-plugin/marketplace.json; then
echo "Committed marketplace.json matches build output."
else
echo "::error::Drift between committed .claude-plugin/marketplace.json and apm pack output. Run 'apm pack --offline' locally and commit the result."
git diff -- .claude-plugin/marketplace.json
exit 1
fi
- name: Per-plugin pack smoke test (validates release.yml inputs)
run: |
echo "::group::per-plugin apm pack"
mkdir -p build/plugins
for kit_dir in plugins/*/; do
kit_name=$(basename "$kit_dir")
echo "::group::pack $kit_name"
( cd "$kit_dir" && apm pack --offline --archive -o "$GITHUB_WORKSPACE/build/plugins" )
echo "::endgroup::"
done
echo "::endgroup::"
echo "Built tarballs:"
ls -la build/plugins/
- name: Upload audit report as artifact
if: always()
uses: actions/upload-artifact@v4
with:
name: apm-self-audit-sarif
path: apm-audit.sarif
if-no-files-found: warn
- name: Step summary
if: always()
run: |
{
echo "## APM self-audit"
echo ""
echo "- **Lib**: \`zava-agent-config\` (marketplace)"
echo "- **Commit**: \`${GITHUB_SHA::7}\`"
echo "- **Marketplace**: \`.claude-plugin/marketplace.json\` (6 plugins)"
echo "- **Audit report**: \`apm-audit.sarif\` (artifact)"
echo "- **Per-plugin pack**: smoke-tested (validates release.yml will succeed)"
} >> "$GITHUB_STEP_SUMMARY"