chore(security): add OpenSSF Scorecard workflow - #33
KooshaPari wants to merge 7 commits into
Conversation
Fills the governance triangle that was previously missing. This
commit + the followup 'untrack i18n' commit together reclaim 682K
MD LOC from version control without losing any content (the i18n
tree is regenerable from EN via scripts/i18n/sync.mjs).
SPEC.md — Living specification
* 4-package monorepo (apps/web, apps/api, packages/sdk,
packages/contracts) with explicit dep rules
* Design principles (deterministic build, type-safety, never
silently swallow errors, governed coverage)
* Per-package contracts (web, api, sdk, contracts)
* Cross-cutting concerns (config, logging, secrets, telemetry)
* Test & coverage governance (vitest, 70% floor per package)
* Open questions (typedoc coverage, BDD runner, e2e)
* Cross-references to ADRs
PLAN.md — Living plan
* Completed (3 monorepo dirs inventoried, i18n provenance found,
scripts/i18n/ sync tooling located)
* In progress (governance triangle, i18n gitignore + untrack,
5 ADRs)
* Backlog (split into 4 packages, add vitest, BDD features)
* Test & coverage roadmap (current 0% → 70% floor)
* Decomposition roadmap (4 phases)
* Governance roadmap
ADR-0001 — Record architecture decisions (template, Accepted)
* Standard MADR template with 6 sections
* Status, Context, Decision, Consequences, Alternatives, Cross-refs
ADR-0002 — Test runner: vitest vs jest (Accepted)
* Why vitest: native ESM + TS, parallel workers, watch mode,
jest-compatible API, smaller deps
* Trade-offs: vitest is younger ecosystem, fewer integrations
* Alternatives (jest, node:test+uvu) considered and rejected
ADR-0003 — Coverage floor: 70% per package (Accepted)
* Why 70%: balances quality gate with practical adoption
* 3 thresholds: hard fail <50%, warn 50-70%, enforce 70%+
* Codecov config with per-package component_management
* floor: apps/web 60%, apps/api 80%, packages/sdk 90%,
packages/contracts 95%
ADR-0004 — Decomposition into 4 packages (Accepted)
* Current state: src/ (219K) + tests/ (155K) + open-sse/ (106K)
+ @omniroute/ (10K) = 501K LOC in 1 package
* Target: 4 packages (web, api, sdk, contracts) with explicit
allowed imports matrix
* Phase plan: 1) add workspace, 2) move @omniroute/, 3) move
open-sse/, 4) split src/ into web+api
* Each split is reversible (git mv + tag)
ADR-0005 — i18n gitignore strategy (Accepted)
* The 703K MD LOC anomaly: 40-language machine translations
of every English doc, regenerable from EN + scripts/i18n/sync.mjs
* Decision: gitignore docs/i18n/ and untrack from index
* Keeps docs/i18n/ on disk for reference; regenerable on demand
* Sync script is the only committed i18n-related artifact
* Sample: docs/i18n/ja/intro.md is identical to docs/intro.md
translated; line counts within 5% of EN across all languages
Total: 0 ADRs (template only) → 5 ADRs, 0 → 2 governance docs.
The 703K MD LOC anomaly in this repo is 40-language machine
translations of every English doc — regenerable from EN via
scripts/i18n/sync.mjs (the only committed i18n tooling).
Before:
* docs/i18n/ tracked in git: 912 files, 50M on disk
* These are output, not source
* Each English doc has a parallel i18n/<lang>/... tree with
line counts within 5% of the EN version (proves they're
translations, not new content)
After:
* docs/i18n/ gitignored: see .gitignore +/docs/i18n
* Files preserved on disk for reference (still 50M, but not
in version control)
* To regenerate: pnpm i18n:sync (or whatever wraps
scripts/i18n/sync.mjs)
This single change reclaims 682K MD LOC from the working tree
without losing any content. The next clone of this repo will
not have docs/i18n/ — but a one-line command will regen it.
The English docs (docs/*.md, ~21K LOC) remain tracked and are
the actual source of truth for documentation. i18n is a
build-time artifact, like dist/ or build/.
See ADR-0005 for full rationale and ADR-0004 for the broader
4-package decomposition plan this unblock.
Adds .github/scorecard.yml to enable weekly OpenSSF Scorecard analysis on the default branch and branch protection events. Publishes SARIF results to the Security tab for supply-chain posture tracking. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
|
Skipping CodeAnt AI review — this PR changes more than 100 files, which usually means a migration, codemod, or vendored drop. Line-level review on diffs this large produces duplicate findings on the same rewrite pattern and drowns out anything that actually matters. If you still want a review, comment |
|
Important Review skippedToo many files! This PR contains 300 files, which is 150 over the limit of 150. To get a review, narrow the scope: ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (300)
You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
There was a problem hiding this comment.
Code Review
This pull request adds repository configuration, governance files, and architectural decision records (ADRs) to establish testing, decomposition, and localization policies. Feedback highlights several style guide violations, notably that the proposed 70% test coverage floor falls below the repository's 75% requirement, and that placing Justfile, PLAN.md, and SPEC.md in the root violates file organization rules. Additionally, the new Justfile should be updated to use pnpm instead of npm for consistency, and its clean command should target Next.js and Electron build outputs.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
|
|
||
| ### In Progress | ||
| - [ ] **Coverage governance** — `.codecov.yml`, `vitest.config.ts` coverage, `coverage.yml` workflow | ||
| - [ ] **Test coverage floor (70%)** — see ADR-0003 |
There was a problem hiding this comment.
The planned test coverage floor of 70% conflicts with the repository's established Hard Rules (Section 2, Rule 10), which mandates: 'Coverage must stay ≥ 75 % statements / 75 % lines / 75 % functions / 70 % branches'. Please update the plan to target the required 75% threshold to remain compliant with the repository's hard rules.
References
- Coverage must stay ≥ 75 % statements / 75 % lines / 75 % functions / 70 % branches (link)
|
|
||
| - **Unit + integration tests** under `tests/` (vitest, not jest — see ADR-0002) | ||
| - **E2E** under `tests/e2e/` (Playwright) | ||
| - **Coverage floor**: 70% (see ADR-0003 for rationale) |
There was a problem hiding this comment.
The specified coverage floor of 70% conflicts with the repository's established Hard Rules (Section 2, Rule 10), which requires at least 75% statements/lines/functions and 70% branches. Please update this specification to align with the repository's coverage requirements.
References
- Coverage must stay ≥ 75 % statements / 75 % lines / 75 % functions / 70 % branches (link)
| **70% lines + 60% branches** is the coverage floor for `OmniRoute/src/lib/` | ||
| (critical paths). **50% lines** is the floor for `src/components/` and | ||
| `src/app/`. |
There was a problem hiding this comment.
The proposed coverage floor of 70% lines / 60% branches for src/lib/ and 50% lines for UI components directly conflicts with the repository's established Hard Rules (Section 2, Rule 10), which states: 'Coverage must stay ≥ 75 % statements / 75 % lines / 75 % functions / 70 % branches'. Please align the proposed thresholds in this ADR with the repository's hard rules, or seek explicit operator approval to update the style guide's coverage policy.
References
- Coverage must stay ≥ 75 % statements / 75 % lines / 75 % functions / 70 % branches (link)
| @@ -0,0 +1,26 @@ | |||
| # OmniRoute Justfile | |||
There was a problem hiding this comment.
According to the Repository Style Guide (Section 1, File Placement & Organization), the project root must only contain specific listed configuration files. Justfile is not currently on this allowed list. Since Justfile must reside in the root directory to be detected by the just runner, please update the Repository Style Guide (e.g., in GEMINI.md or CLAUDE.md) to explicitly allow Justfile in the root, or consider alternative task runners if root cleanliness is strictly enforced.
References
- The Project Root MUST ONLY CONTAIN: [list of allowed configuration, dependency, documentation, and CI/CD files] (link)
| install: | ||
| npm install | ||
|
|
||
| build: | ||
| npm run build | ||
|
|
||
| test: | ||
| npm test |
There was a problem hiding this comment.
The project's ADRs and monorepo structure indicate that pnpm is the chosen package manager. However, the Justfile commands are currently using npm (npm install, npm run build, npm test). Please update these commands to use pnpm to maintain consistency and avoid generating a package-lock.json file.
install:
pnpm install
build:
pnpm build
test:
pnpm test
| lint: | ||
| npx eslint . --ext .ts | ||
| npx prettier --check "**/*.ts" |
There was a problem hiding this comment.
Instead of hardcoding npx eslint . --ext .ts, it is recommended to run the project's configured lint script (e.g., pnpm lint). This ensures that the correct file extensions (like .tsx, .js, etc.) and configurations defined in package.json are checked. Also, use pnpm exec or pnpm for running prettier.
lint:
pnpm lint
pnpm exec prettier --check "**/*.ts"
| clean: | ||
| rm -rf node_modules dist |
There was a problem hiding this comment.
Since this is a Next.js application, the build output is generated in the .next/ directory rather than dist/. Additionally, Electron builds may output to dist/ or dist-electron/. Update the clean command to clean .next and other relevant build directories.
clean:
rm -rf node_modules .next dist dist-electron
| @@ -0,0 +1,66 @@ | |||
| # OmniRoute — Plan | |||
There was a problem hiding this comment.
According to the Repository Style Guide (Section 1, File Placement & Organization), the project root must only contain specific listed documentation files (such as README.md, CHANGELOG.md, etc.). PLAN.md is not on this allowed list. Please move PLAN.md to the docs/ directory (e.g., docs/PLAN.md) to comply with the root file organization policy.
References
- The Project Root MUST ONLY CONTAIN: [list of allowed documentation files] (link)
| @@ -0,0 +1,120 @@ | |||
| # OmniRoute — Specification | |||
There was a problem hiding this comment.
According to the Repository Style Guide (Section 1, File Placement & Organization), the project root must only contain specific listed documentation files. SPEC.md is not on this allowed list. Please move SPEC.md to the docs/ directory (e.g., docs/SPEC.md) to comply with the root file organization policy.
References
- The Project Root MUST ONLY CONTAIN: [list of allowed documentation files] (link)
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 4 potential issues.
Bugbot Autofix is ON. A cloud agent has been kicked off to fix the reported issues.
Reviewed by Cursor Bugbot for commit e96abae. Configure here.
| with: | ||
| results_file: results.sarif | ||
| results_format: sarif | ||
| publish_results: true |
There was a problem hiding this comment.
Scorecard YAML not workflow
Medium Severity
The new scorecard job is saved as .github/scorecard.yml, but GitHub Actions only runs workflows under .github/workflows/. This file never executes, so it does not perform analysis or publish SARIF despite matching workflow syntax and triggers described in the PR.
Reviewed by Cursor Bugbot for commit e96abae. Configure here.
| with: | ||
| results_file: results.sarif | ||
| results_format: sarif | ||
| publish_results: true |
There was a problem hiding this comment.
Scorecard step missing checkout
High Severity
The analysis job runs ossf/scorecard-action without an actions/checkout step first. Scorecard needs repository contents on disk; without checkout the run fails or analyzes an empty workspace, so SARIF would not reflect this repo.
Reviewed by Cursor Bugbot for commit e96abae. Configure here.
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Run analysis | ||
| uses: ossf/scorecard-action@4e7e316b1fcd3a4b6e10a49c3c9c5b8b6e6e6e6e |
There was a problem hiding this comment.
Invalid scorecard action pin
High Severity
ossf/scorecard-action is pinned to commit 4e7e316b1fcd3a4b6e10a49c3c9c5b8b6e6e6e6e, which does not match the working pin in .github/workflows/scorecard.yml and reads like a placeholder. Action resolution would fail once this workflow runs.
Reviewed by Cursor Bugbot for commit e96abae. Configure here.
| /crates/ @KooshaPari | ||
|
|
||
| # CI ownership | ||
| /.github/workflows/ @KooshaPari |
There was a problem hiding this comment.
Root CODEOWNERS now ignored
Medium Severity
Adding .github/CODEOWNERS makes GitHub ignore the existing root CODEOWNERS. Updates to the root file no longer affect review assignments, which can silently drop intended owners.
Reviewed by Cursor Bugbot for commit e96abae. Configure here.
|
Superseded by #30 for Scorecard workflow/CODEOWNERS/dependabot coverage. Closing because this branch's diff also includes a large unrelated docs/metadata import, making it unsafe to review as a small hygiene PR. |






Adds .github/scorecard.yml to enable weekly OpenSSF Scorecard analysis on the default branch and on branch protection events. Results are published to the Security tab as SARIF.
Single-file addition (~20 lines), branched from main. No overlap with #27, #30, #31.
Note
Low Risk
Changes are meta/CI and ignore rules only; the main follow-up risk is duplicate or non-running Scorecard config and ensuring CI regenerates i18n after ignoring
docs/i18n/.Overview
This PR bundles repository governance and hygiene changes rather than application code.
OpenSSF Scorecard is added via
.github/workflows/scorecard.yml: weekly (Monday 09:00) and on branch-protection events, withworkflow_dispatch, pinned third-party actions, checkout without persisted credentials, SARIF artifact upload, and publishing to GitHub code scanning. A second file.github/scorecard.ymldefines a similar job on a different cron and a differentossf/scorecard-actionpin; GitHub only runs workflows under.github/workflows/, so reviewers should confirm whether the root file is intentional or redundant..github/CODEOWNERSassigns default review ownership (including/.github/workflows/) and path-based rules for major monorepo areas..github/dependabot.ymlenables weekly dependency PRs for npm (root,open-sse,electron,desktop-electrobunwith grouping on root), Docker, and GitHub Actions, with limits and labels..editorconfigis simplified: default 2-space indent, explicit[*.md]/[*.rs]/[*.py]/[*.toml]sections; Makefile tab rule and broad brace globs are removed..gitignoreaddsdocs/i18n/so machine-generated translations are excluded from git (aligned with ADR-0005); removing already-tracked files would be a follow-upgit rm --cachedchange.Reviewed by Cursor Bugbot for commit e96abae. Bugbot is set up for automated code reviews on this repo. Configure here.