Skip to content

V2-BE-044 — Make API Security, Build, and Artifact Checks Non-Skippable #395

Description

@dDevAhmed

Objective

Restore a trustworthy API merge gate after August merges landed with failed or skipped jobs.

Scope

  • Require lint, typecheck, unit/integration tests, security scans, container build, migration validation, and generated-artifact drift.
  • Remove unconditional skips and permissive continuation from required jobs.
  • Pin actions and third-party tooling; apply least-privilege workflow permissions.
  • Add reviewed-head approval enforcement for auth, database, indexer, and protocol-sensitive changes.

Acceptance Criteria

  • Each required job is reproducible locally or in a documented container.
  • Deliberate failures in every gate block validation.
  • No required result is neutralized by continue-on-error.
  • Fork workflow authorization is documented correctly.
  • Changed head SHA requires fresh approval for sensitive work.

Dependencies

None.


🏷 Labels

  • backend
  • ci
  • security
  • complexity-medium
  • Stellar Wave

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions