DX-20927 | Back-merge master into development - #53
Conversation
…est files and ContentstackClient
refactor: add deepcode ignore comments for hardcoded credentials in t…
Brings back-merge branch up to date with development so master can be back-merged cleanly (DX-20927). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
🔒 Security Scan Results
⏱️ SLA Breach Summary
✅ BUILD PASSED - All security checks passed |
The repo root has no project or solution file, so Snyk could not detect target files. Restore both projects first and scan with --all-projects. Refs DX-20927 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
🔒 Security Scan Results
⏱️ SLA Breach Summary
✅ BUILD PASSED - All security checks passed |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The SCA job unnecessarily exposes a pull-request write token to mutable third-party actions.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Back-merges production updates into development, aligning security ownership, SCA scanning, and false-positive suppressions.
Changes:
- Updates CODEOWNERS security coverage.
- Expands Snyk scanning to all projects and adds policy enforcement.
- Suppresses trusted XML and test-credential findings.
| File | Description |
|---|---|
CODEOWNERS |
Updates reviewer ownership rules. |
.github/workflows/sca-scan.yml |
Expands SCA scanning and policy checks. |
Scripts/generate_test_report.py |
Suppresses trusted XML warnings. |
contentstack.model.generator/CMA/ContentstackClient.cs |
Suppresses a credential false positive. |
contentstack.model.generator.tests/StackResponseModelTests.cs |
Marks fixture credentials as non-secrets. |
contentstack.model.generator.tests/OAuthModelTests.cs |
Marks fixture secrets as non-production. |
contentstack.model.generator.tests/OAuthIntegrationTests.cs |
Suppresses a fixture-secret warning. |
contentstack.model.generator.tests/ModelGeneratorTests.cs |
Adds test credential suppressions. |
contentstack.model.generator.tests/ContentstackOptionsTests.cs |
Adds test credential suppressions. |
contentstack.model.generator.tests/ContentstackClientTests.cs |
Adds API-key fixture suppressions. |
contentstack.model.generator.tests/ConfigTests.cs |
Suppresses fixture credential warnings. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
With --all-projects the Snyk dotnet action did not produce snyk.json, so the sca-policy step failed even though the scan passed. Refs DX-20927 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
🔒 Security Scan Results
⏱️ SLA Breach Summary
✅ BUILD PASSED - All security checks passed |
Addresses Copilot review: only the sca-policy step needs pull-requests: write, so the Snyk scan now runs in a read-only job and hands snyk.json to a dependent security-sca job. All action refs are pinned to commit SHAs. The policy job keeps the security-sca name used by the required check. Refs DX-20927 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
🔒 Security Scan Results
⏱️ SLA Breach Summary
✅ BUILD PASSED - All security checks passed |

Back-merge of the production branch into
developmentto resolve branch divergence (mostly the CODEOWNERS update and workflow changes that landed on the production branch only).Uses a dedicated
back-merge/DX-20927branch (production branch +developmentmerged in) so the PR is up to date withdevelopmentwithout modifying the production branch.Jira: DX-20927
🤖 Generated with Claude Code