Skip to content

DX-20927 | Back-merge master into development - #53

Merged
reeshika-h merged 9 commits into
developmentfrom
back-merge/DX-20927
Sep 29, 2026
Merged

reeshika-h merged 9 commits into
developmentfrom
back-merge/DX-20927

Conversation

@reeshika-h

Copy link
Copy Markdown
Contributor

Back-merge of the production branch into development to resolve branch divergence (mostly the CODEOWNERS update and workflow changes that landed on the production branch only).

Uses a dedicated back-merge/DX-20927 branch (production branch + development merged in) so the PR is up to date with development without modifying the production branch.

Jira: DX-20927

🤖 Generated with Claude Code

reeshika-h and others added 6 commits July 22, 2026 15:03
refactor: add deepcode ignore comments for hardcoded credentials in t…
Brings back-merge branch up to date with development so master can be back-merged cleanly (DX-20927).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@snyk-io

snyk-io Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@github-actions

Copy link
Copy Markdown

🔒 Security Scan Results

ℹ️ Note: Only vulnerabilities with available fixes (upgrades or patches) are counted toward thresholds.

Check Type Count (with fixes) Without fixes Threshold Result
🔴 Critical Severity 0 0 10 ✅ Passed
🟠 High Severity 0 0 25 ✅ Passed
🟡 Medium Severity 0 0 0 ✅ Passed
🔵 Low Severity 0 0 0 ✅ Passed

⏱️ SLA Breach Summary

✅ No SLA breaches detected. All vulnerabilities are within acceptable time thresholds.

Severity Breaches (with fixes) Breaches (no fixes) SLA Threshold (with/no fixes) Status
🔴 Critical 0 0 15 / 30 days ✅ Passed
🟠 High 0 0 30 / 120 days ✅ Passed
🟡 Medium 0 0 90 / 365 days ✅ Passed
🔵 Low 0 0 180 / 365 days ✅ Passed

✅ BUILD PASSED - All security checks passed

The repo root has no project or solution file, so Snyk could not detect
target files. Restore both projects first and scan with --all-projects.

Refs DX-20927

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings September 29, 2026 06:42
@github-actions

Copy link
Copy Markdown

🔒 Security Scan Results

ℹ️ Note: Only vulnerabilities with available fixes (upgrades or patches) are counted toward thresholds.

Check Type Count (with fixes) Without fixes Threshold Result
🔴 Critical Severity 0 0 10 ✅ Passed
🟠 High Severity 0 0 25 ✅ Passed
🟡 Medium Severity 0 0 0 ✅ Passed
🔵 Low Severity 0 0 0 ✅ Passed

⏱️ SLA Breach Summary

✅ No SLA breaches detected. All vulnerabilities are within acceptable time thresholds.

Severity Breaches (with fixes) Breaches (no fixes) SLA Threshold (with/no fixes) Status
🔴 Critical 0 0 15 / 30 days ✅ Passed
🟠 High 0 0 30 / 120 days ✅ Passed
🟡 Medium 0 0 90 / 365 days ✅ Passed
🔵 Low 0 0 180 / 365 days ✅ Passed

✅ BUILD PASSED - All security checks passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The SCA job unnecessarily exposes a pull-request write token to mutable third-party actions.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Back-merges production updates into development, aligning security ownership, SCA scanning, and false-positive suppressions.

Changes:

  • Updates CODEOWNERS security coverage.
  • Expands Snyk scanning to all projects and adds policy enforcement.
  • Suppresses trusted XML and test-credential findings.
File Description
CODEOWNERS Updates reviewer ownership rules.
.github/​workflows/​sca-scan.yml Expands SCA scanning and policy checks.
Scripts/​generate_test_report.py Suppresses trusted XML warnings.
contentstack.model.generator/​CMA/​ContentstackClient.cs Suppresses a credential false positive.
contentstack.model.generator.tests/​StackResponseModelTests.cs Marks fixture credentials as non-secrets.
contentstack.model.generator.tests/​OAuthModelTests.cs Marks fixture secrets as non-production.
contentstack.model.generator.tests/​OAuthIntegrationTests.cs Suppresses a fixture-secret warning.
contentstack.model.generator.tests/​ModelGeneratorTests.cs Adds test credential suppressions.
contentstack.model.generator.tests/​ContentstackOptionsTests.cs Adds test credential suppressions.
contentstack.model.generator.tests/​ContentstackClientTests.cs Adds API-key fixture suppressions.
contentstack.model.generator.tests/​ConfigTests.cs Suppresses fixture credential warnings.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/sca-scan.yml Outdated
With --all-projects the Snyk dotnet action did not produce snyk.json, so
the sca-policy step failed even though the scan passed.

Refs DX-20927

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 29, 2026 06:45
@github-actions

Copy link
Copy Markdown

🔒 Security Scan Results

ℹ️ Note: Only vulnerabilities with available fixes (upgrades or patches) are counted toward thresholds.

Check Type Count (with fixes) Without fixes Threshold Result
🔴 Critical Severity 0 0 10 ✅ Passed
🟠 High Severity 0 0 25 ✅ Passed
🟡 Medium Severity 0 0 500 ✅ Passed
🔵 Low Severity 0 0 1000 ✅ Passed

⏱️ SLA Breach Summary

✅ No SLA breaches detected. All vulnerabilities are within acceptable time thresholds.

Severity Breaches (with fixes) Breaches (no fixes) SLA Threshold (with/no fixes) Status
🔴 Critical 0 0 15 / 30 days ✅ Passed
🟠 High 0 0 30 / 120 days ✅ Passed
🟡 Medium 0 0 90 / 365 days ✅ Passed
🔵 Low 0 0 180 / 365 days ✅ Passed

✅ BUILD PASSED - All security checks passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The new write-capable workflow action uses a mutable branch reference instead of an immutable commit SHA.

Review effort: Balanced
Findings: 1 High severity

Open (1)

Addresses Copilot review: only the sca-policy step needs pull-requests: write,
so the Snyk scan now runs in a read-only job and hands snyk.json to a
dependent security-sca job. All action refs are pinned to commit SHAs.
The policy job keeps the security-sca name used by the required check.

Refs DX-20927

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 29, 2026 06:53
@github-actions

Copy link
Copy Markdown

🔒 Security Scan Results

ℹ️ Note: Only vulnerabilities with available fixes (upgrades or patches) are counted toward thresholds.

Check Type Count (with fixes) Without fixes Threshold Result
🔴 Critical Severity 0 0 10 ✅ Passed
🟠 High Severity 0 0 25 ✅ Passed
🟡 Medium Severity 0 0 500 ✅ Passed
🔵 Low Severity 0 0 1000 ✅ Passed

⏱️ SLA Breach Summary

✅ No SLA breaches detected. All vulnerabilities are within acceptable time thresholds.

Severity Breaches (with fixes) Breaches (no fixes) SLA Threshold (with/no fixes) Status
🔴 Critical 0 0 15 / 30 days ✅ Passed
🟠 High 0 0 30 / 120 days ✅ Passed
🟡 Medium 0 0 90 / 365 days ✅ Passed
🔵 Low 0 0 180 / 365 days ✅ Passed

✅ BUILD PASSED - All security checks passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The changes are internally consistent and introduce no unresolved correctness or security issues.

Review effort: Balanced
Findings: None

Resolved since last review (1)

@reeshika-h
reeshika-h merged commit 65b2ef1 into development Sep 29, 2026
12 checks passed
@reeshika-h
reeshika-h deleted the back-merge/DX-20927 branch September 29, 2026 07:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants