Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
41 commits
Select commit Hold shift + click to select a range
087cd4f
SD-3304: Update TD scenarios and validations
pedrocarvalhodcsa Sep 3, 2026
0bf0545
SD-3304: Update missing details
pedrocarvalhodcsa Sep 3, 2026
54eb05e
SD-3304: Fix tests and bugs
pedrocarvalhodcsa Sep 3, 2026
11212c4
SD-3304: Rename suites from td and si only to td and si
pedrocarvalhodcsa Sep 4, 2026
4ff49ba
SD-3304: Fix validation and test cases
pedrocarvalhodcsa Sep 4, 2026
e6c0b76
SD-3304: Update md file to reflect changes
pedrocarvalhodcsa Sep 4, 2026
d7d30da
Merge pull request #556 from dcsaorg/SD-3304_update-td
pedrocarvalhodcsa Sep 4, 2026
4bcd66e
SD-3349: Update AN scenarios and validations
pedrocarvalhodcsa Sep 4, 2026
0117d87
SD-3349: Fix issues
pedrocarvalhodcsa Sep 4, 2026
f2f8ae1
SD-3349: Update gitignore
pedrocarvalhodcsa Sep 4, 2026
bf533c3
SD-3349: Add specifications import script from confluence
pedrocarvalhodcsa Sep 4, 2026
66beb9b
SD-3349: Fix AN tests
pedrocarvalhodcsa Sep 4, 2026
01af6e9
SD-3349: Recover deleted files
pedrocarvalhodcsa Sep 4, 2026
687678a
SD-3349: Remove useless file
pedrocarvalhodcsa Sep 4, 2026
5cd7947
Merge pull request #557 from dcsaorg/SD-3349_refactor-an
pedrocarvalhodcsa Sep 4, 2026
dc46954
docs: auto-sync Confluence documentation
Sep 4, 2026
c64710c
SD-3349: Refactor scenarios and validations for endorsment chain
pedrocarvalhodcsa Sep 4, 2026
654019a
SD-3349: Fix issue
pedrocarvalhodcsa Sep 4, 2026
3e8fac4
SD-3349: Fix test
pedrocarvalhodcsa Sep 4, 2026
4ab5bbe
SD-3349: Fix issues
pedrocarvalhodcsa Sep 4, 2026
8e5882b
Merge pull request #558 from dcsaorg/SD-3327_ec-refactor
pedrocarvalhodcsa Sep 4, 2026
fd40914
Sd 3274 SI Update Conformance (#559)
palatsangeetha Sep 6, 2026
7293f97
Merge branch 'test' into dev
pedrocarvalhodcsa Sep 7, 2026
bbf4d9b
SD-3401: Update TD scenarios and validations
pedrocarvalhodcsa Sep 9, 2026
d47493c
SD-3401: Update ebl UC6 instructions
pedrocarvalhodcsa Sep 9, 2026
735bf63
SD-3401: Adjust TNT validations
pedrocarvalhodcsa Sep 9, 2026
ca549a8
SD-3401: Fix all in one sandbox runs
pedrocarvalhodcsa Sep 9, 2026
e8bbb80
Merge pull request #562 from dcsaorg/SD-3401_adjust-tnt-scenarios
pedrocarvalhodcsa Sep 9, 2026
7b64263
Merge pull request #561 from dcsaorg/SD-3401_update-td-scenarios
pedrocarvalhodcsa Sep 9, 2026
7e9ef3b
docs: auto-sync Confluence documentation
Sep 14, 2026
bfeeb7f
SD-3134 Add initial ZAP scan profiles
gj0dcsa Sep 15, 2026
6cef5ad
SD-3134 Add initial ZAP scan profiles
gj0dcsa Sep 15, 2026
9b5e254
SD-3134 Add clickjacking response headers
gj0dcsa Sep 15, 2026
52a3ab8
SD-3134 Add clickjacking response headers
gj0dcsa Sep 15, 2026
e833671
SD-3134 Refine CSP scan handling
gj0dcsa Sep 15, 2026
b2eb83d
SD-3134 Refine CSP scan handling
gj0dcsa Sep 15, 2026
1d0bf38
SD-3438: Update tnt schema (#568)
pedrocarvalhodcsa Sep 17, 2026
a618170
docs: auto-sync Confluence documentation
Sep 21, 2026
49a590b
no-issue: fix documentation sync script
pedrocarvalhodcsa Sep 21, 2026
d238051
no-issue: remove unwanted booking validation
pedrocarvalhodcsa Sep 21, 2026
7977f8a
no-issue: fix CSP
pedrocarvalhodcsa Sep 22, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
166 changes: 166 additions & 0 deletions .github/workflows/confluence-sync.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,166 @@
name: Confluence Sync

on:
schedule:
# Runs every Monday at 02:00 UTC
- cron: '0 2 * * 1'

workflow_dispatch:
# Allow manual trigger from GitHub UI

# Optional: trigger on push to main branch if confluence-config.json changes
push:
paths:
- 'scripts/src/confluence/confluence-config.json'
- 'scripts/src/confluence/sync-confluence.py'
- 'scripts/src/confluence/requirements.txt'
- '.github/workflows/confluence-sync.yml'
branches:
- main

jobs:
sync:
runs-on: ubuntu-latest
name: Sync Confluence to Git

steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
fetch-depth: 0

- name: Set up Python
uses: actions/setup-python@v4
with:
python-version: '3.11'
cache: 'pip'

- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -r scripts/src/confluence/requirements.txt

- name: Run sync tests
run: |
python scripts/src/confluence/sync-confluence.py --self-test
python -m unittest -v scripts/src/confluence/test_sync_confluence.py

- name: Configure git
run: |
git config --local user.email "bot@dcsa.org"
git config --local user.name "DCSA Bot"

- name: Run Confluence Sync
env:
CONFLUENCE_BASE_URL: ${{ secrets.CONFLUENCE_BASE_URL }}
CONFLUENCE_USERNAME: ${{ secrets.CONFLUENCE_USERNAME }}
CONFLUENCE_API_TOKEN: ${{ secrets.CONFLUENCE_API_TOKEN }}
CONFLUENCE_SPACE_KEY: SD
run: |
python scripts/src/confluence/sync-confluence.py

- name: Check for changes
id: git-check
run: |
if git diff --quiet; then
echo "has_changes=false" >> $GITHUB_OUTPUT
else
echo "has_changes=true" >> $GITHUB_OUTPUT
fi

- name: Commit and push changes
if: steps.git-check.outputs.has_changes == 'true'
run: |
git add specifications/confluence-sync/
git commit -m "docs: auto-sync Confluence documentation

- Synced specifications from Confluence space SD
- Timestamp: $(date -u +'%Y-%m-%dT%H:%M:%SZ')
- Workflow: Confluence Sync"
git push
Comment thread
pedrocarvalhodcsa marked this conversation as resolved.

- name: Create Pull Request
if: steps.git-check.outputs.has_changes == 'true'
uses: peter-evans/create-pull-request@v5
with:
commit-message: 'docs: auto-sync Confluence documentation'
title: 'docs: Auto-sync Confluence documentation'
body: |
## Automated Confluence Sync

This PR contains automatically synced documentation from Confluence.

**Sync Details:**
- Source: Confluence Space `SD` (Standards Development)
- Destination: `specifications/confluence-sync/`
- Timestamp: ${{ github.event.head_commit.timestamp }}
- Trigger: ${{ github.event_name }}

### What to check:
- [ ] Files have expected content
- [ ] No sensitive data exposed
- [ ] Markdown formatting looks correct
- [ ] Links are preserved

### Merge Instructions:
If everything looks good, merge this PR to keep specifications current.
branch: confluence-sync-${{ github.run_number }}
delete-branch: true
labels: |
documentation
automated
confluence-sync

- name: Workflow Status
if: always()
run: |
echo "## Confluence Sync Status"
echo "- Scheduled: Every Monday at 02:00 UTC"
echo "- Last Run: $(date -u +'%Y-%m-%d %H:%M:%S UTC')"
echo "- Changes Detected: ${{ steps.git-check.outputs.has_changes }}"
echo "- Configuration: scripts/src/confluence/confluence-config.json"

verify:
runs-on: ubuntu-latest
name: Verify Sync Output
needs: sync
if: always()

steps:
- name: Checkout repository
uses: actions/checkout@v4

- name: Check sync directory exists
run: |
if [ -d "specifications/confluence-sync" ]; then
echo "✓ Sync directory exists"
ls -la specifications/confluence-sync/
else
echo "⚠ Sync directory not found (may be first run)"
fi

- name: Validate markdown files
run: |
if find specifications/confluence-sync -type f -name '*.md' | grep -q .; then
count=$(find specifications/confluence-sync -type f -name '*.md' | wc -l)
echo "✓ Found ${count} markdown files"
while IFS= read -r file; do
if [ -s "$file" ]; then
echo " ✓ ${file} - $(wc -l < "$file") lines"
fi
done < <(find specifications/confluence-sync -type f -name '*.md' | sort)
else
echo "ℹ No markdown files found (check config or Confluence connectivity)"
fi

- name: Summary
run: |
echo "## Sync Verification Complete"
echo "- Documentation location: specifications/confluence-sync/"
echo "- Config file: scripts/src/confluence/confluence-config.json"
echo "- Next sync: Monday 02:00 UTC"
echo ""
echo "To manually trigger sync:"
echo " 1. Go to: Actions → Confluence Sync"
echo " 2. Click: Run workflow"

71 changes: 71 additions & 0 deletions .github/workflows/zap-authenticated-scan.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,71 @@
name: OWASP ZAP Authenticated Scan

on:
workflow_dispatch:
inputs:
target_environment:
description: Non-production GitHub Environment that provides the Conformance scan configuration
required: true
type: choice
options:
- conformance-dev

permissions:
contents: read

jobs:
authenticated-scan:
name: Authenticated scan (${{ inputs.target_environment }})
runs-on: ubuntu-latest
environment: ${{ inputs.target_environment }}
env:
APP_URL: ${{ vars.APP_URL }}
API_URL: ${{ vars.API_URL }}
CONFORMANCE_USER_EMAIL: ${{ secrets.CONFORMANCE_USER_EMAIL }}
CONFORMANCE_USER_PASSWORD: ${{ secrets.CONFORMANCE_USER_PASSWORD }}
steps:
- name: Check out the scan plan
uses: actions/checkout@v6.0.2

- name: Create a fallback report
shell: bash
run: printf '%s\n' '<!doctype html><title>ZAP authenticated scan did not produce a report</title><p>Review this workflow run for failure details.</p>' > zap-authenticated-report-fallback.html

- name: Require authenticated scan configuration
shell: bash
run: |
if [ -z "$APP_URL" ] || [ -z "$API_URL" ] || [ -z "$CONFORMANCE_USER_EMAIL" ] || [ -z "$CONFORMANCE_USER_PASSWORD" ]; then
echo "APP_URL, API_URL, CONFORMANCE_USER_EMAIL, and CONFORMANCE_USER_PASSWORD must be configured for this GitHub Environment."
exit 1
fi

if [ "$APP_URL" != "https://dev.conformance-development-1.dcsa.org" ] || [ "$API_URL" != "https://dev-webui.conformance-development-1.dcsa.org" ]; then
echo "The initial authenticated scan is restricted to the approved Conformance Dev origins."
exit 1
fi

- name: Run authenticated passive scan
uses: zaproxy/action-af@v0.3.0
with:
plan: .github/workflows/zap/zap-authenticated-plan.yaml
docker_env_vars: |
APP_URL
API_URL
CONFORMANCE_USER_EMAIL
CONFORMANCE_USER_PASSWORD

- name: Select authenticated HTML report
if: always()
shell: bash
run: |
if [ ! -f zap-authenticated-report.html ]; then
mv zap-authenticated-report-fallback.html zap-authenticated-report.html
fi

- name: Upload authenticated HTML report
if: always()
uses: actions/upload-artifact@v4
with:
name: zap-authenticated-report-${{ inputs.target_environment }}
path: zap-authenticated-report.html
if-no-files-found: error
73 changes: 73 additions & 0 deletions .github/workflows/zap-baseline-scan.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,73 @@
name: OWASP ZAP Baseline Scan

on:
workflow_dispatch:
inputs:
target_environment:
description: GitHub Environment that provides the Conformance application URL
required: true
type: choice
options:
- conformance-dev
- conformance-dt
- conformance-test

permissions:
contents: read

jobs:
baseline-scan:
name: Baseline scan (${{ inputs.target_environment }})
runs-on: ubuntu-latest
environment: ${{ inputs.target_environment }}
env:
APP_URL: ${{ vars.APP_URL }}
steps:
- name: Check out the scan plan
uses: actions/checkout@v6.0.2

- name: Create a fallback report
shell: bash
run: printf '%s\n' '<!doctype html><title>ZAP baseline scan did not produce a report</title><p>Review this workflow run for failure details.</p>' > zap-baseline-report-fallback.html

- name: Require the approved target URL
shell: bash
run: |
if [ -z "$APP_URL" ]; then
echo "APP_URL must be configured as a GitHub Environment variable."
exit 1
fi

case "${{ inputs.target_environment }}" in
conformance-dev) expected_url="https://dev.conformance-development-1.dcsa.org" ;;
conformance-dt) expected_url="https://dt.conformance-dt-1.dcsa.org" ;;
conformance-test) expected_url="https://test.conformance-test-1.dcsa.org" ;;
*) echo "Unsupported target environment."; exit 1 ;;
esac

if [ "$APP_URL" != "$expected_url" ]; then
echo "APP_URL does not match the approved URL for ${{ inputs.target_environment }}."
exit 1
fi

- name: Run passive baseline scan
uses: zaproxy/action-af@v0.3.0
with:
plan: .github/workflows/zap/zap-baseline-plan.yaml
docker_env_vars: APP_URL

- name: Select baseline HTML report
if: always()
shell: bash
run: |
if [ ! -f zap-baseline-report.html ]; then
mv zap-baseline-report-fallback.html zap-baseline-report.html
fi

- name: Upload baseline HTML report
if: always()
uses: actions/upload-artifact@v4
with:
name: zap-baseline-report-${{ inputs.target_environment }}
path: zap-baseline-report.html
if-no-files-found: error
Loading
Loading