Skip to content

Add support for PackageGuard and use it in the pipeline - #658

Closed
dennisdoomen wants to merge 3 commits into
Fallout-build:developfrom
dennisdoomen:claude/packageguard-generated-support-e39906
Closed

Add support for PackageGuard and use it in the pipeline#658
dennisdoomen wants to merge 3 commits into
Fallout-build:developfrom
dennisdoomen:claude/packageguard-generated-support-e39906

Conversation

@dennisdoomen

@dennisdoomen dennisdoomen commented Aug 25, 2026

Copy link
Copy Markdown
Collaborator

Adds a Fallout CLI tool wrapper for PackageGuard's analyze command, based on AnalyzeCommandSettings.cs, and wires it into the build pipeline as a compliance/SBOM scan.

Tool wrapper

  • src/Fallout.Common/Tools/PackageGuard/PackageGuard.json — spec covering all 18 analyze settings, plus NpmPackageManager and SbomFormat enumerations for the properties restricted to a fixed set of values.
  • PackageGuard.Generated.cs — regenerated via ./build.ps1 GenerateTools.
  • Added a row to the supported-tools table in docs/website/03-common/08-cli-tools.md.
  • Added TestPackageGuard to tests/Fallout.Common.Specs/SettingsSpecs.cs.

Build pipeline

  • New PackageGuard target (build/Build.PackageGuard.cs) generates a CycloneDX SBOM and an HTML + SARIF risk report.
  • Only runs on main, develop, release/*, or support/* — via GitRepository.IsOn*Branch() (including a new IsOnSupportBranch() extension), or, for the tag-triggered release workflow where HEAD is detached, because that workflow's own validate-ref job already proved the tag is reachable from a production branch.
  • New security-scan workflow (generated from a third [GitHubActions] attribute) runs the scan on every push to those branches and uploads the SARIF report to GitHub code scanning via github/codeql-action/upload-sarif.
  • publish-packages-release.yml now runs PackageGuard alongside Test+Pack and attaches both the SBOM and the HTML risk report to the GitHub Release as assets.

Purely additive — no breaking changes.

🤖 Generated with Claude Code

Adds a Fallout CLI tool wrapper for PackageGuard's `analyze` command,
based on its AnalyzeCommandSettings.cs
(https://github.com/dennisdoomen/packageguard/blob/main/Src/PackageGuard/AnalyzeCommandSettings.cs).

- Add src/Fallout.Common/Tools/PackageGuard/PackageGuard.json, covering
  all 18 analyze settings plus NpmPackageManager and SbomFormat
  enumerations for the properties restricted to a fixed set of values.
- Regenerate PackageGuard.Generated.cs via ./build.ps1 GenerateTools.
- Add a row to the supported-tools table in
  docs/website/03-common/08-cli-tools.md.
- Add a TestPackageGuard smoke test to
  tests/Fallout.Common.Specs/SettingsSpecs.cs.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@dennisdoomen dennisdoomen added enhancement New feature or request target/vCurrent Targets the current version labels Aug 25, 2026
dennisdoomen and others added 2 commits August 25, 2026 14:32
Adds a PackageGuard target (build/Build.PackageGuard.cs) that scans the
solution's dependencies, generates a CycloneDX SBOM, and writes an
HTML + SARIF risk report.

- Only runs on main, develop, release/*, or support/* — either directly
  (GitRepository.IsOn*Branch(), including a new IsOnSupportBranch()
  extension) or, for the tag-triggered release workflow where HEAD is
  detached, because that workflow's own validate-ref job already proved
  the tag is reachable from a production branch.
- New dedicated "security-scan" workflow (generated via a third
  [GitHubActions] attribute in Build.CI.GitHubActions.cs) runs the scan
  on every push to those branches and uploads the SARIF risk report to
  GitHub code scanning via github/codeql-action/upload-sarif, using the
  IConfigureGitHubActions custom-step-injection hook.
- publish-packages-release.yml now runs the PackageGuard target
  alongside Test + Pack and attaches the generated SBOM to the GitHub
  Release as an asset.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Alongside the SBOM, publish-github-releases now uploads
output/packageguard/risk-report.html as a release asset when present —
the human-readable counterpart of the SARIF report already sent to
GitHub code scanning (security-scan.yml).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@dennisdoomen dennisdoomen changed the title Add generated tool wrapper for PackageGuard Add support for PackageGuard and use it in the pipeline Aug 25, 2026
@dennisdoomen

Copy link
Copy Markdown
Collaborator Author

Superseded by #659 — moved the branch to the upstream repo (Fallout-build/Fallout) instead of the fork, same commits/content.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request target/vCurrent Targets the current version

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant