Repository navigation
Expand file tree
/
Copy pathsecurity-insights.yml
More file actions
268 lines (266 loc) · 12.2 KB
/
Copy pathsecurity-insights.yml
File metadata and controls
268 lines (266 loc) · 12.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
header:
schema-version: 2.2.0
last-updated: '2026-10-02'
last-reviewed: '2026-09-26'
url: https://raw.githubusercontent.com/finos/architecture-as-code/main/security-insights.yml
comment: |
Architecture as Code (CALM) spans three GitHub repositories: this monorepo,
finos/calm-schema and finos/calm-governance. The other entries under
project.repositories are subprojects/packages within this monorepo,
compiled into independent releases (npm packages, Docker images, a VS Code
extension, etc).
project:
name: Architecture as Code (CALM)
homepage: https://calm.finos.org
roadmap: https://roadmapper.rocketstack.co/view/finos/architecture-as-code/ffffff/24292f
administrators:
- name: rocketstack-matt
primary: true
- name: jpgough-ms
primary: false
- name: markscott-ms
primary: false
documentation:
quickstart-guide: https://calm.finos.org/tutorials/
detailed-guide: https://calm.finos.org/
design: https://calm.finos.org/core-concepts/
code-of-conduct: https://www.finos.org/code-of-conduct
release-process: https://github.com/finos/architecture-as-code/blob/main/CONTRIBUTING.md#-why-we-use-semantic-release
support-policy: https://github.com/finos/architecture-as-code/blob/main/SUPPORT.md
signature-verification: https://github.com/finos/architecture-as-code/blob/main/SECURITY.md#verifying-release-integrity-and-authenticity
repositories:
- name: calm-schema
url: https://github.com/finos/calm-schema
comment: |
Separate repository. CALM JSON Schema, published to npm as
@finos/calm-schema with SLSA provenance. Status: Incubating, actively
maintained.
- name: calm-governance
url: https://github.com/finos/calm-governance
comment: |
Separate repository. Project-wide governance, maintainer roster and
contribution guidelines. Documentation only; no releases.
- name: calm
url: https://github.com/finos/architecture-as-code/tree/main/calm
comment: |
CALM JSON Meta Schema specification, the core architecture modelling
language this project is built around. Status: Active.
- name: cli
url: https://github.com/finos/architecture-as-code/tree/main/cli
comment: |
@finos/calm-cli, the TypeScript CLI for validating, generating and
visualizing CALM architectures. Published to npm. Status: Active.
- name: shared
url: https://github.com/finos/architecture-as-code/tree/main/shared
comment: |
@finos/calm-shared, TypeScript utilities shared across the CLI, the
VSCode extension and other CALM tooling. Bundled into the CLI; not
published separately.
Status: Active.
- name: calm-models
url: https://github.com/finos/architecture-as-code/tree/main/calm-models
comment: |
@finos/calm-models, TypeScript data models generated from the CALM
schema and consumed across the TypeScript packages. The TypeScript
models are bundled into the CLI; the Java models are published to
Maven Central.
Status: Active.
- name: calm-widgets
url: https://github.com/finos/architecture-as-code/tree/main/calm-widgets
comment: |
@finos/calm-widgets, React visualization components and Handlebars
template widgets used to render CALM architectures. Bundled into the
CLI; not published separately.
Status: Active.
- name: calm-ai
url: https://github.com/finos/architecture-as-code/tree/main/calm-ai
comment: |
AI agent tools and prompts for working with CALM. Prompt/tooling
assets only (no build), managed separately from the CLI for easier
maintenance and broader reuse. Status: Active.
- name: calm-hub
url: https://github.com/finos/architecture-as-code/tree/main/calm-hub
comment: |
CALM Hub, a Java/Quarkus REST API backend for storing and serving
CALM architectures (MongoDB or NitriteDB storage). Published as a
Docker image. Status: Active.
- name: calm-hub-ui
url: https://github.com/finos/architecture-as-code/tree/main/calm-hub-ui
comment: |
React frontend for CALM Hub. Status: Active.
- name: calm-server
url: https://github.com/finos/architecture-as-code/tree/main/calm-server
comment: |
@finos/calm-server, a TypeScript CALM server package. Published to
npm. Status: Active.
- name: calm-plugins/vscode
url: https://github.com/finos/architecture-as-code/tree/main/calm-plugins/vscode
comment: |
VS Code extension for authoring and validating CALM architectures.
Published to the VS Code Marketplace as finos.calm-vscode-plugin.
Status: Active.
- name: calm-studio
url: https://github.com/finos/architecture-as-code/tree/main/calm-studio
comment: |
SvelteKit visual CALM editor; itself a nested npm-workspace monorepo
(calm-core, calmscript, extensions, github-action, mcp, diagram web
component, vscode-extension, studio app). Status: Experimental. Its npm and
desktop releases are outside the release controls in SECURITY.md until promoted.
- name: calm-guard
url: https://github.com/finos/architecture-as-code/tree/main/calm-guard
comment: |
CALMGuard, a Next.js continuous-compliance platform for validating
architectures against CALM controls, plus its Docusaurus docs site.
Status: Experimental.
- name: docs
url: https://github.com/finos/architecture-as-code/tree/main/docs
comment: |
Docusaurus documentation site published at calm.finos.org.
Status: Active.
- name: calm-lab
url: https://github.com/finos/architecture-as-code/tree/main/calm-lab
comment: |
CALM Learning Lab, an in-browser terminal, editor and live diagram
that run the CALM engine. A static site deployed from main to
lab.calm.finos.org. Status: Active.
vulnerability-reporting:
reports-accepted: true
bug-bounty-available: false
contact:
name: Architecture as Code Maintainers
primary: true
policy: https://github.com/finos/architecture-as-code/blob/main/SECURITY.md
comment: |
GitHub private vulnerability reporting is enabled on this repository;
use the "Report a vulnerability" action under the Security tab.
repository:
url: https://github.com/finos/architecture-as-code
status: active
accepts-change-request: true
accepts-automated-change-request: true
core-team:
- name: rocketstack-matt
primary: true
- name: jpgough-ms
primary: false
- name: markscott-ms
primary: false
documentation:
contributing-guide: https://github.com/finos/architecture-as-code/blob/main/CONTRIBUTING.md
dependency-management-policy: https://github.com/finos/architecture-as-code/blob/main/SECURITY.md#dependency-and-code-scanning-policy
governance: https://github.com/finos/calm-governance/blob/main/GOVERNANCE.md
review-policy: https://github.com/finos/architecture-as-code/blob/main/MAINTAINERS_GUIDELINES.md
security-policy: https://github.com/finos/architecture-as-code/blob/main/SECURITY.md
license:
url: https://github.com/finos/architecture-as-code/blob/main/LICENSE
expression: Apache-2.0
release:
automated-pipeline: true
distribution-points:
- uri: https://github.com/finos/architecture-as-code/releases
comment: GitHub Releases page for tagged releases across the monorepo's packages.
- uri: https://www.npmjs.com/package/@finos/calm-cli
comment: npm package for the CALM CLI.
- uri: https://www.npmjs.com/package/@finos/calm-server
comment: npm package for CALM Server.
- uri: https://central.sonatype.com/artifact/org.finos.calm/calm-models
comment: Maven Central artifact for the CALM Java models, GPG-signed.
- uri: https://hub.docker.com/r/finos/calm-hub
comment: Docker Hub image for CALM Hub.
- uri: https://marketplace.visualstudio.com/items?itemName=finos.calm-vscode-plugin
comment: VS Code Marketplace listing for the CALM VSCode extension.
attestations:
- name: npm provenance (SLSA) for @finos/calm-cli
location: https://www.npmjs.com/package/@finos/calm-cli
predicate-uri: https://slsa.dev/provenance/v1
comment: |
Published with `npm publish --provenance` from automated-release.yml. The package page shows
the provenance for each version and links to its Sigstore transparency log entry. Verify with
`npm audit signatures`; see SECURITY.md, "Verifying Release Integrity and Authenticity".
- name: npm provenance (SLSA) for @finos/calm-server
location: https://www.npmjs.com/package/@finos/calm-server
predicate-uri: https://slsa.dev/provenance/v1
comment: |
Published with `npm publish --provenance` from automated-release-calm-server.yml. The package
page shows the provenance for each version and links to its Sigstore transparency log entry.
- name: Docker provenance and SBOM
location: https://hub.docker.com/r/finos/calm-hub
predicate-uri: https://slsa.dev/provenance/v1
comment: |
calm-hub images are built by docker/build-push-action with
provenance and SBOM attestations attached to the image index. The SBOM of a
native image lists only its base image.
security:
assessments:
self:
name: Threat model and attack surface analysis
date: '2026-10-03'
evidence: https://github.com/finos/architecture-as-code/blob/main/THREAT_MODEL.md
comment: |
Maintainer-authored threat model and attack surface analysis covering
the CLI, CALM Server, CALM Hub, the VS Code extension, CALM Lab and
the build and release pipeline. Reviewed at least yearly and whenever a
component gains a new interface, trust boundary or distribution channel.
tools:
- name: GitHub Secret Scanning
type: secret-scanning
comment: |
GitHub secret scanning with push protection, enabled in the repository
security settings. The setting is visible only to repository admins, so
it is declared here for unprivileged assessments (OSPS-BR-07.01).
rulesets:
- default
integration:
adhoc: true
ci: true
release: false
- name: CodeQL
type: SAST
comment: .github/workflows/codeql.yml (advanced setup); runs on every pull request, including pull requests from forks, and weekly against main.
rulesets:
- default
integration:
adhoc: false
ci: true
release: false
- name: Semgrep
type: SAST
comment: Runs on every pull request via .github/workflows/semgrep-ci.yml; the semgrep/ci check is required on main.
rulesets:
- Semgrep AppSec Platform policy for finos/architecture-as-code
integration:
adhoc: false
ci: true
release: false
- name: OSV Scanner
type: SCA
comment: |
.github/workflows/osv-scanner.yml on every pull request, on push to main and twice each
working day. Scans the root npm lockfile, the calm-hub and calm-models Maven projects and
the CALM Studio Cargo lockfile; fails on CVSS >= 5; suppressions with justification in
osv-scanner.toml. The CLI and calm-server release workflows publish only if the scan of
the commit being released passed.
rulesets:
- OSV database, CVSS >= 5
integration:
adhoc: false
ci: true
release: true
- name: Dependency Review
type: SCA
comment: actions/dependency-review-action on every pull request; blocks known-vulnerable and known-malicious dependencies.
rulesets:
- fail-on-severity moderate
integration:
adhoc: false
ci: true
release: false
- name: Dependabot
type: SCA
comment: Security updates and alerts for npm, Maven, Cargo and GitHub Actions.
rulesets:
- GitHub Advisory Database
integration:
adhoc: false
ci: true
release: false