--- id: 06-codeql-and-audit-signatures epic: 2026-05-14-ci-security-and-supply-chain title: CodeQL workflow + pnpm audit signatures type: technical-story status: done feature: tooling depends-on: [] blocks: [08-reviewer-prompt-update] --- ## Goal Add two baseline GitHub-native gates: (1) a `pnpm audit signatures --audit-level=high` step in `ci.yml`'s validate job, and (2) a `.github/workflows/codeql.yml` workflow running javascript-typescript static analysis on push/PR/weekly schedule. ## Why `pnpm audit signatures` catches tampered package signatures before they reach production — a post-install script from a compromised maintainer account would fail this check. CodeQL's javascript-typescript analysis catches common vulnerability patterns (XSS, injection, prototype pollution) that are invisible to dependency-scanning tools. Both are zero-cost on public repos and the GitHub Free plan; CodeQL's template includes a clear no-op on plans that don't support it. ## Done when - `ci.yml`'s `validate` job includes a `pnpm audit signatures --audit-level=high` step. The step fails the job on `high` or `critical` severity signature failures. - `.github/workflows/codeql.yml` exists; triggers: `push: branches: [main]`, `pull_request`, and `schedule: - cron: "0 2 * * 3"` (Wednesday 02:00 UTC, staggered from the trace-revalidation cron); language: `javascript-typescript`; uses default queries. Includes a comment noting that CodeQL on private repos requires GitHub Advanced Security (consumer-toggleable per PRD constraint). - `pnpm typecheck && pnpm lint && pnpm test && pnpm conformance && pnpm fallow:audit && pnpm coverage:diff` all pass (no executable code change; CI config only). ## In scope - `.github/workflows/ci.yml` — one new `pnpm audit signatures` step in `validate` job. - `.github/workflows/codeql.yml` — new workflow file. ## Out of scope - Configuring GitHub branch protection to require CodeQL as a status check — consumer-facing instruction deferred to Story 09's guide. - OSSF Scorecard — explicitly out of PRD scope. - StepSecurity Harden Runner — explicitly out of PRD scope. ## Tasks - [x] Add `pnpm audit signatures --audit-level=high` as a step in `ci.yml`'s `validate` job; one commit, all gates pass. - [x] Create `.github/workflows/codeql.yml` (language: `javascript-typescript`; triggers: push to main, pull_request, weekly schedule Wednesday 02:00 UTC; default queries; consumer note about GitHub Advanced Security requirement for private repos); one commit, all gates pass.