Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 28 additions & 0 deletions docs/_data/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,31 @@
- date: '2026-09-08'
updates:
pipeline_connector:
version: 0.8.0
breaking_changes:
- text: |-
Added support for new [Pipeline Policies](/pipeline-policies). The old build and source code policies under `.signpath/policies/*` are only loaded if explicitly referenced as Pipeline Policies and are modified to match the new policy definition scheme.
issues: [SIGN-8632, SIGN-8843, SIGN-8847, SIGN-8846, SIGN-8819]
bug_fixes:
- text: |-
TeamCity: The entire `/refs/heads/*` branch identifier is again used for Git branches instead of the shortened name (e.g. `main`).
issues: [SIGN-8826]
application:
version: 1.220.0
new_features:
- text: |-
[Pipeline Policies](/pipeline-policies) allow central policy controls for restricting source code and build settings of your CI/CD pipeline .
issues: []
jenkins_plugin:
version: 5.0.0
breaking_changes:
- text: |-
The Jenkins Plugin now requires a Pipeline Connector instance to run. Contact [our support team](https://signpath.io/support) for details.
issues: [SIGN-8637]
new_features:
- text: |-
SCM [Pipeline Policies](/pipeline-policies) are now supported for Jenkins builds.
issues: [SIGN-8637]
- date: '2026-08-25'
updates:
self_hosted_installations:
Expand Down
113 changes: 91 additions & 22 deletions docs/_data/editions.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,10 +7,10 @@
projects-hint: quota-hint
users: 'up to 2'
users-hint: quota-hint
signign_requests_release: 'up to 60'
signign_requests_release-hint: quota-hint
signign_requests_test: 'up to 300'
signign_requests_test-hint: quota-hint
signing_requests_release: 'up to 60'
signing_requests_release-hint: quota-hint
signing_requests_test: 'up to 300'
signing_requests_test-hint: quota-hint
ci_pipelines: '1'
file_based_signing:
authenticode: true
Expand Down Expand Up @@ -55,7 +55,7 @@
origin_verification: false
origin_policies: false
build_validation: false
extended_policies: false
pipeline_policies: false
user_management:
sso: false
scim: false
Expand All @@ -81,10 +81,10 @@
projects-hint: 'You may use several artifact configurations per project, e.g. for different components. Click "buy now" and add projects to adjust quota.'
users: 'up to 15'
users-hint: quota-hint
signign_requests_release: 'up to 500'
signign_requests_release-hint: quota-hint
signign_requests_test: 'up to 2500'
signign_requests_test-hint: quota-hint
signing_requests_release: 'up to 500'
signing_requests_release-hint: quota-hint
signing_requests_test: 'up to 2500'
signing_requests_test-hint: quota-hint
ci_pipelines: '1 per project'
file_based_signing:
authenticode: true
Expand Down Expand Up @@ -129,7 +129,7 @@
origin_verification: false
origin_policies: false
build_validation: false
extended_policies: false
pipeline_policies: false
user_management:
sso: false
scim: false
Expand All @@ -146,14 +146,14 @@
gpg_key_management: false
link_type: 'pricing_page'

- name: Advanced Code Signing
title: Advanced Code Signing
- name: Semantic Code Signing
title: Semantic Code Signing
quotas:
certificates: 'unlimited'
projects: 'unlimited'
users: 'unlimited'
signign_requests_release: 'unlimited'
signign_requests_test: 'unlimited'
signing_requests_release: 'unlimited'
signing_requests_test: 'unlimited'
ci_pipelines: 'unlimited'
file_based_signing:
authenticode: true
Expand Down Expand Up @@ -194,10 +194,79 @@
disable_malware_scanning: true
pipeline_integrity:
trusted_build_systems: optional
origin_verification: optional
origin_verification: false
origin_policies: false
build_validation: false
pipeline_policies: false
user_management:
sso: true
scim: true
groups: true
admin_delegation: true
other:
malware_detection: true
hsm_key_storage: true
available_on_premises: true
cert_enrollment: true
support: 'priority'
support-hint: 'Priority support using email, phone and screen sharing'
code_signing_consulting: 'available'
no_display:
gpg_key_management: true
link_type: 'sales_email'

- name: Pipeline Integrity
title: Pipeline Integrity
quotas:
certificates: 'unlimited'
projects: 'unlimited'
users: 'unlimited'
signing_requests_release: 'unlimited'
signing_requests_test: 'unlimited'
ci_pipelines: 'unlimited'
file_based_signing:
authenticode: false
powershell: false
windows_scripting_host: false
clickonce: false
device_drivers: false
office_add_ins: false
opc: false
nuget: false
android: false
java: false
apk: false
rpm: false
deb: false
office_macros: false
xml: false
jsf: false
docker: false
sbom: false
dsse: false
smime: false
cms: false
gpg: false
raw: false
hash_based_signing: none
artifact_configuration:
deep_signing: true
multiple_configurations_per_project: true
metadata_constraints: true
user_defined_parameters: true
policy_enforcement:
manual_approval: true
quorum_approval: true
signing_policies_per_project: 'unlimited'
policies_for_certs: true
resubmit: true
disable_malware_scanning: true
pipeline_integrity:
trusted_build_systems: true
origin_verification: true
origin_policies: true
build_validation: true
extended_policies: true
pipeline_policies: true
user_management:
sso: true
scim: true
Expand All @@ -221,8 +290,8 @@
certificates: 'unlimited'
projects: 'n/a'
users: 'unlimited'
signign_requests_release: 'unlimited'
signign_requests_test: 'unlimited'
signing_requests_release: 'unlimited'
signing_requests_test: 'unlimited'
ci_pipelines: 'unlimited'
file_based_signing: none
hash_based_signing:
Expand Down Expand Up @@ -251,7 +320,7 @@
origin_verification-hint: Not supported by crypto providers
origin_policies: true
build_validation: true
extended_policies: true
pipeline_policies: false
user_management:
sso: true
scim: true
Expand All @@ -277,8 +346,8 @@
projects: 'unlimited'
projects-hint: 'OSS teams must apply for each project individually.'
users: 'unlimited'
signign_requests_release: 'fair use'
signign_requests_test: 'fair use'
signing_requests_release: 'fair use'
signing_requests_test: 'fair use'
ci_pipelines: '1 per project'
file_based_signing:
authenticode: true
Expand Down Expand Up @@ -323,7 +392,7 @@
origin_policies: 'required'
build_validation: 'required'
disable_malware_scanning: false
extended_policies: 'predefined'
pipeline_policies: true
user_management:
sso: false
scim: false
Expand Down
8 changes: 4 additions & 4 deletions docs/_data/featuregroups.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,11 +17,11 @@
title: 'Signing requests'
hint: 'Signing requests (think software packages or releases) per year. Each signing request may contain multiple files.'
href: '/product/editions-explained#signing-requests'
- name: signign_requests_release
- name: signing_requests_release
title: 'release-signing'
hint: 'Signing requests using your EV certificate'
class: f sub
- name: signign_requests_test
- name: signing_requests_test
title: 'test-signing'
hint: 'Signing request using a test certificate that must be installed on target machines. Used for testing the signing configuration, signing internal builds, release candidates etc.'
class: f sub
Expand Down Expand Up @@ -177,8 +177,8 @@
title: 'Build validation'
hint: 'Automatically checks build configurations for security weaknesses.'
class: f sub
- name: extended_policies
title: 'SCM and CI policy control'
- name: pipeline_policies
title: 'Pipeline Policies'
hint: 'Define specific SCM and CI/CD policy requirements, e.g. branch protection or build agents'
class: f sub

Expand Down
3 changes: 3 additions & 0 deletions docs/_data/menus/documentation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -65,6 +65,9 @@
- text: Origin Verification
path: origin-verification

- text: Pipeline Policies
path: pipeline-policies

- text: SLSA Attestations
path: slsa-attestations
items:
Expand Down
132 changes: 132 additions & 0 deletions docs/_data/pipeline-policy-schemas/github.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,132 @@
rules:
- type: creation
description: "Only allow users with bypass permission to create matching refs."
- type: update
description: "Only allow users with bypass permission to update matching refs."
- type: deletion
description: "Only allow users with bypass permissions to delete matching refs."
- type: required_linear_history
description: "Prevent merge commits from being pushed to matching refs."
- type: pull_request
description: "Require all commits be made to a non-target branch and submitted via a pull request before they can be merged."
parameters:
dismiss_stale_reviews_on_push:
description: "New, reviewable commits pushed will dismiss previous pull request review approvals."
method: equals
type: boolean
required: false
require_code_owner_review:
description: "Require an approving review in pull requests that modify files that have a designated code owner."
method: equals
type: boolean
required: false
require_last_push_approval:
description: "Whether the most recent reviewable push must be approved by someone other than the person who pushed it."
method: equals
type: boolean
required: false
required_approving_review_count:
description: "The number of approving reviews that are required before a pull request can be merged."
method: min
type: integer
required: false
required_review_thread_resolution:
description: "All conversations on code must be resolved before a pull request can be merged."
method: equals
type: boolean
required: false
- type: non_fast_forward
description: "Prevent users with push access from force pushing to refs."
- type: code_scanning
description: "Choose which tools must provide code scanning results before the reference is updated. When configured, code scanning must be enabled and have results for both the commit and the reference being updated."
parameters:
code_scanning_tools:
description: "Tools that must provide code scanning results for this rule to pass."
method: all_of
type: object array
required: true
properties:
alerts_threshold:
description: >
The severity level at which code scanning results that raise alerts block a reference update. For more information on alert severity levels, see "[About code scanning alerts](https://docs.github.com/code-security/code-scanning/managing-code-scanning-alerts/about-code-scanning-alerts#about-alert-severity-and-security-severity-levels)."
method: min
type: enum
required: true
policy_type: array
enum:
- none
- errors
- errors_and_warnings
- all
security_alerts_threshold:
description: >
The severity level at which code scanning results that raise security alerts block a reference update. For more information on security severity levels, see "[About code scanning alerts](https://docs.github.com/code-security/code-scanning/managing-code-scanning-alerts/about-code-scanning-alerts#about-alert-severity-and-security-severity-levels)."
method: min
type: enum
required: true
policy_type: array
enum:
- none
- critical
- high_or_higher
- medium_or_higher
- all
tool:
description: "The name of a code scanning tool"
method: one_of
type: string
required: true
policy_type: array
sample: CodeQL
# new rules - no tests yet
- type: required_signatures
description: "Require commits to be signed with a GPG key that is verified by GitHub."
- type: file_path_restriction
description: "Prevent commits that include changes in specified file and folder paths from being pushed to the commit graph. This includes absolute paths that contain file names."
parameters:
restricted_file_paths:
description: "The file paths that are restricted from being pushed to the commit graph."
method: all_of
type: string array
required: true
sample: "\n - 'src/config/local.env'"
- type: file_extension_restriction
description: "Prevent commits that include files with specified file extensions from being pushed to the commit graph."
parameters:
restricted_file_extensions:
description: "The file extensions that are restricted from being pushed to the commit graph."
method: all_of
type: string array
required: true
sample: "\n - '.sql'"
- type: max_file_path_length
description: "Prevent commits that include file paths that exceed the specified character limit from being pushed to the commit graph."
parameters:
max_file_path_length:
description: "The maximum amount of characters allowed in file paths."
method: max
type: integer
required: true
sample: '1024 # characters'
- type: max_file_size
description: "Prevent commits with individual files that exceed the specified limit from being pushed to the commit graph."
parameters:
max_file_size:
description: "The maximum file size allowed in megabytes. This limit does not apply to Git Large File Storage (Git LFS)."
method: max
type: integer
required: true
sample: '10 # mb'
- type: copilot_code_review
description: "Request Copilot code review for new pull requests automatically if the author has access to Copilot code review and their premium requests quota has not reached the limit."
parameters:
review_draft_pull_requests:
description: "Copilot automatically reviews draft pull requests before they are marked as ready for review."
method: equals
type: boolean
required: false
review_on_push:
description: "Copilot automatically reviews each new push to the pull request."
method: equals
type: boolean
required: false
Loading