Skip to content

Latest commit

 

History

656 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Onboarding de Clientes PF/PJ

Sistema de onboarding para cadastro de clientes Pessoa Física e Pessoa Jurídica com autenticação via Keycloak.

Security

CI Dependabot Security Policy

This project runs 13 security checks across a multi-stage pipeline:

Stage Jobs Purpose
Build Backend, Client, Backoffice Parallel builds with artifact caching
Tests Domain/API/Integration, Client checks, Backoffice checks Coverage ≥ 80%, tsc, eslint
Security 10 independent jobs (SAST, SCA, SBOM, DAST, Container, IaC, Secrets) Run in parallel, no dependencies
Category Tools
Build/Test .NET 10 + coverlet (80% coverage threshold)
Frontend Vinxi (tsc, eslint, build) × 2 projects
SAST Semgrep (custom rules), CodeQL (dataflow analysis)
SCA Trivy (dependency CVEs), Dependabot (weekly updates)
SBOM Syft (source code SPDX + container CycloneDX)
DAST OWASP ZAP (baseline scan against running API)
Container Trivy (image scan), Dockle (CIS Benchmarks)
IaC Checkov (Docker Compose), Kubescape (K8s preparation)
Secrets Gitleaks (pattern detection), TruffleHog (active verification)

Pipeline stages: Build → Tests (needs build) — Security runs parallel, independent.

See Security Overview for complete documentation. See CI Pipeline Architecture for multi-stage details and security tool rationale.

Tech Stack

  • Backend: .NET 10, ASP.NET Core Controllers, Entity Framework Core, PostgreSQL
  • Frontend: React 19, Vinxi (Vite-based), TypeScript, Tailwind CSS, TanStack Router
  • Auth: Keycloak 26.1 (hardened), JWT, ROPC grant
  • Infrastructure: Docker Compose, GitHub Actions CI/CD
  • Observability: Serilog, OpenTelemetry

Local Development

Use docker compose up -d to start the full stack. Do not run pnpm dev directly on the host — see docs/dev-setup.md for why and for the escape hatch.

Quick Start

# Start the full stack (frontend SPAs included via docker compose)
cp .env.example .env   # fill secrets
docker compose up -d

# Backend (optional, runs inside compose — start separately only for debugger attach)
dotnet restore Onboarding.slnx
dotnet run --project src/Onboarding.API

Documentation

License

Internal project — all rights reserved.

About

No description, website, or topics provided.

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages