II.
Workflow overview
Reference · liveworkflow:security-review
Security Review overview
Evaluates code changes and infrastructure modifications for security vulnerabilities, compliance gaps, and threat-model alignment.
Attributes
displayName
Security Review
workflowKind
security
triggerType
event-driven
typicalCadence
per-pull-request
complexity
single-team
description
Evaluates code changes and infrastructure modifications for security
vulnerabilities, compliance gaps, and threat-model alignment.
Outgoing edges
applies_to_domain4
- domain:cybersecurity·DomainCybersecurity
- domain:security·DomainSecurity
- domain:cybersecurity·DomainCybersecurity
- domain:security·DomainSecurity
involves_role4
- role:security-reviewer·RoleSecurity Reviewer
- role:code-reviewer·RoleCode Reviewer
- role:security-reviewer·RoleSecurity Reviewer
- role:code-reviewer·RoleCode Reviewer
performed_by_org_unit2
- org-unit:security-team·OrgUnitSecurity Team
- org-unit:security-team·OrgUnitSecurity Team
requires_skill_area4
- skill-area:oauth-flows·SkillAreaOAuth Flows
- skill-area:webhook-verification·SkillAreaWebhook Verification
- skill-area:oauth-flows·SkillAreaOAuth Flows
- skill-area:webhook-verification·SkillAreaWebhook Verification
triggers_responsibility4
- responsibility:run-security-scans·ResponsibilityRun security scans
- responsibility:review-prs-merge-decisions·ResponsibilityReview PRs and make merge decisions
- responsibility:run-security-scans·ResponsibilityRun security scans
- responsibility:review-prs-merge-decisions·ResponsibilityReview PRs and make merge decisions
Incoming edges
follows_workflow2
- stack-profile:healthcare-hipaa-compliant·StackProfileHealthcare / HIPAA Compliant (Node.js + PostgreSQL + Vault + React)
- stack-profile:government-portal·StackProfileGovernment Portal (.NET, Blazor, PostgreSQL, Keycloak, Docker, Azure)