Skip to content

security: harden CodeQL and toolchain maintenance - #61

Merged
rodri-oliveira-dev merged 3 commits into
mainfrom
security/issue-60-codeql-sdk-hardening
Sep 15, 2026
Merged

rodri-oliveira-dev merged 3 commits into
mainfrom
security/issue-60-codeql-sdk-hardening

Conversation

@rodri-oliveira-dev

Copy link
Copy Markdown
Owner

Summary

Hardens the repository security baseline in two focused areas:

  • expands C# CodeQL analysis to the built-in security-extended query suite;
  • adds automated Dependabot maintenance for the .NET SDK declared by global.json.

The CodeQL workflow now also resolves the SDK from global.json instead of using a floating 10.0.x selector, keeping static analysis on the same explicit toolchain contract as the rest of the repository.

Why

ReliableWebhooks sits on an external-input boundary and processes webhook payloads, signatures, retries, and delivery state. Broader CodeQL security coverage is therefore useful, provided findings are triaged rather than suppressed for pipeline convenience.

The .NET SDK is also a supply-chain dependency: compiler and SDK changes can affect analyzers, restore/build behavior, and package output. Keeping global.json under Dependabot closes that maintenance gap without mixing SDK upgrades with NuGet or GitHub Actions updates.

Changes

  • configure CodeQL queries: security-extended;
  • resolve the CodeQL build SDK through global.json;
  • preserve manual CodeQL build, locked restore, least-privilege permissions, and SHA-pinned actions;
  • add a weekly dotnet-sdk Dependabot entry;
  • document the resulting layered security baseline in SECURITY.md.

Validation

  • reviewed the complete branch diff against main;
  • preserved the existing locked restore and Release build commands used by CodeQL;
  • preserved all existing Dependency Review, Sonar, CI, and release workflows;
  • no production code, public API, package contract, or release trigger changed;
  • the PR CI/CodeQL runs will provide repository-native validation of the new query suite.

Closes #60

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@rodri-oliveira-dev
rodri-oliveira-dev merged commit d8e7734 into main Sep 15, 2026
5 checks passed
@rodri-oliveira-dev
rodri-oliveira-dev deleted the security/issue-60-codeql-sdk-hardening branch September 15, 2026 18:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Endurecer SAST e manutenção da toolchain na baseline de segurança

1 participant