Skip to content
This repository was archived by the owner on Sep 17, 2026. It is now read-only.

ci: add dependency and workflow security scans - #44

Merged
sds merged 3 commits into
mainfrom
codex/security-scans-20260917
Sep 17, 2026
Merged

sds merged 3 commits into
mainfrom
codex/security-scans-20260917

Conversation

@sds

@sds sds commented Sep 17, 2026

Copy link
Copy Markdown
Member

Summary

  • run the reusable Dependency Scan and Scan GitHub Actions workflows on pull requests
  • install secure-runner as the first step in every ordinary GitHub Actions job, pinned to the latest gh-actions commit
  • repair the release-tag workflow’s duplicate environment block and quote shell variables so the updated workflows pass validation

Validation

  • actionlint .github/workflows/*.yml
  • zizmor --format plain .github/workflows
  • pnpm run lint
  • pnpm run typecheck
  • pnpm run test (73 tests passed)

@sds
sds merged commit ae12c37 into main Sep 17, 2026
5 checks passed
@sds
sds deleted the codex/security-scans-20260917 branch September 17, 2026 19:56
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant