Problem
A few low-cost hardening items are missing:
- No
SECURITY.md. Private vulnerability reporting is enabled on the repository, but nothing tells a reporter to use it instead of opening a public issue, or which versions receive fixes.
- Workflows without a
permissions: block. lint.yml, docs.yml and renovate-validate.yml run with the repository's default GITHUB_TOKEN permissions. The other workflows already declare theirs.
persist-credentials. Only release.yml sets persist-credentials: false on actions/checkout; the other jobs leave the token in .git/config for every later step.
- Actions pinned by tag. Third-party actions (
astral-sh/setup-uv, JamesIves/github-pages-deploy-action, softprops/action-gh-release, pypa/gh-action-pypi-publish@release/v1) are referenced by mutable tags or branches. Renovate can keep SHA pins up to date (helpers:pinGitHubActionDigests).
Proposal
- Add
SECURITY.md pointing to private vulnerability reporting and stating the supported version line.
- Add
permissions: contents: read at the top of the three workflows.
- Set
persist-credentials: false on every checkout that does not push.
- Pin actions to commit SHAs, at least in
release.yml, and enable the Renovate preset.
Problem
A few low-cost hardening items are missing:
SECURITY.md. Private vulnerability reporting is enabled on the repository, but nothing tells a reporter to use it instead of opening a public issue, or which versions receive fixes.permissions:block.lint.yml,docs.ymlandrenovate-validate.ymlrun with the repository's defaultGITHUB_TOKENpermissions. The other workflows already declare theirs.persist-credentials. Onlyrelease.ymlsetspersist-credentials: falseonactions/checkout; the other jobs leave the token in.git/configfor every later step.astral-sh/setup-uv,JamesIves/github-pages-deploy-action,softprops/action-gh-release,pypa/gh-action-pypi-publish@release/v1) are referenced by mutable tags or branches. Renovate can keep SHA pins up to date (helpers:pinGitHubActionDigests).Proposal
SECURITY.mdpointing to private vulnerability reporting and stating the supported version line.permissions: contents: readat the top of the three workflows.persist-credentials: falseon every checkout that does not push.release.yml, and enable the Renovate preset.