Skip to content

ci: harden release workflows (SHA-pin actions, least-privilege token, TLS timestamper) - #64

Merged
07souravkunda merged 1 commit into
release_3.1.1from
locsec/WI-9a6a0fac
Sep 17, 2026
Merged

07souravkunda merged 1 commit into
release_3.1.1from
locsec/WI-9a6a0fac

ci: harden release workflows (SHA-pin actions, least-privilege token,…

8b8a6ed
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / Semgrep OSS succeeded Aug 26, 2026 in 5s

1 new alert

New alerts in code changed by this pull request

  • 1 warning

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 12 in .github/dependabot.yml

See this annotation in the file changed.

Code scanning / Semgrep OSS

Semgrep Finding: package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown Warning

This Dependabot configuration does not set a cooldown period. Newly published packages can be malicious or unstable. Add a cooldown block with default-days: 7 to each package-ecosystem entry under updates to wait 7 days before proposing updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown