Skip to content

Limen 0.0.1 - #4

Open
apostasie wants to merge 3 commits into
mainfrom
work
Open

Limen 0.0.1#4
apostasie wants to merge 3 commits into
mainfrom
work

Conversation

@apostasie

Copy link
Copy Markdown
Collaborator

No description provided.

Signed-off-by: apostasie <spam_blackhole@farcloser.world>

@mendral-app mendral-app Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Supply Chain Security Review

✅ Approve

No dependency changes detected by osv-scanner. Workflows use SHA-pinned actions/checkout@9c091bb… (verified v7.0.0), minimal permissions: {} at top level with scoped contents: read/contents: write per job, persist-credentials: false, and the custom setup-aqua action downloads the installer at a pinned tag with SHA256 verification. The update-aqua-checksum workflow's write scope is appropriately limited to Renovate branches only.

Tag @mendral-app with feedback or questions. View session

@mendral-app mendral-app Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Supply Chain Security Review

✅ Approve

CI overhaul with strong supply-chain hygiene: all actions SHA-pinned, top-level permissions: {} with minimal per-job grants, aqua installer checksum-verified, persist-credentials: false on checkout, and no pull_request_target usage.

Tag @mendral-app with feedback or questions. View session

Signed-off-by: apostasie <spam_blackhole@farcloser.world>

@mendral-app mendral-app Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Supply Chain Security Review

✅ Approve

No dependency changes detected by osv-scanner. Workflows are well-hardened: top-level permissions: {}, per-job least-privilege scopes, actions/checkout pinned to verified SHA (9c091bb… = v7.0.0), aqua installer fetched with SHA256 verification, persist-credentials: false, branch name passed via env not interpolation, and write token scoped to the single push step.

Tag @mendral-app with feedback or questions. View session

Signed-off-by: apostasie <spam_blackhole@farcloser.world>

@mendral-app mendral-app Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Supply Chain Security Review

✅ Approve

Workflows are well-hardened: all third-party actions pinned by full SHA to verified releases, top-level permissions: {} with minimal per-job grants, persist-credentials: false, concurrency with cancel-in-progress, and the custom composite action checksum-verifies the aqua installer before execution. No dependency changes detected by osv-scanner.

Tag @mendral-app with feedback or questions. View session

@apostasie apostasie closed this Jul 7, 2026
@apostasie apostasie reopened this Jul 7, 2026
@apostasie
apostasie enabled auto-merge (rebase) July 7, 2026 18:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant