Skip to content

chore: harden CI, workflows, and runtime defaults#24

Merged
lewiswigmore merged 4 commits into
mainfrom
hardening/code-hardening-implementation
Apr 10, 2026
Merged

chore: harden CI, workflows, and runtime defaults#24
lewiswigmore merged 4 commits into
mainfrom
hardening/code-hardening-implementation

Conversation

@lewiswigmore
Copy link
Copy Markdown
Owner

Summary

  • harden CI/release/security workflows and permissions
  • add SECURITY.md, CODEOWNERS refinements, and PR security checklist
  • tighten runtime API key/CORS defaults with tests and docs updates

Validation

  • npm run lint
  • npm run build
  • npm run test

lewiswigmore and others added 4 commits April 10, 2026 22:44
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Keep matrix job/check names aligned with branch protection contexts (build 20.x/22.x) while retaining the aggregate required-checks job.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Pin Actions references to commit SHAs to satisfy repository policy (selected actions + SHA pinning required) and unblock workflow startup on PRs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This repository already has CodeQL default setup enabled. Removing the advanced CodeQL workflow avoids SARIF processing failures on PR checks.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@lewiswigmore lewiswigmore merged commit 1128d82 into main Apr 10, 2026
7 checks passed
@lewiswigmore lewiswigmore deleted the hardening/code-hardening-implementation branch April 10, 2026 22:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant