Problem
No static security analysis exists on the codebase.
Scope
Add a GitHub Actions CodeQL workflow for TypeScript scanning.
Acceptance criteria
- Scans
javascript language on push to main and PRs
- Alerts in Security tab
- No high/critical alerts on baseline scan
- Documented in
SECURITY.md
Complexity: Easy · 75 points
Problem
No static security analysis exists on the codebase.
Scope
Add a GitHub Actions CodeQL workflow for TypeScript scanning.
Acceptance criteria
javascriptlanguage on push tomainand PRsSECURITY.mdComplexity: Easy · 75 points