Skip to content

Security hardening: close supply-chain and policy gaps - #4

Merged
ms-kumar merged 3 commits into
mainfrom
security/hardening-gaps
Sep 25, 2026
Merged

ms-kumar merged 3 commits into
mainfrom
security/hardening-gaps

Conversation

@ms-kumar

Copy link
Copy Markdown
Owner

Gap analysis (deep scan 2026-09-25)

Checked: Dependabot alerts, pip-audit on project env, secret scan (tree + full history), dangerous code patterns (eval/exec/pickle.loads/yaml.load/subprocess), Actions pinning, workflow permissions, Dependabot config, branch protection, secret scanning/push protection, CodeQL status.

Already secure (verified, no change):

Gaps fixed in this PR (one commit each):

  1. Actions on mutable tags (@v4/@v5, supply-chain risk) → pinned to SHAs
  2. No dependabot.yml (updates were ad-hoc) → weekly schedule, grouped uv updates
  3. No SECURITY.md → reporting policy + supported versions

Deliberately not changed (needs your call):

  • Branch protection on main is off — recommend requiring PR + CI/Test checks (command in comments)
  • release.yml has no provenance attestation — follow-up once publishing to PyPI

@ms-kumar
ms-kumar marked this pull request as ready for review September 25, 2026 02:44
@ms-kumar
ms-kumar merged commit fc10d5d into main Sep 25, 2026
8 of 9 checks passed
@ms-kumar ms-kumar mentioned this pull request Sep 25, 2026
12 tasks
@ms-kumar
ms-kumar deleted the security/hardening-gaps branch September 25, 2026 02:57
@ms-kumar ms-kumar added the enhancement New feature or request label Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant