This project uses several layers to reduce risk in dependencies and workflows.
- Dependabot (
.github/dependabot.yml) opens weekly update PRs againstdevelopfor npm and GitHub Actions. - Dependency Review (
.github/workflows/dependency-review.yml) runs on pull requests whenpackage.json/package-lock.jsonchange and flags known-vulnerable dependencies.
- npm audit (high severity threshold), license allowlist (
license-checker), Gitleaks, and CycloneDX SBOM generation run in the Security Scanning job in.github/workflows/ci.yml. - CodeQL (
.github/workflows/codeql.yml) analyzes JavaScript/TypeScript on push/PR and weekly. - DCO (
.github/workflows/dco.yml) enforcesSigned-off-bylines on every commit in a PR.
- OpenSSF Scorecard (
.github/workflows/scorecards.yml) publishes results to the repository’s Security tab (scheduled, on push tomain, and manual dispatch — not everydeveloppush).
Vercel production deploys are not tied to every PR; see VERCEL.md.
Workflows use version tags (e.g. actions/checkout@v4). For maximum reproducibility, maintainers may pin third-party actions to full commit SHAs and let Dependabot propose updates. This is optional but aligns with OpenSSF guidance.
Enable secret scanning, Dependabot alerts, and private vulnerability reporting on GitHub where available; see .github/README_GIT.md.