Skip to content

Latest commit

 

History

History
30 lines (17 loc) · 1.81 KB

File metadata and controls

30 lines (17 loc) · 1.81 KB

Supply chain and security automation

This project uses several layers to reduce risk in dependencies and workflows.

Dependency updates

CI checks

Trust signals

  • OpenSSF Scorecard (.github/workflows/scorecards.yml) publishes results to the repository’s Security tab (scheduled, on push to main, and manual dispatch — not every develop push).

Vercel vs GitHub Actions

Vercel production deploys are not tied to every PR; see VERCEL.md.

Pinning GitHub Actions

Workflows use version tags (e.g. actions/checkout@v4). For maximum reproducibility, maintainers may pin third-party actions to full commit SHAs and let Dependabot propose updates. This is optional but aligns with OpenSSF guidance.

Repository settings

Enable secret scanning, Dependabot alerts, and private vulnerability reporting on GitHub where available; see .github/README_GIT.md.