Skip to content

Add layered CI and release supply-chain security #127

Description

@rowkav09

Goal

Add a layered, least-privilege GitHub security baseline for source, dependencies, workflows and release artifacts.

Bounded scope

Deliver as small linked PRs:

  • CodeQL scanning for JavaScript
  • dependency review for pull requests
  • actionlint and zizmor workflow validation
  • StepSecurity Harden Runner in audit-only mode on sensitive jobs
  • SPDX SBOM generation for immutable release artifacts
  • provenance attestations for Windows and other immutable release artifacts where repository visibility and GitHub plan support them
  • full-SHA pinning for new third-party Actions and job-level minimum permissions

Dependency update bot selection is deliberately out of scope until Renovate vs Dependabot is chosen.

Done when

Each approved check runs with least privilege, reports actionable results, does not expose secrets or private media data, and release assets have an attached SBOM and verifiable provenance where supported.

Activity

  1. rowkav09 commented on Sep 22, 2026

    @rowkav09
    MemberAuthor

    Progress update: actionlint/zizmor, Harden Runner audit mode, stable-release SPDX SBOMs, and Windows bundle provenance are now merged in #150, #148, #151, and #152. Dependency Review was attempted in #144 but is parked because private-repository support requires GitHub Advanced Security; the workflow was removed in #150 so an unavailable paid feature does not leave every PR red. Revisit only after the repository owner chooses a plan that supports it.

  2. moved this to Backlog in nowplayingon Sep 23, 2026
  3. rowkav09 commented on Sep 23, 2026

    @rowkav09
    MemberAuthor

    The repo is now public, so the parked items (CodeQL, Dependency Review) no longer need GHAS. Tracked in #287 along with secret scanning and a history scan.

  4. rowkav09 commented on Sep 24, 2026

    @rowkav09
    MemberAuthor

    All scoped items are merged. PR map:

    Secret scanning and push protection are tracked on their own in #287.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions