Repository navigation
Add layered CI and release supply-chain security #127
Copy link
Copy link
Closed
Description
Activity
- added 2 commits that reference this issue
on Sep 21, 2026 Progress update: actionlint/zizmor, Harden Runner audit mode, stable-release SPDX SBOMs, and Windows bundle provenance are now merged in #150, #148, #151, and #152. Dependency Review was attempted in #144 but is parked because private-repository support requires GitHub Advanced Security; the workflow was removed in #150 so an unavailable paid feature does not leave every PR red. Revisit only after the repository owner chooses a plan that supports it.
The repo is now public, so the parked items (CodeQL, Dependency Review) no longer need GHAS. Tracked in #287 along with secret scanning and a history scan.
All scoped items are merged. PR map:
- actionlint + zizmor workflow validation: ci: fix actionlint Linux archive name #150 (
workflow-security.yml) - Harden Runner audit mode on sensitive jobs: ci: audit release job network egress #148
- SPDX SBOM on stable releases: ci: attach SPDX SBOM to stable releases #151
- Provenance attestations for Windows bundles: ci: attest published Windows bundles #152
- Dependency Review: first try ci: review dependency changes in pull requests #144, parked while private, re-added on every PR in ci: review dependency changes on every pull request (#287) #300 (Security baseline now that the repo is public: CodeQL, dependency review, secret scanning #287)
- CodeQL for JS/TS, Actions and C#: ci: add CodeQL for JavaScript/TypeScript, Actions and C# (#287) #302, alert fixes in fix(updater): linear-time version parsing, skip malformed release tags (#172) #310 and test: fix CodeQL tag-filter and file-race alerts in tests (#287) #311 (Security baseline now that the repo is public: CodeQL, dependency review, secret scanning #287)
- Full-SHA pinning + least privilege: every
uses:in.github/workflowsis pinned to a 40-char SHA and every workflow sets top-levelpermissions(checked 24 Sept on a4e9d15)
Secret scanning and push protection are tracked on their own in #287.
- actionlint + zizmor workflow validation: ci: fix actionlint Linux archive name #150 (
Metadata
Metadata
Assignees
Type
Projects
- StatusShow more project fieldsDone
Goal
Add a layered, least-privilege GitHub security baseline for source, dependencies, workflows and release artifacts.
Bounded scope
Deliver as small linked PRs:
Dependency update bot selection is deliberately out of scope until Renovate vs Dependabot is chosen.
Done when
Each approved check runs with least privilege, reports actionable results, does not expose secrets or private media data, and release assets have an attached SBOM and verifiable provenance where supported.