Skip to content

security: harden CI and secrets handling - #15

Merged
damoahdominic merged 1 commit into
mainfrom
security/hardening-2026-03-14
Mar 14, 2026
Merged

security: harden CI and secrets handling#15
damoahdominic merged 1 commit into
mainfrom
security/hardening-2026-03-14

Conversation

@damoahdominic

Copy link
Copy Markdown
Owner

Summary

  • Add detect-secrets pre-commit config + CI baseline scan
  • Add CodeQL workflow
  • Add Dependabot config
  • Pin GitHub Actions to commit SHAs
  • Explicitly set Electron webPreferences defaults (contextIsolation true, nodeIntegration false)
  • Add BYOK key security notes to CONTRIBUTING

Testing

  • Not run (docs/CI config changes only)

@damoahdominic
damoahdominic force-pushed the security/hardening-2026-03-14 branch from fdd945f to a3d68cd Compare March 14, 2026 19:32
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@damoahdominic
damoahdominic merged commit 7530151 into main Mar 14, 2026
3 checks passed
@damoahdominic
damoahdominic deleted the security/hardening-2026-03-14 branch March 14, 2026 20:14
damoahdominic added a commit that referenced this pull request Mar 16, 2026
damoahdominic added a commit that referenced this pull request Mar 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants