Problem
Code scanning is not configured. Current CI has no dependency-review admission. Security checks must be real and fork-safe, and must state Rust extraction and Bun metadata limits.
Scope
.github/workflows/ci.yml, tools/ci_required.sh and narrowly relevant checker tests; optional docs/engineering/security-ci.md. This issue is the designated single writer for these CI paths.
Acceptance
- Immutable action pins; Rust, JS/TS and Actions CodeQL coverage where supported, with documented extraction limits.
- Ephemeral hosted PR execution; no pull_request_target execution of PR code, secrets, persistent checkout credentials or hidden failures.
- Dependency comparison fails on introduced known vulnerabilities and absent/partial required metadata; no claim that unsupported Bun lock data was reviewed.
- Existing CI required consumes every selected security result and rejects failures/missing results.
- Verify current GitHub scans and PR behavior; CodeQL execution/upload is not automatically a clean-alert gate.
- Regression/negative controls cover result admission and dependency metadata failure; full required local gates.
No runtime or public API boundary change. Repository-admin code-scanning merge policy is coordinated by the parent governance issue.
Internal coordination
Maintainer execution: KEL-180. Public scope, progress and acceptance remain visible here; contributors do not need access to the internal board.
Problem
Code scanning is not configured. Current CI has no dependency-review admission. Security checks must be real and fork-safe, and must state Rust extraction and Bun metadata limits.
Scope
.github/workflows/ci.yml, tools/ci_required.sh and narrowly relevant checker tests; optional docs/engineering/security-ci.md. This issue is the designated single writer for these CI paths.
Acceptance
No runtime or public API boundary change. Repository-admin code-scanning merge policy is coordinated by the parent governance issue.
Internal coordination
Maintainer execution: KEL-180. Public scope, progress and acceptance remain visible here; contributors do not need access to the internal board.