Skip to content

ci: add CodeQL and dependency-review admission #170

Description

@0monish

Problem

Code scanning is not configured. Current CI has no dependency-review admission. Security checks must be real and fork-safe, and must state Rust extraction and Bun metadata limits.

Scope

.github/workflows/ci.yml, tools/ci_required.sh and narrowly relevant checker tests; optional docs/engineering/security-ci.md. This issue is the designated single writer for these CI paths.

Acceptance

  • Immutable action pins; Rust, JS/TS and Actions CodeQL coverage where supported, with documented extraction limits.
  • Ephemeral hosted PR execution; no pull_request_target execution of PR code, secrets, persistent checkout credentials or hidden failures.
  • Dependency comparison fails on introduced known vulnerabilities and absent/partial required metadata; no claim that unsupported Bun lock data was reviewed.
  • Existing CI required consumes every selected security result and rejects failures/missing results.
  • Verify current GitHub scans and PR behavior; CodeQL execution/upload is not automatically a clean-alert gate.
  • Regression/negative controls cover result admission and dependency metadata failure; full required local gates.

No runtime or public API boundary change. Repository-admin code-scanning merge policy is coordinated by the parent governance issue.

Internal coordination

Maintainer execution: KEL-180. Public scope, progress and acceptance remain visible here; contributors do not need access to the internal board.

Activity

  1. self-assigned this
    on Sep 7, 2026
  2. added
    foundationOpen-source foundation readiness and its evidence
    on Sep 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

foundationOpen-source foundation readiness and its evidence

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions