Problem statement
Current security projection is incomplete and GitHub Actions are not uniformly pinned to immutable SHAs.
Desired outcome
Managed public repositories receive the full v1 security baseline and clear plan-capability results.
Scope
- Secret, dependency, code scanning; SBOM; private reporting; security contact/response policy.
- Immutable action pins and update automation.
- Fork-safe permissions and no secret exposure.
Non-goals
- Purchasing GitHub features or weakening requirements silently.
Acceptance criteria
Test expectations
Begin with failing unpinned-action, permission, missing-control, SBOM, and fork-event fixtures.
Security implications
Independent security review and threat-focused workflow testing are required.
Documentation implications
Generate security model and response targets.
Dependencies
Projection and conformance issues.
Human decision points
Security waivers and exposure of previously private data.
Problem statement
Current security projection is incomplete and GitHub Actions are not uniformly pinned to immutable SHAs.
Desired outcome
Managed public repositories receive the full v1 security baseline and clear plan-capability results.
Scope
Non-goals
Acceptance criteria
Test expectations
Begin with failing unpinned-action, permission, missing-control, SBOM, and fork-event fixtures.
Security implications
Independent security review and threat-focused workflow testing are required.
Documentation implications
Generate security model and response targets.
Dependencies
Projection and conformance issues.
Human decision points
Security waivers and exposure of previously private data.