Skip to content

Expand CI security checks #7

@SSBrouhard

Description

@SSBrouhard

Goal

Move from unit-test-only CI to a baseline public-repo security posture.

Acceptance criteria

  • CI runs compile and tests on pull requests.
  • CodeQL workflow is enabled or documented if unavailable.
  • Dependency updates are configured through Dependabot.
  • Add a secrets-scan or document the substitute when GitHub secret scanning is unavailable.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:securitySecurity hardening and analysisrelease:v0.3.0Work targeted for v0.3.0 production alpha

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions