Skip to content

Security hardening - #98

Merged
jeremydixon22 merged 1 commit into
mainfrom
security/hardening
Aug 17, 2026
Merged

Security hardening#98
jeremydixon22 merged 1 commit into
mainfrom
security/hardening

Conversation

@jeremydixon22

Copy link
Copy Markdown
Member

Summary

  • require a configured API key before the server container starts and verify anonymous MCP is rejected
  • commit and enforce NuGet dependency locks; add a hash-verified Python REST/MCP host deployment profile
  • keep CodeQL, dependency review, container security, release integrity, and execution-consumer assurance workflows continuously active

Verification

  • dotnet restore Vyral.sln --locked-mode
  • Python hash-verified server-profile installation
  • policy, workflow-health, version, and public-export rehearsals
  • server startup/authentication checks (full strict Docker harness deferred to hosted runner: this local Docker host rejects the chiseled image under its existing no-new-privileges/read-only setup before process execution)

@jeremydixon22
jeremydixon22 merged commit 806481b into main Aug 17, 2026
16 checks passed
@jeremydixon22
jeremydixon22 deleted the security/hardening branch August 17, 2026 22:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant