Skip to content

Enterprise: CI/CD pipeline and supply-chain scanning #65

Description

@sorenwacker

Part of #61 (Tier 1).

Problem. Gates (ruff, ruff-format, vulture@80, strict mypy, pytest) run only locally via pre-commit/pre-push. No CI enforcement, coverage tracking, or security scanning.

Goal. GitHub Actions running the same gates on every PR + coverage report + Dependabot + SAST/dependency scan + SBOM + automated, signed releases.

Acceptance. PRs blocked on red gates; coverage published; vulnerable deps flagged; releases reproducible.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions