Parent issue
Part of #885 — Update app's GitHub Apps and automation
Objective
Evaluate and enable appropriate repository security scanning.
Evidence
- Dependabot security updates are enabled.
- Secret scanning and push protection are currently disabled.
- No code-scanning analysis is configured or available for the repository.
- The application includes server routes, external APIs, wallet integrations, GraphQL, and runtime secrets.
Scope
- Evaluate secret scanning and push protection for repository visibility and operational needs.
- Add CodeQL or an approved equivalent for the TypeScript/Nuxt codebase.
- Review current Dependabot alerts and define ownership/response expectations.
- Document false-positive handling and remediation workflow.
Acceptance criteria
- Security scanning decisions are documented with rationale.
- Approved secret scanning and code scanning are enabled where appropriate.
- Initial alerts are triaged and assigned owners.
- CI/security checks do not expose secrets in logs.
Out of scope
A complete application penetration test or remediation of every historical alert.
Parent issue
Part of #885 — Update app's GitHub Apps and automation
Objective
Evaluate and enable appropriate repository security scanning.
Evidence
Scope
Acceptance criteria
Out of scope
A complete application penetration test or remediation of every historical alert.