Skip to content

Evaluate secret scanning and code scanning #898

Description

@kylymo

Parent issue

Part of #885Update app's GitHub Apps and automation

Objective

Evaluate and enable appropriate repository security scanning.

Evidence

  • Dependabot security updates are enabled.
  • Secret scanning and push protection are currently disabled.
  • No code-scanning analysis is configured or available for the repository.
  • The application includes server routes, external APIs, wallet integrations, GraphQL, and runtime secrets.

Scope

  • Evaluate secret scanning and push protection for repository visibility and operational needs.
  • Add CodeQL or an approved equivalent for the TypeScript/Nuxt codebase.
  • Review current Dependabot alerts and define ownership/response expectations.
  • Document false-positive handling and remediation workflow.

Acceptance criteria

  • Security scanning decisions are documented with rationale.
  • Approved secret scanning and code scanning are enabled where appropriate.
  • Initial alerts are triaged and assigned owners.
  • CI/security checks do not expose secrets in logs.

Out of scope

A complete application penetration test or remediation of every historical alert.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions