Skip to content

security-pack: add OSS security workflow + Dependabot + pre-commit#21

Merged
hinanohart merged 6 commits into
mainfrom
security-pack-init
May 15, 2026
Merged

security-pack: add OSS security workflow + Dependabot + pre-commit#21
hinanohart merged 6 commits into
mainfrom
security-pack-init

Conversation

@hinanohart
Copy link
Copy Markdown
Owner

Auto-generated security pack from ~/.claude/templates/security-pack/.

Workflow (.github/workflows/security.yml)

  • step-security/harden-runner (audit mode, 2 weeks)
  • actions/dependency-review-action (PR gate, moderate+)
  • trufflesecurity/trufflehog (verified secrets)
  • Semgrep CI (auto config)
  • ossf/scorecard-action (weekly + push)

Dependabot

github-actions / pip / npm / docker, weekly, grouped minor+patch.

pre-commit

gitleaks, ruff, shellcheck, actionlint, hadolint, osv-scanner, detect-private-key.

Settings auto-enabled via gh api

  • Dependabot alerts + security updates
  • Secret scanning + push protection
  • CodeQL default-setup (language auto-detect)
  • Branch protection: linear_history, non_fast_forward, deletion blocked

@hinanohart hinanohart merged commit 365523e into main May 15, 2026
15 checks passed
@hinanohart hinanohart deleted the security-pack-init branch May 15, 2026 12:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant