Skip to content

ci: add security review and audit checks#47

Closed
benvinegar wants to merge 1 commit intomainfrom
ci/security-checks
Closed

ci: add security review and audit checks#47
benvinegar wants to merge 1 commit intomainfrom
ci/security-checks

Conversation

@benvinegar
Copy link
Copy Markdown
Member

Summary

  • add a dedicated Security workflow with dependency review on PRs and an allowlisted Bun audit job on PRs and main
  • make CI and release workflows explicitly default to read-only contents permissions
  • document the new audit command and add tests for the audit parser/allowlist behavior

Testing

  • bun run typecheck
  • bun test
  • bun run check:pack
  • bun run check:security-audit

@benvinegar
Copy link
Copy Markdown
Member Author

Closing for backlog cleanup. This security workflow/audit work is now too far behind current main to merge cleanly. If we still want it, it should be reopened as a fresh PR rebased onto the current CI layout.

@benvinegar benvinegar closed this Apr 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant