Skip to content

ci: security updates - #51

Open
aliziel wants to merge 3 commits into
mainfrom
ci/security-updates
Open

ci: security updates#51
aliziel wants to merge 3 commits into
mainfrom
ci/security-updates

Conversation

@aliziel

@aliziel aliziel commented Jul 1, 2026

Copy link
Copy Markdown
Collaborator

Dependabot

Dependabot security updates are already enabled, this config will automate version updates. We likely won't find the right alert:noise balance on the first attempt, so we should be open to further tuning.

Config covers:

  • pip (CDK build)
  • docker (API container image)
  • github-actions (CI)

Schedule

Currently on the default schedule, so we'd get in batches all at once, but can spread out more if that's the preference.

Cooldowns

Also used more granular cooldown configs for major/minor version bumps on uv only, but can add to other package ecosystems if that's preferred as well. Some suggest up to 14 days, but we also had a teammember get blocked on patching.a security fix, so attempting to balance.

OSSF Scorecard

From the Open Source Security Foundation. Audits repository security posture, practices, and config.

https://scorecard.dev/
https://github.com/ossf/scorecard-action

Schedule

Alongside pushes to main, also runs Monday 10:30/11:30 CT to ensure consistent assessment. Time was chosen to run before Monday tagup, but can absolutely be changed.

Token permissions

Moved id-token: write from top-level (all jobs) to specific job required.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant