Skip to content

Improve CI/CD security#420

Closed
mauriciolauffer wants to merge 2 commits into
cap-js:mainfrom
mauriciolauffer:cicd
Closed

Improve CI/CD security#420
mauriciolauffer wants to merge 2 commits into
cap-js:mainfrom
mauriciolauffer:cicd

Conversation

@mauriciolauffer
Copy link
Copy Markdown
Contributor

Add dependabot for NPM and GitHub Actions. Weekly checks with 1 day cooldown to avoid pushing freshly compromised deps.

Add Harden Runner to all GitHub Actions to monitor the processes.

@sjvans
Copy link
Copy Markdown
Contributor

sjvans commented May 18, 2026

thanks @mauriciolauffer

i extracted the dependabot cooldown to #422. our security experts are looking into the hardened runner option.

sjvans added a commit that referenced this pull request May 21, 2026
@sjvans
Copy link
Copy Markdown
Contributor

sjvans commented May 22, 2026

hi @mauriciolauffer
if our security experts decide harden runner shall be used, we'll open a new pr.
thanks again!

@sjvans sjvans closed this May 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants