Skip to content

ci: daily security-drift check (fail on open HIGH code-scanning alerts)#240

Merged
coaxk merged 1 commit into
mainfrom
ci/security-drift-check
Jun 14, 2026
Merged

ci: daily security-drift check (fail on open HIGH code-scanning alerts)#240
coaxk merged 1 commit into
mainfrom
ci/security-drift-check

Conversation

@coaxk

@coaxk coaxk commented Jun 14, 2026

Copy link
Copy Markdown
Owner

Keeps the code-scanning baseline at zero open HIGH/CRITICAL. Scheduled-on-main (not per-PR) to dodge the async-alert race + fork-token footguns; dismissal-aware (state=open), paginated, security-severity filtered. Loud detector, intentionally NOT a required check. Logic verified locally against the current baseline (0 open HIGH -> passes). Will dispatch-test on main post-merge to confirm the Actions-token plumbing.

@coaxk coaxk merged commit 901f7ad into main Jun 14, 2026
@coaxk coaxk deleted the ci/security-drift-check branch June 14, 2026 23:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant