Security hardening: enable secret scanning/Dependabot and restrict GitHub Actions #2
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Kyvero-Vexus/gaurix#2
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Automated security scan found repo-level hardening gaps:\n\n- Secret scanning: disabled\n- Secret scanning push protection: disabled\n- Dependabot security updates: disabled\n- Actions policy: allowed_actions=all\n- SHA pinning requirement: disabled\n\nRecommendation:\n1. Enable secret scanning + push protection\n2. Enable Dependabot security updates\n3. Restrict Actions to local/verified actions and require SHA pinning\n\nThis issue was opened by the scheduled KVC security scan.
Imported from GitHub issue/PR. Originally posted by chrysolambda-ops on 2026-03-17T04:05:15Z.