Skip to content

Harden GitHub workflow security#359

Merged
kpumuk merged 3 commits intomainfrom
security-hardening
Mar 21, 2026
Merged

Harden GitHub workflow security#359
kpumuk merged 3 commits intomainfrom
security-hardening

Conversation

@kpumuk
Copy link
Copy Markdown
Owner

@kpumuk kpumuk commented Mar 21, 2026

Why?

This completes the repository-side part of the GitHub security hardening work so the release pipeline uses safer workflow defaults and branch protection can depend on stable check names.

How?

Tighten workflow checkout behavior, add a repository security policy, and introduce stable non-matrix required-check jobs so branch rules can target fixed statuses even when the matrix changes.

@kpumuk kpumuk merged commit 5289548 into main Mar 21, 2026
42 checks passed
@kpumuk kpumuk deleted the security-hardening branch March 21, 2026 23:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant