Skip to content

Harden Scorecard signals around release signing and PR checks#392

Merged
NagyVikt merged 1 commit intomainfrom
agent/codex/harden-scorecard-best-practices-2026-04-23-18-42
Apr 23, 2026
Merged

Harden Scorecard signals around release signing and PR checks#392
NagyVikt merged 1 commit intomainfrom
agent/codex/harden-scorecard-best-practices-2026-04-23-18-42

Conversation

@NagyVikt
Copy link
Copy Markdown
Collaborator

Automated by gx branch finish (PR flow).

Add pull_request coverage for CI and CodeQL, exact dependency pins, npm Dependabot coverage, and signed GitHub release assets via Sigstore bundles. Also fix the security advisory link and widen CODEOWNERS so stricter review settings have matching repo metadata.

Constraint: Signed-release credit only improves on future or re-run releases because existing tags have no uploaded assets
Rejected: Require two reviewers immediately | likely blocks this mostly single-maintainer repo without proving sustainable reviewer capacity
Confidence: medium
Scope-risk: moderate
Directive: If branch protection is tightened after merge, keep required check names aligned with workflow job names before renaming them
Tested: node --test test/metadata.test.js
Tested: timeout 180 npm test
Tested: openspec validate agent-codex-harden-scorecard-best-practices-2026-04-23-18-42 --type change --strict
Tested: openspec validate --specs
Not-tested: Live GitHub Actions release run producing .sigstore.json assets
Not-tested: Live Scorecard rerun after the next signed release and branch-protection update
@NagyVikt NagyVikt merged commit f0ee72a into main Apr 23, 2026
@NagyVikt NagyVikt deleted the agent/codex/harden-scorecard-best-practices-2026-04-23-18-42 branch April 23, 2026 16:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant