diff --git a/DEFENSE_IN_DEPTH.md b/DEFENSE_IN_DEPTH.md index 594f7a92..4adf37df 100644 --- a/DEFENSE_IN_DEPTH.md +++ b/DEFENSE_IN_DEPTH.md @@ -49,4 +49,4 @@ Profile: npm library · public ## 7. Repository lockdown - [x] Phishing-resistant 2FA (passkeys / hardware keys) on the GitHub and npm accounts — PR #1706 - [x] Recovery codes stored offline in a password manager — PR #1706 -- [x] `lockdown-repo.sh` applied by a repo admin (never committed to this repo); `--check` with `--required-checks` and `--allowed-actions` passes (PRs required on the default branch, merges blocked unless required status checks pass, tag ruleset, immutable releases, fork-PR approval (public repos), read-only workflow tokens, Actions allowlist, secret scanning, Dependabot disabled, private vulnerability reporting (public repos)) — PR #1705 +- [x] `lockdown-repo.sh` applied by a repo admin (never committed to this repo); `--check` with `--required-checks "test,test-22,test-24,test-26,zizmor"` and `--allowed-actions "pnpm/*,codecov/*,cloudflare/*"` passes (PRs required on the default branch, merges blocked unless required status checks pass, tag ruleset, immutable releases, fork-PR approval (public repos), read-only workflow tokens, Actions allowlist, secret scanning, Dependabot disabled, private vulnerability reporting (public repos)) — PR #1705, required checks updated PR #1707 diff --git a/SECURITY.md b/SECURITY.md index 98405dd5..ad350451 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -23,7 +23,7 @@ We will acknowledge receipt, work with you on a coordinated disclosure timeline, This repository follows the [defense-in-depth](https://github.com/jaredwray/agentic/blob/main/skills/security/defense-in-depth-nodejs/SKILL.md) hardening checklist; progress is tracked in [DEFENSE_IN_DEPTH.md](./DEFENSE_IN_DEPTH.md). Measures currently in place: -- All changes land through pull requests — direct pushes to `main` are blocked, and merging requires passing status checks. +- All changes land through pull requests — direct pushes to `main` are blocked, and merging requires passing status checks (`test`, `test-22`, `test-24`, `test-26`, `zizmor`). - Tags can only be created by repository admins; published GitHub Releases are immutable (assets and tags cannot be changed after publish). - Workflow runs from outside collaborators always require maintainer approval, and only allowlisted GitHub Actions can run. - CI workflows default to read-only `contents: read` permissions; generated output is never committed back from CI; every action is pinned to a full commit SHA; Socket Firewall (`sfw`) wraps `pnpm install`; workflows are security-linted with zizmor on every PR.