Skip to content

fix(security): close open scanning alerts and doc breakages#103

Merged
abolsen merged 2 commits intomainfrom
fix/code-scanning-open-alerts
Apr 19, 2026
Merged

fix(security): close open scanning alerts and doc breakages#103
abolsen merged 2 commits intomainfrom
fix/code-scanning-open-alerts

Conversation

@abolsen
Copy link
Copy Markdown
Contributor

@abolsen abolsen commented Apr 19, 2026

Summary

  • split VS Code extension release flow into a non-release build workflow plus tag-only publish workflow that consumes prebuilt artifacts
  • remove publish-path patterns that trigger zizmor artipacked and cache-poisoning, and add guarded run-id resolution for release publishes
  • clean README/SECURITY hygiene by removing broken badges/placeholder URL and documenting current install and review posture

Test plan

  • Reviewed workflow YAML and docs diffs for intended behavior
  • ReadLints check on edited files (no diagnostics)
  • GitHub Actions checks on this PR

Made with Cursor

Split extension build from tag publishing to avoid artifact credential and cache-poisoning risks, and refresh security/install docs to remove broken badges and placeholder links.

Made-with: Cursor
@github-actions github-actions bot added ci CI/CD and automation changes docs Documentation updates labels Apr 19, 2026
Ensure pre-commit end-of-file-fixer passes in CI by keeping SECURITY.md newline-terminated.

Made-with: Cursor
@abolsen abolsen merged commit cb68b4e into main Apr 19, 2026
26 checks passed
@abolsen abolsen deleted the fix/code-scanning-open-alerts branch April 19, 2026 21:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci CI/CD and automation changes docs Documentation updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant