Skip to content

Public readiness: CI hardening + OpenSSF Scorecard alignment #14

Description

@DocGerd
  • Least-privilege: explicit top-level permissions: (contents: read) in all workflows.
  • Pin all GitHub Actions by commit SHA (Scorecard: Pinned-Dependencies).
  • Add concurrency groups to cancel superseded PR runs (the app suite costs ~8 min on runners).
  • Wire pipeline/verify_mask.py into CI as a data-integrity job when app/public/data/* or pipeline/* change (the connectivity gate from Mask: 14 of 44 harbors disconnected from open water at default safety depth (incl. Flensburg) #6/PR Mask: reconnect all harbors (2x resolution, center-sampled land, connectivity gate) #8 currently only runs manually; needs a slim venv + the committed mask, NOT a rebuild).
  • Run the OpenSSF Scorecard action + badge; work through its findings (token permissions, branch protection, dependency pinning largely covered by the other issues in this batch).
  • Consider OpenSSF Best Practices (passing level) badge once README/SECURITY/tests documentation exist.

Part of the public-readiness batch — do not implement yet.

🤖 Generated with Claude Code

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions