Maturity context
- Project maturity: operational (66/100)
- Dimension:
security_configuration
- Priority: high
Evidence
- SECURITY.md instructs reporters to use GitHub private vulnerability reporting when available
- GitHub reports private vulnerability reporting disabled
- GitHub reports secret scanning, push protection, and Dependabot security updates disabled
- The extension resolves GitHub credentials and performs privileged mutations
Scope
- Enable private vulnerability reporting.
- Enable available secret scanning, non-provider pattern scanning, validity checks, and push protection.
- Enable Dependabot security updates or document an equivalent alert/update SLA.
- Assign maintainers and document alert triage, false-positive handling, and credential-rotation escalation.
Acceptance criteria
- The Security page exposes a private report flow.
- GitHub API metadata reports the selected scanning and update controls enabled.
- SECURITY.md names the configured private route and current support scope.
- A documented process identifies an owner and response target for secret or dependency alerts.
Help wanted
Settings require organization/repository admin access; policy updates can be reviewed independently.
Generated from the repository maturity assessment dated 2026-07-11. Do not include credentials, customer data, or local-only files in public discussion.
Maturity context
security_configurationEvidence
Scope
Acceptance criteria
Help wanted
Settings require organization/repository admin access; policy updates can be reviewed independently.
Generated from the repository maturity assessment dated 2026-07-11. Do not include credentials, customer data, or local-only files in public discussion.