Skip to content

Enable private vulnerability reporting, secret scanning, and dependency alert automation #39

Description

@cervantesh

Maturity context

  • Project maturity: operational (66/100)
  • Dimension: security_configuration
  • Priority: high

Evidence

  • SECURITY.md instructs reporters to use GitHub private vulnerability reporting when available
  • GitHub reports private vulnerability reporting disabled
  • GitHub reports secret scanning, push protection, and Dependabot security updates disabled
  • The extension resolves GitHub credentials and performs privileged mutations

Scope

  • Enable private vulnerability reporting.
  • Enable available secret scanning, non-provider pattern scanning, validity checks, and push protection.
  • Enable Dependabot security updates or document an equivalent alert/update SLA.
  • Assign maintainers and document alert triage, false-positive handling, and credential-rotation escalation.

Acceptance criteria

  • The Security page exposes a private report flow.
  • GitHub API metadata reports the selected scanning and update controls enabled.
  • SECURITY.md names the configured private route and current support scope.
  • A documented process identifies an owner and response target for secret or dependency alerts.

Help wanted

Settings require organization/repository admin access; policy updates can be reviewed independently.


Generated from the repository maturity assessment dated 2026-07-11. Do not include credentials, customer data, or local-only files in public discussion.

Metadata

Metadata

Assignees

No one assigned

    Labels

    help wantedCommunity or collaborator help is welcome.maturityWork derived from a repository maturity assessment.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions