Skip to content

v1.7.0: supply-chain hardening and security policy

Latest

Choose a tag to compare

@albertoarena albertoarena released this 05 Aug 18:36
· 17 commits to main since this release

Supply-chain hardening and tooling. No change to the shipped package.

Added

  • A SECURITY.md security policy that documents a private disclosure channel and the reporting scope, so a vulnerability can be reported privately instead of through a public issue.

Changed

  • The frontend test suites now run in CI. A new workflow installs Node, runs the Vitest unit tests, and runs the Playwright browser tests on every push and pull request, so client-side changes and dependency bumps are exercised automatically rather than relying on a local run.
  • The development test runner (Vitest) was upgraded to 4.x. Test tooling only, with no change to the shipped package.

Security

  • Every GitHub Actions reference in CI is now pinned to a full commit SHA with a trailing version comment, so a moved or compromised tag can no longer redirect a workflow to unintended code.
  • Added a Dependabot configuration covering GitHub Actions, Composer, and npm, on a weekly schedule with a seven-day cooldown, so dependency and action updates arrive as reviewable pull requests and the pinned SHAs stay current.