Skip to content

hookified - chore: defense - record repository lockdown and completed manuals - #195

Merged
jaredwray merged 4 commits into
mainfrom
cursor/defense-lockdown-record-96ce
Aug 20, 2026
Merged

hookified - chore: defense - record repository lockdown and completed manuals#195
jaredwray merged 4 commits into
mainfrom
cursor/defense-lockdown-record-96ce

Conversation

@jaredwray

@jaredwray jaredwray commented Aug 20, 2026

Copy link
Copy Markdown
Owner

Summary

Record a passing lockdown-repo.sh apply/--check (section 7), including immutable GitHub Releases, plus the maintainer-confirmed npm / account manuals. List the matching live controls in SECURITY.md.

Status update: DEFENSE_IN_DEPTH.md: lockdown (including immutable releases) → (PR #195 pending); npm stage-only / Drydock / 2FA / passkeys / recovery codes → verified (maintainer); Aikido release gate → PR #194. Catalog has no remaining unchecked items.

Changes

  • Check off § 7 lockdown from the maintainer apply/--check with --required-checks "test,zizmor" and --allowed-actions "codecov/*,cloudflare/*".
  • Record immutable GitHub Releases (enabled in the apply run: "enabled immutable releases").
  • Check off § 5 manuals: stage-only OIDC trusted publishing, 2FA promotion, Drydock, 2FA + disallow tokens.
  • Check off § 7 manuals: phishing-resistant 2FA (passkeys) and offline recovery codes (maintainer-confirmed earlier; the script still prints them as leftovers).
  • Add SECURITY.md bullets for required PRs/status checks, admin-only tags, immutable releases, fork-PR approval, the Actions allowlist, and staged npm publishing.

Verification

  • Maintainer apply reported immutable releases enabled and the rest of the GitHub settings written
  • Confirmed rulesets Pull requests required and Tags only by admins are active on the repo
  • Maintainer confirmed the remaining (manual) catalog items are complete

Reference: defense-in-depth-nodejs § 5–7

Please check if the PR fulfills these requirements

  • Followed the Contributing and Code of Conduct guidelines.
  • Tests for the changes have been added (for bug fixes/features) with 100% code coverage.

What kind of change does this PR introduce? (Bug fix, feature, docs update, ...)
docs / security

Open in Web Open in Cursor 

cursoragent and others added 2 commits August 20, 2026 15:40
Record a passing lockdown-repo.sh --check on jaredwray/hookified and add
the matching live GitHub settings to SECURITY.md. Do not claim immutable
releases or npm stage-only publishing; those were not in the audit output.

Co-authored-by: Jared Wray <me@jaredwray.com>
Co-authored-by: Jared Wray <me@jaredwray.com>
@codecov

codecov Bot commented Aug 20, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (7a23b9e) to head (0930d7d).

Additional details and impacted files
@@            Coverage Diff            @@
##              main      #195   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files            5         5           
  Lines          433       433           
  Branches       109       109           
=========================================
  Hits           433       433           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@jaredwray
jaredwray marked this pull request as ready for review August 20, 2026 15:42
Check off maintainer-confirmed stage-only OIDC, Drydock, 2FA publish
settings, passkeys, and recovery codes. Add the live npm staging
summary to SECURITY.md.

Co-authored-by: Jared Wray <me@jaredwray.com>
@cursor cursor Bot changed the title hookified - chore: defense - record repository lockdown hookified - chore: defense - record repository lockdown and completed manuals Aug 20, 2026
The maintainer apply run enabled immutable releases. Match that in the
catalog and SECURITY.md summary.

Co-authored-by: Jared Wray <me@jaredwray.com>
@jaredwray
jaredwray merged commit 1d463a6 into main Aug 20, 2026
16 checks passed
@jaredwray
jaredwray deleted the cursor/defense-lockdown-record-96ce branch August 20, 2026 15:54
@jaredwray jaredwray mentioned this pull request Aug 20, 2026
4 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants