docs: cite org-security and tag-validation references#73
Conversation
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
Adds two previously orphaned reference files to the References table: org-security-settings.md (SHA pinning) and tag-validation.md (defense-in-depth). The reusable-workflow-security reference is already cited upstream. Signed-off-by: Sebastian Mendel <github@sebastianmendel.de>
21e79d6 to
72a920e
Compare
There was a problem hiding this comment.
Code Review
This pull request updates the SKILL.md file by adding two new entries to the references table: one for organization-level security settings regarding SHA pinning and another for tag validation as a defense-in-depth measure. I have no feedback to provide as there were no review comments.
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
There was a problem hiding this comment.
Pull request overview
Updates the GitHub Project skill documentation to include two existing but previously uncited reference documents in the SKILL.md “References” table, improving discoverability of security guidance.
Changes:
- Add a reference entry for
references/org-security-settings.md(org-level security / SHA pinning). - Add a reference entry for
references/tag-validation.md(tag validation / defense-in-depth).
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Signed-off-by: Sebastian Mendel <github@sebastianmendel.de>
41e07f8 to
11d8b86
Compare
|



Summary
Adds two previously orphaned reference files to the References table:
org-security-settings.md(SHA pinning) andtag-validation.md(defense-in-depth). Thereusable-workflow-securityreference is already cited upstream.Test plan