Skip to content

chore(security): hardening pass — SECURITY.md, dependabot, pin actions#4

Merged
Taure merged 1 commit intomainfrom
chore/security-hardening
Apr 14, 2026
Merged

chore(security): hardening pass — SECURITY.md, dependabot, pin actions#4
Taure merged 1 commit intomainfrom
chore/security-hardening

Conversation

@Taure
Copy link
Copy Markdown
Contributor

@Taure Taure commented Apr 14, 2026

Same hardening pattern as widgrensit/asobi#66 and widgrensit/asobi_lua#5. Addresses cross-cutting security review (2026-04-14).

- Add SECURITY.md with private vulnerability reporting policy
- Add dependabot.yml for GitHub Actions and Go modules
- Pin actions/checkout and actions/setup-go to SHA (was @v4/@v5)

Addresses cross-cutting security review (2026-04-14).
LICENSE already present.
@Taure Taure merged commit 6bf6214 into main Apr 14, 2026
1 check passed
@Taure Taure deleted the chore/security-hardening branch April 14, 2026 20:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant