Skip to content

chore: apply supply chain security defaults#36

Merged
CallMeGreg merged 4 commits into
mainfrom
copilot/update-supply-chain-security-defaults
May 20, 2026
Merged

chore: apply supply chain security defaults#36
CallMeGreg merged 4 commits into
mainfrom
copilot/update-supply-chain-security-defaults

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented May 20, 2026

Description

Applies supply chain security hardening defaults: Dependabot version-update cooldowns and a human-review flag on the release workflow's broad permissions.

dependabot.yml

  • Added cooldown.default-days: 3 to the existing github-actions entry

Already satisfied / not applicable

  • go.mod + go.sum checked in; no writable module commands in CI
  • All Actions pinned to full commit SHAs
  • No pull_request_target usage
  • No npm/Python/Ruby ecosystems present

Release Type

  • Major - Breaking changes
  • Minor - New features, backwards compatible
  • Patch - Bug fixes, backwards compatible

@CallMeGreg CallMeGreg marked this pull request as ready for review May 20, 2026 19:39
@CallMeGreg CallMeGreg merged commit 1d2e8f3 into main May 20, 2026
5 checks passed
@CallMeGreg CallMeGreg deleted the copilot/update-supply-chain-security-defaults branch May 20, 2026 19:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants