Skip to content

ci(security): add CodeQL scanning - #39

Closed
0xnavarro wants to merge 2 commits into
mainfrom
ci/codeql-security-scan-final-20260920
Closed

0xnavarro wants to merge 2 commits into
mainfrom
ci/codeql-security-scan-final-20260920

Conversation

@0xnavarro

Copy link
Copy Markdown
Contributor

Public change

Add first-party GitHub CodeQL analysis for JavaScript/TypeScript on pull requests, pushes to main, and a weekly scheduled scan.

The workflow uses only GitHub-owned actions, pins every action to a full immutable commit SHA, persists no checkout credentials, and uses only contents: read + the minimal security-events: write. Build mode is none, so repository dependency scripts do not execute under CodeQL upload authority.

Validation

  • Public repository security-only change.
  • No secrets or private Brida data.
  • All actions full-SHA pinned.
  • Compatible with repository Actions allowlist.
  • pnpm check: PASS (23/23 SDK/release tests + 8/8 policy tests).
  • Workflow YAML parse: PASS.
  • Full-history leak scan: PASS.
  • npm pack --dry-run: PASS, 7 intended files.
  • Dependency audit: no known vulnerabilities.

Compatibility / risk

No runtime/API/registry behavior changes. After the check runs successfully on this exact head, CodeQL (JavaScript/TypeScript) will be added to required main checks.

Release intent

  • release-impact: none
  • release-note: Add CodeQL static analysis to the public SDK security gates.
  • qa-scope: CodeQL JavaScript/TypeScript analysis plus all existing required public CI checks.

@0xnavarro 0xnavarro closed this Sep 21, 2026
@0xnavarro 0xnavarro reopened this Sep 21, 2026
@0xnavarro 0xnavarro closed this Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant