Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 7 additions & 1 deletion .github/workflows/code-coverage.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,12 @@ jobs:
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Install Socket Firewall
uses: SocketDev/action@ba6de6cc0565af1f42295590380973573297e31f # v1.3.2
with:
mode: firewall-free
firewall-version: "1.15.1"

- name: Install pnpm
uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0

Expand All @@ -32,7 +38,7 @@ jobs:
cache: 'pnpm'

- name: Install Dependencies
run: pnpm install --frozen-lockfile
run: sfw pnpm install --frozen-lockfile

- name: Build
run: pnpm build
Expand Down
8 changes: 7 additions & 1 deletion .github/workflows/release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,12 @@ jobs:
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Install Socket Firewall
uses: SocketDev/action@ba6de6cc0565af1f42295590380973573297e31f # v1.3.2
with:
mode: firewall-free
firewall-version: "1.15.1"

- name: Install pnpm
uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0

Expand All @@ -31,7 +37,7 @@ jobs:
registry-url: 'https://registry.npmjs.org'

- name: Install Dependencies
run: pnpm install --frozen-lockfile
run: sfw pnpm install --frozen-lockfile

- name: Build
run: pnpm build
Expand Down
8 changes: 7 additions & 1 deletion .github/workflows/tests.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,12 @@ jobs:
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Install Socket Firewall
uses: SocketDev/action@ba6de6cc0565af1f42295590380973573297e31f # v1.3.2
with:
mode: firewall-free
firewall-version: "1.15.1"

- name: Install pnpm
uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0

Expand All @@ -36,7 +42,7 @@ jobs:
cache: 'pnpm'

- name: Install Dependencies
run: pnpm install --frozen-lockfile
run: sfw pnpm install --frozen-lockfile

- name: Build
run: pnpm build
Expand Down
4 changes: 2 additions & 2 deletions DEFENSE_IN_DEPTH.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,8 +25,8 @@ Profile: npm library · public
## 4. GitHub Actions
- [x] `permissions: contents: read` (or `{}` + per-job grants) on every workflow — verified 2026-09-09
- [x] No `contents: write` except jobs whose purpose is mutating the repo (GitHub Release, Changesets version PR); generated output is a workflow artifact, never committed back from CI — verified 2026-09-09
- [ ] Every action pinned to a full commit SHA (`npx actions-up`) (PR #69 pending)
- [ ] Every job installs Socket Firewall (`SocketDev/action` SHA-pinned, `firewall-version` pinned); `pnpm install` / `npm install` run as `sfw pnpm install` / `sfw npm install`
- [x] Every action pinned to a full commit SHA (`npx actions-up`) — PR #69
- [ ] Every job installs Socket Firewall (`SocketDev/action` SHA-pinned, `firewall-version` pinned); `pnpm install` / `npm install` run as `sfw pnpm install` / `sfw npm install` (PR #70 pending)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Since this pull request implements the Socket Firewall integration (as described in the PR title and summary), this checklist item should be marked as completed ([x]) and the (PR pending) suffix should be removed.

Suggested change
- [ ] Every job installs Socket Firewall (`SocketDev/action` SHA-pinned, `firewall-version` pinned); `pnpm install` / `npm install` run as `sfw pnpm install` / `sfw npm install` (PR #70 pending)
- [x] Every job installs Socket Firewall (`SocketDev/action` SHA-pinned, `firewall-version` pinned); `pnpm install` / `npm install` run as `sfw pnpm install` / `sfw npm install`

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Leaving this unchecked with (PR #70 pending) on purpose. security-status-tracking only flips an item to - [x] … — PR #n after that PR merges. Checking it off here would claim Socket Firewall is on main before it is.

- [ ] `.github/workflows/check-workflows.yaml` lints workflows with zizmor on every PR
- [x] Workflow `name:` and job `name:` contain no spaces (kebab-case) so they can be set as required status checks — verified 2026-09-09
- [ ] `persist-credentials: false` on checkouts that don't push
Expand Down
2 changes: 1 addition & 1 deletion SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ hardening checklist; progress is tracked in [DEFENSE_IN_DEPTH.md](./DEFENSE_IN_D
- pnpm is pinned via `packageManager` (`pnpm@12.3.0`).
- Dependencies install through pnpm with a 7-day cooldown on new versions, lifecycle scripts blocked by default, `trustPolicy: no-downgrade`, and exotic subdependencies blocked.
- The lockfile is committed and CI installs with `--frozen-lockfile`. There is no Dependabot config; dependency updates go through reviewed PRs.
- CI workflows default to read-only `contents: read` permissions; generated output is never committed back from CI.
- CI workflows default to read-only `contents: read` permissions; generated output is never committed back from CI; every action is pinned to a full commit SHA.
- Workflows do not use `pull_request_target`.
- The published package sets `repository.url` to this repo so provenance can map back.
- `.github/CODEOWNERS` names `@jaredwray` for `/.github/`, `/.vscode/`, `/.cursor/`, `/.devcontainer/`, and `/scripts/`.
Expand Down