Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion DEFENSE_IN_DEPTH.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ Profile: npm library · public

## 6. Security tooling
- [x] Aikido runs on every build — verified 2026-09-09 (PR #65: Aikido Security: check code)
- [ ] Aikido release gate: the release workflow's stage-publish job `needs:` a passing `scan-release` (PR #75 pending)
- [x] Aikido release gate: the release workflow's stage-publish job `needs:` a passing `scan-release` — PR #75
- [ ] Socket reviews every PR that changes dependencies

## 7. Repository lockdown
Expand Down
2 changes: 1 addition & 1 deletion SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@ hardening checklist; progress is tracked in [DEFENSE_IN_DEPTH.md](./DEFENSE_IN_D
- `.github/CODEOWNERS` names `@jaredwray` for `/.github/`, `/.vscode/`, `/.cursor/`, `/.devcontainer/`, and `/scripts/`.
- Codespaces and Cursor Cloud Agents install through Aikido Safe Chain; package-manager shims must not be bypassed.
- The Codespaces Dev Container image is pinned by digest (`name:<tag>@sha256:<digest>`), not a floating tag.
- Aikido scans every build.
- Aikido scans every build. Stage-publish is gated on a passing Aikido `scan-release` job.