ci: harden PR security pipeline (#10)
Add comprehensive security scanning to CI/CD pipeline including CodeQL, Gitleaks, Semgrep custom rules, dependency review, and lifecycle script checks
This commit is contained in:
@@ -0,0 +1,21 @@
|
||||
# Code ownership for security-sensitive paths
|
||||
# These files require maintainer review on every PR
|
||||
|
||||
# Security-critical: auth, secrets, OAuth flow
|
||||
/src/auth-server.ts @patlux
|
||||
/src/oauth.ts @patlux
|
||||
/src/converters.ts @patlux
|
||||
|
||||
# CI/CD pipeline
|
||||
.github/workflows/ @patlux
|
||||
|
||||
# Dependencies
|
||||
package.json @patlux
|
||||
package-lock.json @patlux
|
||||
|
||||
# Security tooling
|
||||
.semgrep/ @patlux
|
||||
.gitleaks.toml @patlux
|
||||
|
||||
# This file itself
|
||||
.github/CODEOWNERS @patlux
|
||||
Reference in New Issue
Block a user