ci: harden PR security pipeline (#10)

Add comprehensive security scanning to CI/CD pipeline including CodeQL, Gitleaks, Semgrep custom rules, dependency review, and lifecycle script checks
This commit is contained in:
Patrick Wozniak
2026-05-28 23:58:50 +02:00
committed by GitHub
parent 17175abd28
commit 21d712a1cc
5 changed files with 492 additions and 0 deletions
+21
View File
@@ -0,0 +1,21 @@
# Code ownership for security-sensitive paths
# These files require maintainer review on every PR
# Security-critical: auth, secrets, OAuth flow
/src/auth-server.ts @patlux
/src/oauth.ts @patlux
/src/converters.ts @patlux
# CI/CD pipeline
.github/workflows/ @patlux
# Dependencies
package.json @patlux
package-lock.json @patlux
# Security tooling
.semgrep/ @patlux
.gitleaks.toml @patlux
# This file itself
.github/CODEOWNERS @patlux