Skip to content

Add a security policy and harden the CI workflows - #1190

Merged
petergoldstein merged 2 commits into
mainfrom
security/harden-workflows-and-policy
Oct 4, 2026
Merged

petergoldstein merged 2 commits into
mainfrom
security/harden-workflows-and-policy

Conversation

@petergoldstein

Copy link
Copy Markdown
Owner

The first part of section 1 of the new security hardening plan (docs/security-hardening-plan.md, added here).

Changes

  • SECURITY.md: supported release lines, how to report a vulnerability through GitHub's private vulnerability reporting (already enabled), what happens after a report, and what's in scope.

  • docs/security-hardening-plan.md: the overall plan:

    1. repository and release hardening
    2. a code audit by attack surface
    3. property tests and fuzzing for the bug classes behind GHSA-6wmv-xq9m-fmp7 and Fix multi-server get_multi stopping at an empty value #1170
    4. ongoing process

    Section 2 names areas to audit, not specific suspected weaknesses. Those stay private until they've been checked.

  • Least-privilege workflow tokens: every workflow now has a top-level permissions: contents: read. The test, RuboCop, benchmark and profile jobs only need to read the repo. release.yml keeps its contents: write, and CodeQL keeps its job-level security-events: write.

  • Actions pinned by commit SHA, each with its version as a comment. Dependabot's weekly github-actions updates will keep the pins current:

    • actions/checkout v7.0.1
    • ruby/setup-ruby v1.327.0
    • github/codeql-action v4.38.2
    • actions/upload-artifact v7.0.1

For review

The supported versions table in SECURITY.md is a policy decision. It lists 5.2, 5.1, 5.0, 4.3 and 3.2, matching the lines that received fixes this month. Adjust as needed. The policy deliberately promises no response times.

Not in this PR

These are repository settings, not files:

  • branch protection on main and the stable branches
  • secret scanning and push protection

🤖 Generated with Claude Code

petergoldstein and others added 2 commits October 4, 2026 18:33
- SECURITY.md: supported release lines, how to report a vulnerability
  privately, and what happens after a report
- docs/security-hardening-plan.md: the plan for finding latent
  vulnerabilities after GHSA-6wmv-xq9m-fmp7 and #1170
- Give every workflow a top-level least-privilege token
  (permissions: contents: read); release.yml and CodeQL keep their wider,
  explicit permissions
- Pin third-party actions by commit SHA; Dependabot's github-actions
  updates keep the pins current

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@petergoldstein
petergoldstein merged commit b3579c6 into main Oct 4, 2026
31 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant