Add a security policy and harden the CI workflows - #1190
Merged
Merged
Conversation
- SECURITY.md: supported release lines, how to report a vulnerability privately, and what happens after a report - docs/security-hardening-plan.md: the plan for finding latent vulnerabilities after GHSA-6wmv-xq9m-fmp7 and #1170 - Give every workflow a top-level least-privilege token (permissions: contents: read); release.yml and CodeQL keep their wider, explicit permissions - Pin third-party actions by commit SHA; Dependabot's github-actions updates keep the pins current Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The first part of section 1 of the new security hardening plan (
docs/security-hardening-plan.md, added here).Changes
SECURITY.md: supported release lines, how to report a vulnerability through GitHub's private vulnerability reporting (already enabled), what happens after a report, and what's in scope.docs/security-hardening-plan.md: the overall plan:Section 2 names areas to audit, not specific suspected weaknesses. Those stay private until they've been checked.
Least-privilege workflow tokens: every workflow now has a top-level
permissions: contents: read. The test, RuboCop, benchmark and profile jobs only need to read the repo.release.ymlkeeps itscontents: write, and CodeQL keeps its job-levelsecurity-events: write.Actions pinned by commit SHA, each with its version as a comment. Dependabot's weekly
github-actionsupdates will keep the pins current:actions/checkoutv7.0.1ruby/setup-rubyv1.327.0github/codeql-actionv4.38.2actions/upload-artifactv7.0.1For review
The supported versions table in
SECURITY.mdis a policy decision. It lists 5.2, 5.1, 5.0, 4.3 and 3.2, matching the lines that received fixes this month. Adjust as needed. The policy deliberately promises no response times.Not in this PR
These are repository settings, not files:
mainand the stable branches🤖 Generated with Claude Code