Use case
The repo has a security issue template, security / severity: labels, a large security audit catalog (#108–#145) and a security-first posture in AGENTS.md — but no automated security tooling at all: no CodeQL/SAST, no dependency vulnerability scanning (osv-scanner / dependency-review-action / audit step), no SBOM, and no SECURITY.md, so GitHub surfaces no disclosure policy. For a framework that parses untrusted wire frames, HOCON, and HTTP input, this is the biggest missing tool class after the linter (#417).
Proposed approach
SECURITY.md: supported versions (pre-1.0 policy), private disclosure channel, response expectations. Quick win, land first.
- CodeQL workflow (
javascript-typescript), scheduled + PR, with a triage-then-tune approach to keep noise down.
dependency-review-action on PRs + a scheduled osv-scanner run over bun.lock.
- Optional follow-up: SBOM generation on release.
Acceptance criteria
Related
Use case
The repo has a security issue template,
security/severity:labels, a large security audit catalog (#108–#145) and a security-first posture in AGENTS.md — but no automated security tooling at all: no CodeQL/SAST, no dependency vulnerability scanning (osv-scanner /dependency-review-action/ audit step), no SBOM, and noSECURITY.md, so GitHub surfaces no disclosure policy. For a framework that parses untrusted wire frames, HOCON, and HTTP input, this is the biggest missing tool class after the linter (#417).Proposed approach
SECURITY.md: supported versions (pre-1.0 policy), private disclosure channel, response expectations. Quick win, land first.javascript-typescript), scheduled + PR, with a triage-then-tune approach to keep noise down.dependency-review-actionon PRs + a scheduled osv-scanner run overbun.lock.Acceptance criteria
SECURITY.mdpresent and linked from the READMEsecurity+severity:taxonomyRelated