Skip to content

[Feature] Security scanning: CodeQL, dependency review/OSV, SECURITY.md #539

Description

@pathosDev

Use case

The repo has a security issue template, security / severity: labels, a large security audit catalog (#108–#145) and a security-first posture in AGENTS.md — but no automated security tooling at all: no CodeQL/SAST, no dependency vulnerability scanning (osv-scanner / dependency-review-action / audit step), no SBOM, and no SECURITY.md, so GitHub surfaces no disclosure policy. For a framework that parses untrusted wire frames, HOCON, and HTTP input, this is the biggest missing tool class after the linter (#417).

Proposed approach

  • SECURITY.md: supported versions (pre-1.0 policy), private disclosure channel, response expectations. Quick win, land first.
  • CodeQL workflow (javascript-typescript), scheduled + PR, with a triage-then-tune approach to keep noise down.
  • dependency-review-action on PRs + a scheduled osv-scanner run over bun.lock.
  • Optional follow-up: SBOM generation on release.

Acceptance criteria

  • SECURITY.md present and linked from the README
  • CodeQL running on PRs + schedule with a triaged baseline (no open untriaged alerts)
  • Dependency review / OSV scanning wired and documented
  • New findings get filed with the existing security + severity: taxonomy

Related

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestinfrastructureCI / build / live-integration testspriority: highTop priority — high impact, plan nextproduction-goalBlocks or defines the path to production readinesssecuritySecurity-relevant — see severity label for impact tier

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions