Goal
Enable defense-in-depth repository controls for vulnerable dependencies, committed secrets, and static code-scanning findings.
Background
Live repository settings on 2026-08-30 report dependabot_security_updates disabled and secret scanning, non-provider patterns, push protection, and validity checks disabled. The code-scanning alerts endpoint reports that no analysis exists.
The repository's Ruff, Bandit, pip-audit, redaction, and threat-model gates are valuable, but they do not prevent a credential from being pushed, open reviewed security-update pull requests, or provide CodeQL-style cross-file analysis.
Scope
- Enable the dependency graph, Dependabot alerts/security updates, and a reviewed update policy.
- Enable secret scanning, push protection, validity checks, and supported non-provider patterns.
- Enable CodeQL default or advanced setup for the supported Python surface.
- Make actionable security checks required on protected
main.
- Document triage, false-positive dismissal, SLA, and emergency response ownership.
- Record any organization/plan control that cannot be enabled and its compensating control.
Acceptance Criteria
- Repository settings read back the intended dependency, secret, and code-scanning features as enabled.
- A safe test secret pattern is blocked or detected in a documented rehearsal.
- Code scanning produces a successful analysis for
main and pull requests.
- Dependabot security updates open a reviewed PR when a test fixture/rehearsal dependency is vulnerable, or equivalent evidence proves configuration.
- Security checks are required by branch protection and cannot be silently skipped on release-source changes.
- Dismissals require reason, reviewer, and audit trail; ownership and remediation SLAs are documented.
- Existing Bandit and
pip-audit gates remain in place and are not treated as substitutes for repository controls.
Validation
Read back GitHub security settings and branch protection; inspect the first successful code-scanning run; execute safe secret/dependency rehearsal cases; verify alert and dismissal workflows.
Non-Goals
- Do not commit a real credential or known exploitable production dependency.
- Do not replace the runtime threat model, trusted publishing, or artifact attestations.
Dependencies
Project Fields
- Status: Backlog
- Priority: P1
- Area: Security
- Initiative: v1.0 Readiness
- Size: M
Ownership
Goal
Enable defense-in-depth repository controls for vulnerable dependencies, committed secrets, and static code-scanning findings.
Background
Live repository settings on 2026-08-30 report
dependabot_security_updatesdisabled and secret scanning, non-provider patterns, push protection, and validity checks disabled. The code-scanning alerts endpoint reports that no analysis exists.The repository's Ruff, Bandit,
pip-audit, redaction, and threat-model gates are valuable, but they do not prevent a credential from being pushed, open reviewed security-update pull requests, or provide CodeQL-style cross-file analysis.Scope
main.Acceptance Criteria
mainand pull requests.pip-auditgates remain in place and are not treated as substitutes for repository controls.Validation
Read back GitHub security settings and branch protection; inspect the first successful code-scanning run; execute safe secret/dependency rehearsal cases; verify alert and dismissal workflows.
Non-Goals
Dependencies
Project Fields
Ownership