Decision (lemarier, Roger Ask 01M3HFKC4NY4GN7Y02X9H59MM9, answered 2026-09-27 "Do these": "1 and 2"), following the security baseline from #28.
Scope of the answer:
- Rulesets requiring checks on
main for public repositories: require the check and origin89-security jobs and block force pushes. The free plan allows rulesets on public repositories only. The Ask recommended waiting until the security workflow has run clean for a week; the answer did not change that timing.
- Triage open CodeQL alerts: fix real findings through PRs and dismiss false positives with a written reason. Open alerts at the time of the Ask: km43 36, data 10, brand 3, buddy 2, cloud 1, website 1. Checked again today: km43 36, firmware 1.
Not chosen: requiring 2FA for organization members (option 3).
State when this issue was filed: no ruleset exists on km43 or firmware, and neither repository has dismissed alerts, so nothing from this decision has been applied yet.
Done when: every public repository has an active ruleset on main requiring those checks with force pushes blocked, and every open CodeQL alert is fixed by a merged PR or dismissed with a reason.
Decision (lemarier, Roger Ask
01M3HFKC4NY4GN7Y02X9H59MM9, answered 2026-09-27 "Do these": "1 and 2"), following the security baseline from #28.Scope of the answer:
mainfor public repositories: require thecheckandorigin89-securityjobs and block force pushes. The free plan allows rulesets on public repositories only. The Ask recommended waiting until the security workflow has run clean for a week; the answer did not change that timing.Not chosen: requiring 2FA for organization members (option 3).
State when this issue was filed: no ruleset exists on km43 or firmware, and neither repository has dismissed alerts, so nothing from this decision has been applied yet.
Done when: every public repository has an active ruleset on
mainrequiring those checks with force pushes blocked, and every open CodeQL alert is fixed by a merged PR or dismissed with a reason.