Skip to content

Apply the chosen security follow-ups: required-check rulesets and CodeQL triage #33

Description

@lemarier

Decision (lemarier, Roger Ask 01M3HFKC4NY4GN7Y02X9H59MM9, answered 2026-09-27 "Do these": "1 and 2"), following the security baseline from #28.

Scope of the answer:

  1. Rulesets requiring checks on main for public repositories: require the check and origin89-security jobs and block force pushes. The free plan allows rulesets on public repositories only. The Ask recommended waiting until the security workflow has run clean for a week; the answer did not change that timing.
  2. Triage open CodeQL alerts: fix real findings through PRs and dismiss false positives with a written reason. Open alerts at the time of the Ask: km43 36, data 10, brand 3, buddy 2, cloud 1, website 1. Checked again today: km43 36, firmware 1.

Not chosen: requiring 2FA for organization members (option 3).

State when this issue was filed: no ruleset exists on km43 or firmware, and neither repository has dismissed alerts, so nothing from this decision has been applied yet.

Done when: every public repository has an active ruleset on main requiring those checks with force pushes blocked, and every open CodeQL alert is fixed by a merged PR or dismissed with a reason.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions