Skip to content

ci: add CodeQL, Dependabot, and dependency review#3

Closed
microsasa wants to merge 0 commit intomainfrom
ci/security-workflows
Closed

ci: add CodeQL, Dependabot, and dependency review#3
microsasa wants to merge 0 commit intomainfrom
ci/security-workflows

Conversation

@microsasa
Copy link
Owner

@microsasa microsasa commented Mar 13, 2026

Enable free GitHub security features:

  • CodeQL: code scanning on PRs + weekly Monday schedule
  • Dependabot alerts: vulnerability notifications (enabled via API)
  • Dependabot security updates: auto-PRs for vulnerable deps (enabled via API)

Note: Dependency review action requires GHAS (paid) for private repos — not included.

Closes #4

@microsasa microsasa force-pushed the ci/security-workflows branch 3 times, most recently from 315494a to 0f66fa1 Compare March 13, 2026 23:11
@microsasa microsasa closed this Mar 13, 2026
@microsasa microsasa force-pushed the ci/security-workflows branch from 0f66fa1 to f9c5834 Compare March 13, 2026 23:25
@microsasa microsasa deleted the ci/security-workflows branch March 13, 2026 23:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci: enable free GitHub security features

1 participant