ci: add code scanning and require code owners - #9
Conversation
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
furkanerday
left a comment
There was a problem hiding this comment.
Reviewed the complete diff, description, commit history, checks, discussion, repository policy, relevant contracts, tests, dependency and release integrity, licensing, and public-safety implications. Required checks are green and no actionable review threads remain.
furkanerday
left a comment
There was a problem hiding this comment.
Human-authored commits 1566abd, d02ad62, 23b67d5 lack author-matching Signed-off-by trailers. Each author must amend their own affected commit and re-push it; a later maintainer commit cannot cure an earlier contributor commit. Re-request review after the rewritten commit history and required checks complete.
Summary
Security Design
Validation
git diff --checkpassesNote
Add CodeQL scanning, OpenSSF Scorecard, and CODEOWNERS to the repository
mainand on a weekly schedule, reporting results to GitHub code scanning.mainand weekly, publishing SARIF results to GitHub code scanning and retaining them as artifacts for 5 days.@kriptoburakand@furkanerday.Macroscope summarized 23b67d5.