Skip to content

Harden repo settings and add community health files#46

Merged
mchmarny merged 2 commits intomainfrom
harden/repo-settings
Mar 2, 2026
Merged

Harden repo settings and add community health files#46
mchmarny merged 2 commits intomainfrom
harden/repo-settings

Conversation

@mchmarny
Copy link
Owner

@mchmarny mchmarny commented Mar 2, 2026

Summary

  • Pin self-referencing action to SHA in reputation workflow (fixes Scorecard pinned-dependencies alert)
  • Add CODEOWNERS (@mchmarny for all files)
  • Add issue templates (bug report, feature request) and PR template
  • Repo API settings already applied: enforce_admins, dismiss_stale_reviews, require_code_owner_reviews, private vulnerability reporting, secret scanning enhancements, restricted actions

Test plan

  • CI passes
  • Community health score improves from 71%
  • Scorecard pinned-dependencies alert resolves

- Pin self-referencing action to SHA in reputation workflow
- Add CODEOWNERS, issue templates, and PR template
- API: enable enforce_admins, dismiss_stale_reviews,
  require_code_owner_reviews, private vulnerability reporting,
  secret scanning non-provider patterns and validity checks,
  restrict actions to verified/selected
@github-actions
Copy link

github-actions bot commented Mar 2, 2026

Contributor Reputation

🟡 Score: 67.0%

Metric Value
Author Association NONE
Account Age 5,902 days
Verified Commits 84/121
PRs Merged NaN
PRs Closed NaN
Public Repos 158
Forked Repos NaN
Followers 279
Recent PR Repos NaN

Powered by reputer

@mchmarny mchmarny self-assigned this Mar 2, 2026
@github-actions
Copy link

github-actions bot commented Mar 2, 2026

Contributor Reputation

🟡 Score: 67.0%

Metric Value
Author Association NONE
Account Age 5,902 days
Verified Commits 84/121
PRs Merged NaN
PRs Closed NaN
Public Repos 158
Forked Repos NaN
Followers 279
Recent PR Repos NaN

Powered by reputer

@mchmarny mchmarny enabled auto-merge (squash) March 2, 2026 21:46
@mchmarny mchmarny merged commit b2047a8 into main Mar 2, 2026
6 checks passed
@mchmarny mchmarny deleted the harden/repo-settings branch March 2, 2026 21:47
@mchmarny mchmarny restored the harden/repo-settings branch March 6, 2026 00:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant