Roadmap item 7/10 · Workstream: Security · Risk: High · Approval required: Yes · Target milestone: M1 — Stabilise control plane
Objective
Establish a verifiable minimum security posture for the repository and its automation: least-privilege workflow permissions, secrets that never reach logs or public artefacts, continuous dependency scanning, and enforced branch protection on main.
Non-goals
- Rotating existing secrets (separate, human-approved change)
- Org-wide policy
- Pen-testing
Acceptance criteria
Dependencies
- Admin access for branch protection (human)
Risk
High — permission tightening can break workflows; each change must be verified on a real run.
Test evidence required
- Workflow permissions audit table (workflow → permissions) before/after
- Green runs of every modified workflow
- Screenshot or API output of branch protection settings
- Deliberate test secret blocked by push protection
Definition of done
Objective
Establish a verifiable minimum security posture for the repository and its automation: least-privilege workflow permissions, secrets that never reach logs or public artefacts, continuous dependency scanning, and enforced branch protection on
main.Non-goals
Acceptance criteria
permissions:with the minimum needed; defaultcontents: readpip-auditor equivalent) with a documented triage SLA by severitymain: required status checks, PR review, no force push, no deletionDependencies
Risk
High — permission tightening can break workflows; each change must be verified on a real run.
Test evidence required
Definition of done
SECURITY.mdupdated with the baseline and triage SLA