Skip to content

Add security baseline: permissions, secret handling, dependency scanning, and branch protections #324

Description

@labgadget015-dotcom

Roadmap item 7/10 · Workstream: Security · Risk: High · Approval required: Yes · Target milestone: M1 — Stabilise control plane

Objective

Establish a verifiable minimum security posture for the repository and its automation: least-privilege workflow permissions, secrets that never reach logs or public artefacts, continuous dependency scanning, and enforced branch protection on main.

Non-goals

  • Rotating existing secrets (separate, human-approved change)
  • Org-wide policy
  • Pen-testing

Acceptance criteria

  • Every workflow declares top-level permissions: with the minimum needed; default contents: read
  • Third-party actions pinned (major at minimum, SHA for anything with write scopes); all actions on a supported Node runtime
  • Secret scanning + push protection on; a CI check fails on committed secrets; logs/step summaries/artefacts carry no secret values (repo is public)
  • Dependency scanning (Dependabot alerts + pip-audit or equivalent) with a documented triage SLA by severity
  • Branch protection on main: required status checks, PR review, no force push, no deletion
  • Inventory of secrets (names, owners, expiry dates, rotation procedure) — names only, never values

Dependencies

  • Admin access for branch protection (human)

Risk

High — permission tightening can break workflows; each change must be verified on a real run.

Test evidence required

  • Workflow permissions audit table (workflow → permissions) before/after
  • Green runs of every modified workflow
  • Screenshot or API output of branch protection settings
  • Deliberate test secret blocked by push protection

Definition of done

  • Baseline merged and enforced
  • SECURITY.md updated with the baseline and triage SLA
  • Expiry dates (GitHub PAT 2027-05-07, n8n API key) tracked with reminders
  • Evidence URL and Correlation ID recorded on the project item

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitySecurity vulnerability or concern

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions