memcache - chore: defense - scaffold security docs - #105
Conversation
Replace the public security policy with private-disclosure reporting and add the defense-in-depth checklist, reconciling items already true in this repo. Co-authored-by: Jared Wray <me@jaredwray.com>
Co-authored-by: Jared Wray <me@jaredwray.com>
Co-authored-by: Jared Wray <me@jaredwray.com>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #105 +/- ##
=========================================
Coverage 100.00% 100.00%
=========================================
Files 8 8
Lines 1399 1399
Branches 303 308 +5
=========================================
Hits 1399 1399 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7bba6c59d8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| - [ ] `SECURITY.md` present — contact info + "How this repository is secured" summary (PR #105 pending) | ||
| - [ ] `DEFENSE_IN_DEPTH.md` present (this file) (PR #105 pending) |
There was a problem hiding this comment.
Mark the newly added security documents as present
When this commit lands, both checklist requirements are already satisfied by this same diff, but they remain unchecked and permanently labeled “PR #105 pending.” Because this file is presented as the repository's security-progress tracker, the merged document will incorrectly report that its own security policy and checklist are missing; mark these entries complete rather than recording transient PR state.
Useful? React with 👍 / 👎.
* chore: defense - add CODEOWNERS for high-risk paths Require @jaredwray review on /.github/, /.cursor/, /.devcontainer/, and /scripts/. Reconcile § 1 security docs as merged in PR #105. Co-authored-by: Jared Wray <me@jaredwray.com> * chore: defense - record PR #106 on CODEOWNERS checklist Co-authored-by: Jared Wray <me@jaredwray.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Summary
Scaffold the public security policy and the defense-in-depth checklist so this repo can be hardened one item at a time against the latest catalog.
Status update
DEFENSE_IN_DEPTH.md: § 1 Security docs → (PR #105 pending)Reconciled already-true items (no matching PR):
packageManagerpin (pnpm@11.5.2), no Dependabot config, workflowpermissions: contents: read, nopull_request_target, accuraterepository.url, Aikido GitHub app on builds, Socket GitHub app on PRs. Existing pnpm cooldown is 2 days (2880), not the catalog's 7-day baseline — that stays unchecked for a later PR.Changes
SECURITY.mdwith private-disclosure reporting plus a "How this repository is secured" summary (no control bullets until those sections land).DEFENSE_IN_DEPTH.mdfrom the current catalog (Profile: npm library · public).Verification
SECURITY.mdandDEFENSE_IN_DEPTH.mdpresent and internally linkedReference
defense-in-depth-nodejs § 1