Skip to content

Enforce workflow and dependency security controls #58

Description

@stefan-jansen

Findings: BR-024, BR-031.

Pin third-party workflow actions to reviewed commit hashes and require dependency-vulnerability and
source-security results under a documented severity and exception policy.

Primary surfaces: GitHub workflows, dependency automation, security configuration, retained
release evidence.

Acceptance:

  • Every third-party action is pinned to a full commit hash.
  • Every release records dependency and source scan inputs and outputs.
  • Findings at or above the documented threshold block release unless a named, expiring exception
    is reviewed and visible.

Dependencies: Issue 13.


Plan reference: /home/stefan/ml4t/libraries/ml4t-backtest-dev/.workspace/work/backtest-stable-release/milestone-3/plan.md - Issue 18 in milestone 0.1.0-m3 - Compatibility and release enforcement.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions