Skip to content

Commit 50826ac

Browse files
committed
docs(changelog): add unreleased security hardening entries
1 parent 7b10af4 commit 50826ac

1 file changed

Lines changed: 15 additions & 0 deletions

File tree

‎docs/CHANGELOG.md‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,21 @@ All notable changes to this project will be documented in this file.
1717

1818
## [Unreleased]
1919

20+
### Security
21+
22+
- **Secret scanning + push protection** — enabled on the repository; credentials pushed by mistake are now blocked at the source.
23+
- **Dependabot alerts + automated security updates** — enabled; known-CVE dependency updates are now proposed automatically.
24+
- **Private vulnerability reporting** — enabled; researchers can report issues privately via GitHub Security Advisories instead of public issues.
25+
- **Branch ruleset on `main`** — replaces classic branch protection; requires all CI checks (`pre-commit`, `build 3.10–3.13`) to pass before merge, enforced on admins. Classic protection had no required checks and did not enforce on admins.
26+
- **Tag ruleset** — `v*` release tags are now immutable; they cannot be moved or deleted.
27+
- **`pypi` environment protection** — required reviewer approval added; a push to `main` no longer publishes to PyPI without a human gate.
28+
- **SHA-pinned GitHub Actions** — all third-party actions pinned to commit SHAs (`trufflehog`, `setup-uv`, `gh-action-pypi-publish`, `action-gh-release`). Previously `trufflesecurity/trufflehog@main` was a floating branch reference — a critical supply-chain risk.
29+
- **`uv sync --frozen`** — enforced in CI; the lockfile can no longer silently change during a build.
30+
- **OSV-Scanner** (`google/osv-scanner-action`) — added as a daily scheduled scan and on every PR targeting `main` or `develop`, against the OSV.dev malicious package index.
31+
- **Dependabot configuration** (`.github/dependabot.yml`) — weekly updates for `pip` and `github-actions` ecosystems with a 5-day cooldown window to mitigate supply-chain worm attacks; all PRs routed to `develop`.
32+
- **`SECURITY.md`** — added; documents the responsible disclosure process (GitHub private advisories) and the repository's supply-chain posture.
33+
- **`AGENTS.md` security rules** — mandatory rules added for coding agents: no direct pushes to `main`, no manual lockfile edits, no workflow modifications without approval, no local `hatch publish`.
34+
2035
## [0.19.0] - 2026-05-11
2136

2237
### Added

0 commit comments

Comments
 (0)