Skip to content

Tracker: security and board automation on a GitHub App credential #2543

Description

@cliffhall

Goal

Put the repo's security and board automation on one GitHub App credential, so alerts, advisories and new issues reach board #28 without a maintainer running /issue-triage by hand, and so v2 code is scanned before the release PR rather than on it.

Why now

The v2.9.0 release showed every gap at once:

Structure

Everything that writes to the board waits on one prerequisite: the GitHub App. Two items need no credential and can start immediately.

The Sub-issues panel on this issue is the canonical list. Order of work:

  1. Unblocked, start now: CodeQL on v2/main, and fixing alerts Skip the dist/index.js bit #74–Improve Windows Support #76.
  2. The prerequisite: create the GitHub App (an org-admin act; human-gated).
  3. Then, in any order: move the Dependabot sweep onto the App, the code-scanning sweep (Nightly security sweep: turn Dependabot and code-scanning (CodeQL) alerts into board-tracked issues #2542), GHSA draft cards (GHSA draft cards: place on the board for the affected line, and include affected versions + reporter #2462), nightly triage (Nightly triage: sweep unboarded issues onto the board and run the board audit #2463), and boarding for the SDK watch and monthly refresh.

Invariants every sub-issue keeps

These are from AGENTS.md:

  • No model runs in a write-capable job. The deterministic sweeps need no model. Nightly triage (Nightly triage: sweep unboarded issues onto the board and run the board audit #2463) does, and must use the three-job shape sdk-watch.yml established.
  • A marker is trusted only on automation-authored issues, because the repo is public.
  • Every action in a credentialed job is SHA-pinned (verify:action-pins).
  • A sweep that cannot read its listing fails loudly and writes nothing.
  • Accepting and publishing a security advisory stay human-gated; automation only creates tracking cards.

Done when

Every sub-issue is closed, and a nightly run boards what it files with no manual step.

Activity

  1. added this to the v2.10.0 milestone on Sep 30, 2026
  2. added
    v2Issues and PRs for v2
    choreMaintenance: deps, build tooling, CI, cleanup — no user-facing behavior change
    on Sep 30, 2026
  3. cliffhall commented on Sep 30, 2026

    @cliffhall
    MemberAuthor

    Triage: Priority High (total 9)

    • Severity 4 — security findings go untracked and v2 code is unscanned until release (the v2.9.0 ReDoS)
    • Urgency 4 — blocks the planned automation; wanted for v2.10.0
    • Bonuses: +1 milestoned (v2.10.0)

    Board: #28, Status Todo. Part of tracker #2543.

  4. modified the milestones: v2.10.0, v2.11.0 on Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    choreMaintenance: deps, build tooling, CI, cleanup — no user-facing behavior changev2Issues and PRs for v2

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions