Skip to content

Repository hygiene for Plumb: security policy, Dependabot, pinned Actions, lean dist - #1

Merged
edeoliv merged 1 commit into
mainfrom
chore/repo-hygiene
Sep 3, 2026
Merged

edeoliv merged 1 commit into
mainfrom
chore/repo-hygiene

Conversation

@edeoliv

@edeoliv edeoliv commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Plumb scores this package 70 (Security 51.5) for four mechanical findings: no security policy, no dependency updater, Actions referenced by mutable tags, and dev files shipped in the Composer archive. This PR addresses all four without touching code: SECURITY.md with a private advisory route; weekly grouped Dependabot with a 7-day cooldown for Composer and Actions; workflow actions pinned to the current tags' commit SHAs; .gitattributes export-ignore for tests, CI and tooling; the docs workflow removed. Tag a release after merging so Plumb picks it up on the next scan.

@edeoliv
edeoliv merged commit 4f30571 into main Sep 3, 2026
1 of 19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant