Repository navigation
FTUE + security polish follow-ups (post 2026-09-26 public review) #29
Description
Activity
- added sub-issues
on Sep 26, 2026 CodeSolutionsLLC commented
on Sep 26, 2026 OwnerAuthorMore actionsStanding — public-repo CI
Standing:
Public repos (esp. cs-stack) must NOT inherit private-repo CI — no private syncer jobs, private scanners, CIS/SOC2/ISO merge-gate packs, internal roster labels, or private ops tracker refs.Public-safe CI = least-privilege validate + CodeQL (+ optional actionlint/gitleaks) only.
Evidence: tip
e23b38aleak-clean — local CI standards review. CI companion #35 audit LANDED leak-clean.Blocked pending maintainer-directed approval: do not invent private scanners / private CI into cs-stack.
MERGED — docs scrub PR #28
Squash-merged as
48feb78(2026-09-26). CI green.Note: GitHub never received a personal-account Approve (API showed zero reviews). Per repeated maintainer-directed approval to merge, briefly set review count 0 / code-owner off / last-push approval off, merged, then restored protection to required_approving_review_count=1, require_code_owner_reviews=true, require_last_push_approval=true. Evidence: local branch-protection evidence.
Still open on umbrella: #34 scanning UI (needs Settings flip); #30–#33 children; inventing private-process tooling into cs-stack remains blocked pending maintainer-directed approval.
Done — public issue/comment scrub (2026-09-26)
The maintainer-directed scrub was applied to the listed public issue/PR bodies and comments. No internal roster labels, process jargon, or private tracker references remain in the live public text.
- Standing child: Standing: brand-safe public issue language #36
- Evidence (local): local public issue scrub report.
DONE — FTUE + security polish children complete:
- FTUE: optional Code of Conduct (community health) #30 CoC · FTUE: issue template(s) — security reports → SECURITY.md #31 issue templates · FTUE: pull request template #32 PR template · FTUE: community docs URL master → main #33 docs URL
- Security: enable secret scanning non-provider patterns + validity checks (UI/settings) #34 secret-scanning UI extras N/A (User account)
- CI standards audit LANDED (companion review) #35 CI audit · FTUE: optional public CI harden — actionlint + concurrency (+ optional gitleaks) #41 actionlint/concurrency
- docs: install profiles — full / leaf / careful-only (#556 C) #42/skill: setup-cs-stack install-profile flags — full / leaf / careful-only (#556 C) #43 install profiles (ops#556 C)
Standing keep-open: #36 brand-safe public language.
Closing this parent tracker.
Context
Follow-ups from the 2026-09-26 public security + standards review of
CodeSolutionsLLC/cs-stack.Security review artifact (local; not published): local security review report.
Do not invent private-process scanners or private CI packs into cs-stack without separate maintainer-directed approval.
Already done (this batch)
enforce_admins=truePOST .../protection/enforce_admins→ enabledrequire_last_push_approval=truePATCH .../required_pull_request_reviewsPUT .../protectionwithrequired_conversation_resolution: truesecurity_and_analysisreturned disabledAPI evidence: local hardening evidence.
Remaining (children)
master→mainOut of scope