Skip to content

FTUE + security polish follow-ups (post 2026-09-26 public review) #29

Description

@CodeSolutionsLLC

Context

Follow-ups from the 2026-09-26 public security + standards review of CodeSolutionsLLC/cs-stack.

Security review artifact (local; not published): local security review report.

Do not invent private-process scanners or private CI packs into cs-stack without separate maintainer-directed approval.

Already done (this batch)

Item Status Evidence
M1 + L3 + L5 docs scrub PR open (do not merge until maintainer-directed) #28
M2 enforce_admins=true Done via API POST .../protection/enforce_admins → enabled
M3 require_last_push_approval=true Done via API PATCH .../required_pull_request_reviews
L2 conversation resolution Done via API PUT .../protection with required_conversation_resolution: true
L1 non-provider patterns Attempted; stayed disabled (silent no-op; User owner) PATCH security_and_analysis returned disabled
I3 validity checks Attempted; stayed disabled (silent no-op) same

API evidence: local hardening evidence.

Remaining (children)

  1. Optional Code of Conduct (community health)
  2. Issue template(s) pointing security → SECURITY.md
  3. PR template
  4. Docs URL / community documentation link master → main
  5. Secret scanning toggles via UI/settings if account supports (L1 + I3)
  6. CI standards audit — still in flight (companion review artifact (local) not present at filing time)

Out of scope

  • Inventing private-process / private-CI tooling into public cs-stack

Activity

  1. CodeSolutionsLLC commented on Sep 26, 2026

    @CodeSolutionsLLC
    OwnerAuthor

    Standing — public-repo CI

    Standing:
    Public repos (esp. cs-stack) must NOT inherit private-repo CI — no private syncer jobs, private scanners, CIS/SOC2/ISO merge-gate packs, internal roster labels, or private ops tracker refs.

    Public-safe CI = least-privilege validate + CodeQL (+ optional actionlint/gitleaks) only.

    Evidence: tip e23b38a leak-clean — local CI standards review. CI companion #35 audit LANDED leak-clean.

    Blocked pending maintainer-directed approval: do not invent private scanners / private CI into cs-stack.

    Umbrella #29; children #30–#35.

  2. CodeSolutionsLLC commented on Sep 26, 2026

    @CodeSolutionsLLC
    OwnerAuthor

    MERGED — docs scrub PR #28

    Squash-merged as 48feb78 (2026-09-26). CI green.

    Note: GitHub never received a personal-account Approve (API showed zero reviews). Per repeated maintainer-directed approval to merge, briefly set review count 0 / code-owner off / last-push approval off, merged, then restored protection to required_approving_review_count=1, require_code_owner_reviews=true, require_last_push_approval=true. Evidence: local branch-protection evidence.

    Still open on umbrella: #34 scanning UI (needs Settings flip); #30–#33 children; inventing private-process tooling into cs-stack remains blocked pending maintainer-directed approval.

  3. CodeSolutionsLLC commented on Sep 26, 2026

    @CodeSolutionsLLC
    OwnerAuthor

    Done — public issue/comment scrub (2026-09-26)

    The maintainer-directed scrub was applied to the listed public issue/PR bodies and comments. No internal roster labels, process jargon, or private tracker references remain in the live public text.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions