Parent: #35
Grandparent: #29
Why
Code Human OK (2026-09-27): optional public CI harden from the companion CI audit on #35. Skill: public-repo-ci-skeleton optional harden section.
In scope (public-safe only)
- actionlint — pinned release tarball + sha256 verify; fail-hard job on
.github/workflows/*.yml. Prefer a sibling job (e.g. Workflow lint) so existing required check names stay stable until maintainers add the new context.
concurrency on validate (and CodeQL if natural) — cancel in-progress on the same ref:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
- gitleaks — optional; public action +
contents: read only. Skip if the PR is cleaner without a third-party Action; note the skip in the PR body.
Out of scope / DENY
- Private reusable workflows, syncers, PAT-health, compliance / ISO scanners, private house packs
pull_request_target, fail-open required gates, cross-repo actions/checkout
- Seat / roster / bot vocabulary in Actions names or required checks
- Flipping to full SHA-pin of all Actions (needs separate Human OK)
- Soft pull of starship-* into public packs
- Merging (maintainers only)
Acceptance
Paths
- In:
.github/workflows/ (validate.yml, codeql.yml; new workflow file only if needed for actionlint)
- Out: docs playbooks, skill bodies, issue/PR templates, SECURITY.md, CODEOWNERS unless a required-path touch is unavoidable
Capability
remote-ok
Parent: #35
Grandparent: #29
Why
Code Human OK (2026-09-27): optional public CI harden from the companion CI audit on #35. Skill:
public-repo-ci-skeletonoptional harden section.In scope (public-safe only)
.github/workflows/*.yml. Prefer a sibling job (e.g.Workflow lint) so existing required check names stay stable until maintainers add the new context.concurrencyonvalidate(and CodeQL if natural) — cancel in-progress on the same ref:contents: readonly. Skip if the PR is cleaner without a third-party Action; note the skip in the PR body.Out of scope / DENY
pull_request_target, fail-open required gates, cross-repoactions/checkoutAcceptance
concurrencyon validate (and CodeQL if touched)contents: readunless a job truly needs more, documented)Paths
.github/workflows/(validate.yml, codeql.yml; new workflow file only if needed for actionlint)Capability
remote-ok