Skip to content

ci: Tier 1 OSS security scanners (CodeQL + Dependabot + OSV-Scanner)#14

Merged
mastermanas805 merged 1 commit into
masterfrom
oss/tier1-security-scanners
May 21, 2026
Merged

ci: Tier 1 OSS security scanners (CodeQL + Dependabot + OSV-Scanner)#14
mastermanas805 merged 1 commit into
masterfrom
oss/tier1-security-scanners

Conversation

@mastermanas805
Copy link
Copy Markdown
Member

Summary

Free GitHub-native + OSS scanners. 100% free for public repos.

  • CodeQL security-extended for JS/TS (XSS, prototype pollution, SSRF, code injection)
  • Dependabot npm + github-actions weekly grouped
  • OSV-Scanner cross-ecosystem CVE scan via OSV.dev

Cost

Zero.

Test plan

  • CodeQL completes on PR
  • OSV-Scanner completes
  • Dependabot fires next Monday

🤖 Generated with Claude Code

CodeQL (security-extended for JS/TS) + Dependabot (npm + actions) +
OSV-Scanner. 100% free for public repos.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-advanced-security
Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@mastermanas805 mastermanas805 merged commit 7a8bc1a into master May 21, 2026
5 checks passed
@mastermanas805 mastermanas805 deleted the oss/tier1-security-scanners branch May 21, 2026 17:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants