HarperFast / HarperFast/harper

[Epic] Supply-chain & CI security hardening

Open
#1,664 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
89
Forks
10
Avg merge
2d 6h
Merged PRs (30d)
200

Description

Tracking epic for supply-chain and CI/release-pipeline security hardening: GITHUB_TOKEN permission audit, SAST tooling, lockfile publishing, dependency scanning, and a hardened Docker image.

---
_Filed by Claude (Opus 4.8), issue-backlog triage & grouping pass._

Contributor guide

Open the contributing guide

Research direction

No files, tests, or entry points are identified in the epic. Start by separating the GITHUB_TOKEN audit, SAST tooling, lockfile publishing, dependency scanning, and hardened Docker image into concrete tasks; done means each listed security-hardening area has an agreed implementation and verification path.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, github-actions, javascript, nodejs
Domain
ci-cd, devops, release, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.