HarperFast / HarperFast/harper
[Epic] Supply-chain & CI security hardening
Open
- Dominant language
- JavaScript
- Stars
- 89
- Forks
- 10
- Avg merge
- 2d 6h
- Merged PRs (30d)
- 200
Description
Tracking epic for supply-chain and CI/release-pipeline security hardening: GITHUB_TOKEN permission audit, SAST tooling, lockfile publishing, dependency scanning, and a hardened Docker image.
---
_Filed by Claude (Opus 4.8), issue-backlog triage & grouping pass._
Contributor guide
Research direction
No files, tests, or entry points are identified in the epic. Start by separating the GITHUB_TOKEN audit, SAST tooling, lockfile publishing, dependency scanning, and hardened Docker image into concrete tasks; done means each listed security-hardening area has an agreed implementation and verification path.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, github-actions, javascript, nodejs
- Domain
- ci-cd, devops, release, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100