Skip to content

Commit 4db4fc5

Browse files
committed
docs: record repository security hardening
1 parent 4a2bb5c commit 4db4fc5

1 file changed

Lines changed: 4 additions & 3 deletions

File tree

‎docs/MAINTAINER_HANDOVER.md‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -36,9 +36,10 @@ This document prepares a transfer; it does not record a completed ownership chan
3636
contain them. Plan a subsequent beta release after choosing publisher access and ownership.
3737
- The current source uses MIT; the already published `0.1.0` artifact retains its original Apache
3838
2.0 metadata. Keep that distinction explicit until a subsequent release is published.
39-
- CodeQL is active. At the review date, Dependabot security alerts/security updates and secret
40-
scanning/push protection were disabled. Enable the appropriate GitHub security features and
41-
review any resulting alerts. Scheduled dependency-version PRs are already enabled.
39+
- CodeQL, Dependabot vulnerability alerts/security updates, secret scanning, and secret-scanning
40+
push protection are active. GitHub left non-provider patterns and validity checks unavailable or
41+
disabled when requested during the review. Review any resulting alerts after transfer. Scheduled
42+
dependency-version PRs are also enabled.
4243
- No repository rulesets were present at the review date. A protected default branch is an
4344
optional next step when more maintainers contribute; it should fit the team's merge workflow.
4445
- The public API remains provisional and JDK 25 remains required. A repository transfer is not

0 commit comments

Comments
 (0)