Skip to content

chore: add enterprise CI/CD pipelines, dependabot, husky audit pre-co…#11

Merged
RamosJSouza merged 1 commit intomainfrom
chore/ci-add-github-actions-ci-cd-security-hardening
Mar 14, 2026
Merged

chore: add enterprise CI/CD pipelines, dependabot, husky audit pre-co…#11
RamosJSouza merged 1 commit intomainfrom
chore/ci-add-github-actions-ci-cd-security-hardening

Conversation

@RamosJSouza
Copy link
Owner

…mmit, security headers hardening, badges and compliance docs

Implement full .github/workflows (ci, cd, security, dependabot) Add husky + pre-commit npm audit check
Enhance Helmet with HSTS, stricter CSP, etc.
Update package.json description/keywords/scripts
Add badges to README + first v1.0.0 release stub
Create CONTRIBUTING.md, SECURITY.md and compliance section Add tsconfig-paths + rotate-jwt-keys script + RLS test example

…mmit, security headers hardening, badges and compliance docs

Implement full .github/workflows (ci, cd, security, dependabot)
Add husky + pre-commit npm audit check
Enhance Helmet with HSTS, stricter CSP, etc.
Update package.json description/keywords/scripts
Add badges to README + first v1.0.0 release stub
Create CONTRIBUTING.md, SECURITY.md and compliance section
Add tsconfig-paths + rotate-jwt-keys script + RLS test example
@gitguardian
Copy link

gitguardian bot commented Mar 14, 2026

⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secret in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
27153195 Triggered Generic Password 485b6ef .github/workflows/ci.yml View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secret safely. Learn here the best practices.
  3. Revoke and rotate this secret.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

@RamosJSouza RamosJSouza merged commit a4cc486 into main Mar 14, 2026
3 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant