Skip to content

mono - chore: defense - record CODEOWNERS and lockdown apply - #1705

Merged
jaredwray merged 2 commits into
mainfrom
cursor/defense-reconcile-1704-7da5
Aug 24, 2026
Merged

mono - chore: defense - record CODEOWNERS and lockdown apply#1705
jaredwray merged 2 commits into
mainfrom
cursor/defense-reconcile-1704-7da5

Conversation

@jaredwray

@jaredwray jaredwray commented Aug 24, 2026

Copy link
Copy Markdown
Owner

Summary

Record that CODEOWNERS is on main and that a repo admin applied lockdown-repo.sh (defense-in-depth § 2 / § 7).

Status update

DEFENSE_IN_DEPTH.md: CODEOWNERS → — PR #1704; lockdown apply → — PR #1705

Changes

  • Check off the CODEOWNERS catalog item
  • Check off the lockdown apply item from the admin apply log (all nine settings ✓)
  • Expand the SECURITY.md summary with live GitHub settings: PRs required on main, admin-only tags, immutable releases, fork-PR workflow approval, and the Actions allowlist

Left unchecked (maintainer manuals): npm stage-only trusted publisher, Drydock, package 2FA / disallow tokens, phishing-resistant account 2FA, and offline recovery codes.

Verification

  • #1704 is merged on main
  • Admin apply output: workflow token read-only, fork-PR approval, branch + tag rulesets, immutable releases, secret scanning, private vulnerability reporting, Dependabot off, Actions allowlist

Reference: defense-in-depth-nodejs § 2 / § 7

Open in Web Open in Cursor 

cursoragent and others added 2 commits August 24, 2026 23:09
Reconcile DEFENSE_IN_DEPTH.md after #1704 landed and mention the
CODEOWNERS file in the public SECURITY.md summary.

Co-authored-by: Jared Wray <me@jaredwray.com>
Check off § 7 after the admin apply and list the live GitHub settings
in SECURITY.md. Account 2FA and npm registry manuals stay open.

Co-authored-by: Jared Wray <me@jaredwray.com>
@cursor cursor Bot changed the title mono - chore: defense - mark CODEOWNERS item as merged mono - chore: defense - record CODEOWNERS and lockdown apply Aug 24, 2026
@codecov

codecov Bot commented Aug 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (82e5371) to head (a888334).

Additional details and impacted files
@@            Coverage Diff            @@
##              main     #1705   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files           29        29           
  Lines         3513      3513           
  Branches       795       794    -1     
=========================================
  Hits          3513      3513           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@jaredwray
jaredwray merged commit 21892be into main Aug 24, 2026
16 of 17 checks passed
@jaredwray
jaredwray deleted the cursor/defense-reconcile-1704-7da5 branch August 24, 2026 23:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants