Skip to content

chore: align agent-core GitHub security with probe-core#7

Merged
fuse merged 1 commit into
developfrom
chore/align-security-with-probe-core
May 26, 2026
Merged

chore: align agent-core GitHub security with probe-core#7
fuse merged 1 commit into
developfrom
chore/align-security-with-probe-core

Conversation

@fuse

@fuse fuse commented May 26, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Add SECURITY.md (same structure as fluid-pub/probe-core, scoped to agent-core).
  • Align .github/dependabot.yml with probe-core: assignees, open-pull-requests-limit, grouped github-actions updates.
  • Add CodeQL workflow header comment for parity with probe-core.

GitHub settings (already applied on the repo)

  • Dependabot security updates: enabled
  • Secret scanning push protection: enabled
  • Private vulnerability reporting: enabled

Test plan

  • Merge PR; confirm Security → Overview shows Enabled for security policy, advisories, private reporting, Dependabot, code scanning, secret scanning.
  • Enable Code quality (Go, develop) in Settings if not already on — same manual step as other public Go cores when org preview allows it.

Add SECURITY.md, Dependabot assignees and grouped Actions updates, and
document the alignment in CHANGELOG.
@fuse fuse merged commit 4f10489 into develop May 26, 2026
4 checks passed
@fuse fuse deleted the chore/align-security-with-probe-core branch May 26, 2026 15:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant