agentbbs/.github
Anthony Ettinger 281dbaf518 ci: add ThreatCrush security scan
Installs threatcrush-scan@1.1.0 from the sh1pt Actions Store.
Scans pull requests for hardcoded credentials, injection, SSRF, unsafe
deserialisation and dependency tampering; uploads SARIF to the Security
tab.

Report-only — it will not fail a pull request. Set the pack's failOn
input to critical,high once the existing findings are triaged.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-03 10:31:02 +00:00
..
workflows ci: add ThreatCrush security scan 2026-08-03 10:31:02 +00:00
dependabot.yml chore: keep all agentbbs services on latest software (#69) 2026-06-30 20:06:06 -07:00
threatcrush-to-sarif.py ci: add ThreatCrush security scan 2026-08-03 10:31:02 +00:00