logicsrc/.github
Anthony Ettinger 870c56b67e ci: add ThreatCrush security scan
Installs threatcrush-scan@1.1.0 from the sh1pt Actions Store.
Scans pull requests for hardcoded credentials, injection, SSRF, unsafe
deserialisation and dependency tampering; uploads SARIF to the Security
tab.

Report-only — it will not fail a pull request. Set the pack's failOn
input to critical,high once the existing findings are triaged.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-03 10:36:57 +00:00
..
workflows ci: add ThreatCrush security scan 2026-08-03 10:36:57 +00:00
threatcrush-to-sarif.py ci: add ThreatCrush security scan 2026-08-03 10:36:57 +00:00