Skip to content

baseline-gates-hardening - #335

Draft
KooshaPari wants to merge 8 commits into
mainfrom
codex/byteport-baseline-gates-20260805
Draft

baseline-gates-hardening#335
KooshaPari wants to merge 8 commits into
mainfrom
codex/byteport-baseline-gates-20260805

Conversation

@KooshaPari

Copy link
Copy Markdown
Owner

Summary

  • Replace both unresolved trunk-io/trunk-action v1.0.4 references with the verified immutable upstream commit 22e948f7bb9f870bc6c42625585f1ef27e9c5afc.
  • Use cargo-deny's bare GNU identifier GPL-3.0 so the existing license policy parses on cargo-deny >= 0.18.4.
  • Set Gitleaks BASE_REF to the pull request target SHA, so PR scans use a real base object instead of assuming the first PR commit's parent is present.

Validation

  • git diff --check passes.
  • The Trunk SHA was verified against the upstream v1.0.4 tag via the GitHub API.
  • The Gitleaks override matches the action's documented BASE_REF input and preserves the existing scan thresholds and action pin.
  • No full workflow reruns were performed in this change.

Scope

This is a baseline-gates workflow/configuration hardening PR, intentionally separate from PR #334. It does not change application code, lint findings, or dependency vulnerability versions (rkyv/event-listener remain a separate remediation task).

@sonarqubecloud

sonarqubecloud Bot commented Aug 5, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant