mirror of
https://github.com/Jeuners/ECC.git
synced 2026-09-09 15:02:30 +02:00
Add a repo-level supply-chain incident response playbook for npm/GitHub Actions package-registry incidents, anchored on the May 2026 TanStack compromise and prior Shai-Hulud-style npm incidents. - add `docs/security/supply-chain-incident-response.md` with exposure checks, immediate response steps, workflow rules, publication rules, and escalation triggers - link the playbook from `SECURITY.md` - reject `pull_request_target` workflows that restore or save shared dependency caches - add a regression test for the new `pull_request_target + actions/cache` guardrail Validation: - node tests/ci/validate-workflow-security.test.js (12 passed, 0 failed) - node scripts/ci/validate-workflow-security.js (validated 7 workflow files) - npx markdownlint-cli 'SECURITY.md' 'docs/security/supply-chain-incident-response.md' - npx markdownlint-cli '**/*.md' --ignore node_modules - git diff --check - node tests/run-all.js (2377 passed, 0 failed) - GitHub CI for #1848 green across Ubuntu, Windows, and macOS No release, tag, npm publish, plugin tag, marketplace submission, or announcement was performed. |
||
|---|---|---|
| .. | ||
| architecture | ||
| business | ||
| examples | ||
| fixes | ||
| ja-JP | ||
| ko-KR | ||
| pt-BR | ||
| releases | ||
| ru | ||
| security | ||
| tr | ||
| vi-VN | ||
| zh-CN | ||
| zh-TW | ||
| ANTIGRAVITY-GUIDE.md | ||
| ARCHITECTURE-IMPROVEMENTS.md | ||
| capability-surface-selection.md | ||
| COMMAND-AGENT-MAP.md | ||
| continuous-learning-v2-spec.md | ||
| ECC-2.0-GA-ROADMAP.md | ||
| ECC-2.0-REFERENCE-ARCHITECTURE.md | ||
| ECC-2.0-SESSION-ADAPTER-DISCOVERY.md | ||
| HERMES-OPENCLAW-MIGRATION.md | ||
| HERMES-SETUP.md | ||
| hook-bug-workarounds.md | ||
| JOYCODE-GUIDE.md | ||
| legacy-artifact-inventory.md | ||
| MANUAL-ADAPTATION-GUIDE.md | ||
| MEGA-PLAN-REPO-PROMPTS-2026-03-12.md | ||
| PHASE1-ISSUE-BUNDLE-2026-03-12.md | ||
| PLAN-PRD-PATTERN.md | ||
| PR-399-REVIEW-2026-03-12.md | ||
| PR-QUEUE-TRIAGE-2026-03-13.md | ||
| QWEN-GUIDE.md | ||
| SELECTIVE-INSTALL-ARCHITECTURE.md | ||
| SELECTIVE-INSTALL-DESIGN.md | ||
| SESSION-ADAPTER-CONTRACT.md | ||
| skill-adaptation-policy.md | ||
| SKILL-DEVELOPMENT-GUIDE.md | ||
| SKILL-PLACEMENT-POLICY.md | ||
| stale-pr-salvage-ledger.md | ||
| token-optimization.md | ||
| TROUBLESHOOTING.md | ||