Skip to content

Audit and harden dependency management #19

Description

@coderooz

Status: Pending

What

Security and dependency audit:

  • Run npm audit and resolve all vulnerabilities
  • Add Dependabot config (already created .github/dependabot.yml — verify it works)
  • Pin exact versions for production dependencies
  • Review transitive dependencies for unnecessary bloat
  • Add .npmrc with save-exact=true
  • Verify all peerDependencies are correctly specified across workspace packages
  • Check for duplicate packages in lockfile (npm ls)
  • Add SECURITY.md (already created — verify content)
  • Set up code scanning with CodeQL

Related: #3

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions