Skip to content

Governance: remediate html4tree Scorecard alerts and disabled security surfaces #693

Description

@seonghobae

Scope

ContextualWisdomLab/html4tree still exposes repository-governance findings while PR #170 source and dependency gates are clean on current head 1bc3a63c7ac24353497794c14de5fbb2a7720295.

Current evidence

  • current-head CI build, JaCoCo verification, CodeQL, Semgrep, Trivy, OSV, dependency review and Scorecard checks pass
  • current Security Scan log emits no actual warning or error annotations
  • open code-scanning governance alerts remain from the 2026-07-13 Scorecard analysis:
  • repository issues are disabled, so ordinary governance tracking cannot live in the target repository
  • private vulnerability reporting and Dependabot security updates are enabled
  • secret scanning, non-provider patterns, validity checks, and push protection are disabled and require an explicit repository-setting decision

Required governance decisions

  • centralize or add a discoverable SECURITY.md without inventing an unsupported contact path
  • add a pinned .github/dependabot.yml for Gradle/GitHub Actions version updates, separate from already-enabled security updates
  • preserve the Gradle wrapper only with verified provenance/integrity and record a bounded Scorecard dismissal rationale if it remains intentional; do not delete the build bootstrap blindly
  • decide explicitly whether to enable the currently disabled secret-scanning surfaces
  • re-run Scorecard/SARIF on current default-branch state and close only alerts proven remediated or intentionally governed

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: dependenciesDependency or lockfile maintenancearea: operationsOperability, observability, readiness, SLO, backup, or retentionarea: securitySecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behaviortype: featureNew or expanded product capability

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions