Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: DwayneCode/PowerShell_SamErde
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: main
Choose a base ref
...
head repository: SamErde/PowerShell
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: main
Choose a head ref
Checking mergeability… Don’t worry, you can still create the pull request.
  • 2 commits
  • 3 files changed
  • 2 contributors

Commits on Oct 1, 2026

  1. 🔒 security(ci): harden workflow credentials, permissions, and executi…

    …on controls (SamErde#19)
    
    * 🔒 security(ci): harden workflow credentials, permissions, and execution controls
    
    - Set persist-credentials: false on the GitGuardian, MegaLinter, and
      PSScriptAnalyzer checkouts; none of these jobs push back to the repository.
    - Add per-ref concurrency to GitGuardian with cancel-in-progress: false so
      queued incremental secret scans still cover every pushed commit range.
    - Add conservative finite job timeouts (20/45/20 minutes).
    - Add an explicit job-level contents: read permission to the GitGuardian job.
    - Replace MegaLinter's blanket DISABLE_ERRORS: true with
      ENABLE_ERRORS_LINTERS: ACTION_ACTIONLINT so findings remain reported while
      only a verified-clean linter gates the build.
    
    Refs SamErde#18
    
    Co-authored-by: Copilot App <[email protected]>
    
    * 🔒 security(ci): drop GitGuardian concurrency to preserve scan coverage
    
    GitHub Actions retains only one pending run per concurrency group, so a third
    rapid push evicts the second run even when cancel-in-progress is false. Since
    each ggshield run scans only its own github.event.before -> head range, the
    evicted range would never be scanned. Removes the grouping and documents the
    tradeoff in the workflow.
    
    Addresses Codex review feedback on SamErde#19.
    
    Co-authored-by: Copilot App <[email protected]>
    
    * 📚 docs(ci): correct GitGuardian scan-range comment (Refs SamErde#18)
    
    ggshield v1.43.0 reads GITHUB_PUSH_BASE_SHA (not github.event.before) and falls
    back to GITHUB_DEFAULT_BRANCH, then GITHUB_SHA~1... Verified against the pinned
    action source. Comment only; no behavior change.
    
    Co-authored-by: Copilot App <[email protected]>
    
    * 🔒 security(ci): remove public-repo SARIF actions permission (Refs SamErde#18)
    
    Co-authored-by: Copilot App <[email protected]>
    
    ---------
    
    Co-authored-by: Copilot App <[email protected]>
    SamErde and Copilot authored Oct 1, 2026
    Configuration menu
    Copy the full SHA
    c93b4aa View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    ac882ff View commit details
    Browse the repository at this point in the history
Loading