Generated from a GitHub settings audit on 2026-07-16.
Use this as a working checklist. If this repository is no longer maintained, archive it and close this issue instead of applying every hardening item.
Branch And Merge Controls
Security Scanning
GitHub Actions
Repository Hygiene
Verification
Audit Notes
- Default branch
main is currently unprotected.
- Security settings: Dependabot alerts=enabled, Dependabot security updates=enabled, secret scanning=disabled, push protection=disabled, code security=missing.
- Actions workflow permissions: default=read, can_approve_prs=False.
- Actions policy: enabled=True, allowed_actions=all.
- Repo hygiene: delete_branch_on_merge=True, allow_forking=True, wiki=True, license=present.
Generated from a GitHub settings audit on 2026-07-16.
Use this as a working checklist. If this repository is no longer maintained, archive it and close this issue instead of applying every hardening item.
Branch And Merge Controls
mainwith a branch rule or ruleset: require pull requests, passing CI checks when available, conversation resolution, and block force pushes/deletions.Security Scanning
GitHub Actions
Repository Hygiene
Verification
mainbranch settings in Settings > Branches or Rulesets.Audit Notes
mainis currently unprotected.