-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Description
Context
Linked from the Daily Org Oversight Report — 2026-03-09.
Summary
`fro-bot/fro-bot.github.io` currently has no code scanning analysis configured. Other repos in the org (`.github`, `agent`) run both CodeQL and OpenSSF Scorecard scans.
Recommended Actions
- Add a CodeQL workflow — create `.github/workflows/codeql.yml` with analysis appropriate for the repo's language(s)
- Add a Scorecard workflow — create `.github/workflows/scorecard.yml` to run OpenSSF Scorecard checks
- Enable GitHub code scanning alerts in the repository security settings
This brings the repo into coverage parity with the rest of the org.
References
/cc @fro-bot
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels