Skip to content

ci: add centralized vuln remediation workflow#145

Open
ulziibay-kernel wants to merge 3 commits intomainfrom
security/vuln-remediation-reusable
Open

ci: add centralized vuln remediation workflow#145
ulziibay-kernel wants to merge 3 commits intomainfrom
security/vuln-remediation-reusable

Conversation

@ulziibay-kernel
Copy link
Copy Markdown
Contributor

@ulziibay-kernel ulziibay-kernel commented Apr 9, 2026

Thin caller to the reusable 3-stage pipeline (triage → fix → PR) in kernel/infra. Per-repo config in .github/vuln-remediation.json.

Made with Cursor


Note

Medium Risk
Introduces automation with contents and pull-requests write permissions that can create/modify branches and PRs. Risk is mainly around workflow trust and execution from the referenced reusable workflow.

Overview
Adds a new GitHub Actions workflow, vuln-remediation.yml, that runs on a weekly cron and via manual dispatch to call the reusable kernel/security-workflows vulnerability remediation pipeline (configured to use go.mod for Go version).

Adds a minimal socket.yml (version: 2) to enable Socket’s configuration/versioning.

Reviewed by Cursor Bugbot for commit 76b7895. Bugbot is set up for automated code reviews on this repo. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant