chore: add governance and security scanning #105

Merged
manlycucumber merged 1 commit from chore/governance into develop 2026-07-01 06:34:55 +00:00
manlycucumber commented 2026-07-01 06:34:18 +00:00 (Migrated from github.com)

Phase 0 governance batch for Site: CODEOWNERS (default owner + reserved review paths), a CodeQL workflow (scans Actions workflows — CodeQL has no PHP analyzer; PHP SAST stays with the app's own gates), and a FUNDING.yml placeholder. Org-wide CONTRIBUTING (DCO + clean-room), Code of Conduct, SECURITY, and the Liturgical-correction issue form live in Introibo-App/.github. Config only.

Phase 0 governance batch for `Site`: CODEOWNERS (default owner + reserved review paths), a CodeQL workflow (scans Actions workflows — CodeQL has no PHP analyzer; PHP SAST stays with the app's own gates), and a FUNDING.yml placeholder. Org-wide CONTRIBUTING (DCO + clean-room), Code of Conduct, SECURITY, and the Liturgical-correction issue form live in [Introibo-App/.github](https://github.com/Introibo-App/.github). Config only.
github-advanced-security[bot] commented 2026-07-01 06:35:00 +00:00 (Migrated from github.com)

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. ### What Enabling Code Scanning Means: - The 'Security' tab will display more code scanning analysis results (e.g., for the default branch). - Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. - You will be able to see the analysis results for the pull request's branch on this [overview](/Introibo-App/Site/security/code-scanning?query=pr%3A105+is%3Aopen) once the scans have completed and the checks have passed. For more information about GitHub Code Scanning, check out [the documentation](https://docs.github.com/code-security/code-scanning/introduction-to-code-scanning/about-code-scanning).
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Directorium/Site!105
No description provided.