afterhours-shift-manager/.github
Adam Moussa 7e4458724f Harden release workflow and regex against CodeQL findings
Address three code-scanning alerts on the PR:

- Critical (actions/untrusted-checkout): split release.yaml into a
  read-only `prepare` job that checks out and runs repo code, and a
  privileged `publish` job (contents:write + OIDC) that never checks out
  repo code — it tags, releases, and invokes purely through the GitHub
  and AWS APIs. Also assert head_branch == main.
- High x2 (py/polynomial-redos): rewrite the italic and link regexes in
  markdown_to_mrkdwn with possessive quantifiers and exclusive character
  classes so they run in linear time on adversarial input. Adds a
  regression test.
2026-06-11 19:30:55 -04:00
..
workflows Harden release workflow and regex against CodeQL findings 2026-06-11 19:30:55 -04:00
dependabot.yml Repo hygiene: PR labeler + README badges + dependabot (INFRA-56/57/66) (#106) 2026-06-11 14:13:35 -04:00