afterhours-shift-manager/.github/workflows
Adam Moussa 7e4458724f Harden release workflow and regex against CodeQL findings
Address three code-scanning alerts on the PR:

- Critical (actions/untrusted-checkout): split release.yaml into a
  read-only `prepare` job that checks out and runs repo code, and a
  privileged `publish` job (contents:write + OIDC) that never checks out
  repo code — it tags, releases, and invokes purely through the GitHub
  and AWS APIs. Also assert head_branch == main.
- High x2 (py/polynomial-redos): rewrite the italic and link regexes in
  markdown_to_mrkdwn with possessive quantifiers and exclusive character
  classes so they run in linear time on adversarial input. Adds a
  regression test.
2026-06-11 19:30:55 -04:00
..
changelog-guard.yml Add changelog-driven releases and App Home tab 2026-06-11 19:15:20 -04:00
ci.yaml Add pytest suite and wire it into CI (#85) (#86) 2026-06-01 19:07:08 -04:00
dependency-review.yml Add dependency-review caller workflow (#97) 2026-06-05 12:26:41 -04:00
deploy.yaml Merge ring-scheduler-3cx and resolve all open issues (#62) 2026-05-12 19:55:39 -04:00
labeler.yml Repo hygiene: PR labeler + README badges + dependabot (INFRA-56/57/66) (#106) 2026-06-11 14:13:35 -04:00
release.yaml Harden release workflow and regex against CodeQL findings 2026-06-11 19:30:55 -04:00