The software supply-chain security hardening (17-task plan) is implemented and merged to main (merge commit ed84f35). The code-side work is complete; the items below cannot be done in code and need to be configured in the GitHub repo settings / verified after a release.
Repository Security settings
Settings → Code security and analysis:
Secrets
Branch protection on main
Mark the new CI checks as required status checks:
2026-07-23: Alle o. g. Checks als required durchgesetzt via Repository-Ruleset main required checks (id 19642125, active) — s. Kommentar. gitleaks verifiziert lauffähig: Action erkennt WolfTasks als individuellen Account → kein GITLEAKS_LICENSE nötig, läuft bei jedem Push/PR über nur GITHUB_TOKEN, letzter Lauf auf main grün (no leaks found).
Post-release verification (deferred CI-gate check)
Separate follow-up (not part of this work)
🤖 Generated with Claude Code
The software supply-chain security hardening (17-task plan) is implemented and merged to
main(merge commited84f35). The code-side work is complete; the items below cannot be done in code and need to be configured in the GitHub repo settings / verified after a release.Repository Security settings
Settings → Code security and analysis:
codeql.ymlworkflow is in place)Secrets
Add repository secretOBSOLET (2026-07-23): nightly OWASP wurde durch Trivy-FS-Scan ersetzt (PR fix(security): replace NVD-bound OWASP nightly with Trivy SCA scan (#30) #31), Secret am 2026-07-04 gelöscht — nicht mehr zutreffend.NVD_API_KEY— speeds up the nightly OWASP Dependency-Check scan (nightly-security.yml)Branch protection on
mainMark the new CI checks as required status checks:
dependency-reviewcodeql(both matrix legs: java-kotlin, javascript-typescript)gitleaksPost-release verification (deferred CI-gate check)
v*.*.*tag triggersdocker-publish.yml, confirm that cosign signatures, SBOM, and SLSA provenance actually attach to the published Docker Hub images (cosign verify ...with--certificate-identity-regexppointing atWolfTasks/TaskWolf). ✅ Verifiziert 2026-07-23 gegen v1.0.15 — s. Kommentar.lodash@4.17.11, critical):npm auditgate +dependency-reviewgate both RED; Trivy image-gate efficacy already evidenced by real-world base-image CVE blocks (PRs fix(security): upgrade libexpat 2.8.1-r0 -> 2.8.2-r0 in base images #34/fix(layout): pin sidebar to viewport height so logout stays reachable (#11) #48/#15 i18n S3 — localize comments slice (+ relative-time rollout, DE/EN) #65) + the 07-22 postgresql nightly failure. PR closed unmerged, branch deleted. See comment.Separate follow-up (not part of this work)
taskowolf/TaskWolf; the real remote isWolfTasks/TaskWolf. Reconcile repo-wide (or rename the repo/org iftaskowolfis the intended canonical name). ✅ 2026-07-23 via PR docs: fix GitHub repo slug taskowolf/TaskWolf → WolfTasks/TaskWolf #95 (merged0add6df): live mkdocsrepo_url/repo_name+git clone-Beispiele aufWolfTasks/TaskWolf; Packagecom.taskowolf, Docker-Imageskwolfgang/taskowolf-*, DB-Name/User + historische Archive bewusst unverändert.🤖 Generated with Claude Code