Skip to content

Add Destructive Command Guard workflow#249

Open
wheeljackz wants to merge 3 commits intomainfrom
wheeljack/setup-destructive-command-guard
Open

Add Destructive Command Guard workflow#249
wheeljackz wants to merge 3 commits intomainfrom
wheeljack/setup-destructive-command-guard

Conversation

@wheeljackz
Copy link
Copy Markdown
Collaborator

@wheeljackz wheeljackz commented Apr 27, 2026

Summary

  • Add a conservative Destructive Command Guard workflow for repository-wide scan coverage.
  • Pin DCG to v0.4.5 and install the Linux binary directly because the published composite action tag/installer currently does not resolve successfully on GitHub Actions.
  • Keep permissions read-only and fail only on error-severity findings.

Validation

  • YAML parsed with Ruby YAML loader.
  • git diff --check passed.
  • GitHub Actions DCG job is now running from the direct binary installer.

Current check result

  • DCG check passes on the PR branch.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant