Skip to content

ci: use centralized vuln remediation workflow from infra#192

Open
ulziibay-kernel wants to merge 3 commits intomainfrom
security/vuln-remediation-reusable
Open

ci: use centralized vuln remediation workflow from infra#192
ulziibay-kernel wants to merge 3 commits intomainfrom
security/vuln-remediation-reusable

Conversation

@ulziibay-kernel
Copy link
Copy Markdown
Contributor

@ulziibay-kernel ulziibay-kernel commented Apr 9, 2026

Replace per-repo workflow + prompt with a thin caller that invokes the reusable 3-stage pipeline (triage → fix → PR) in kernel/infra. Per-repo config in .github/vuln-remediation.json.

Made with Cursor


Note

Low Risk
Low risk: adds a scheduled/manual GitHub Actions workflow and a minimal socket.yml config file; no application/runtime code changes.

Overview
Introduces a scheduled + manually-triggerable Vulnerability Remediation GitHub Actions workflow that delegates to the centralized reusable workflow in kernel/security-workflows, with permissions to open PRs and commit fixes.

Adds a minimal socket.yml (version: 2) to enable Socket configuration for dependency/vulnerability tooling.

Reviewed by Cursor Bugbot for commit 68e0690. Bugbot is set up for automated code reviews on this repo. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant