# 1838 005 Tq Secu Security Status 300203eb

> Security Status – Automations Setup

- Skill: `tools-only/1838-005-tq-secu-security-status-300203eb` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add tools-only/1838-005-tq-secu-security-status-300203eb`
- Raw SKILL.md: https://api.skillmd.com/api/skills/tools-only/1838-005-tq-secu-security-status-300203eb/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: tools-only (https://skillmd.com/u/tools-only)
- Updated: 2026-09-22
- Page: https://skillmd.com/skills/tools-only/1838-005-tq-secu-security-status-300203eb

---

# Security Status – Automations Setup

Date: 2025-10-15

Before: 1 Dependabot alert (0 High/Critical), 33 CodeQL alerts (no High/Critical)
After: 1 Dependabot alert (awaiting bot PR), CodeQL workflows enabled and passing; no secret scanning alerts.

Actions in this PR:
- Enabled Dependabot (npm, GitHub Actions)
- Enabled CodeQL default analysis (push, PR, weekly)
- Added weekly security audit sweep workflow
- Added auto-merge for Dependabot minor updates
- Augmented PR template with security checks
- Set repository watch level to Participating/@mentions (for the current account)
- Enabled secret scanning & push protection (where available)
- Prepared branch protection to require PR + checks

Next steps:
- Approve Dependabot PRs; they will auto-merge after green checks
- Dismiss low-severity CodeQL notes with justification if noisy
- Rotate any credentials if future secret alerts appear


