Would you take a pull-request security scan workflow?

Author: ralyodioCreated Aug 14, 2026Updated Aug 14, 2026

Would a pull-request security scan be useful here, or is this already covered?

One workflow. On each pull request it scans the checked-out repository for hardcoded credentials, injection, SSRF and unsafe deserialisation, and writes findings to the Security tab. Report-only — findings never fail the build.

Two files under .github/, a pinned @profullstack/[email protected] whose tarball is hashed before install, and pull_request rather than pull_request_target.

A pull request is open alongside this with the diff, if reading it is easier than discussing it.

Disclosure: I maintain ThreatCrush; MIT and free. Written with AI assistance. Closing this is a fine answer and I will not ask again.