I think we should probably add a page on security. I think it could include the following for starters: * [x] GitHub Actions security #798 * New check family * Some reasoning for zizmor checks * Maybe we could upstream, or mention, my [secure-ci skill](https://github.com/henryiii/skills) * [x] Pre-commit security (warning about hash pinning being something you can spoof) * [ ] Discussion of lock files and latest install dates * [x] Discussion of cooldowns (dependabot supports them) #820 * [ ] Pip audit and uv audit * [ ] Eventually: SBOMs Open to ideas!
I think we should probably add a page on security. I think it could include the following for starters:
Open to ideas!