Governance
Security policy, ownership, issue intake and dependency updates.
Awesome Maintainer Defense
Inspect local governance, GitHub Actions, and moderation automation. Turn evidence into proposed patches.
Python 3.10+ · MIT · v1.1.1
SECURITY.md
CODEOWNERS
.github/workflows/*.yml
maintainer-defense audit .
MD-WF-002 · HIGH
.github/workflows/
ci.yml:3
fix− permissions: write-all+ permissions: {}
Review, refine, and apply through your normal workflow.
Python 3.10+ required. Run these commands in your repository.
Recorded CLI output from a local test fixture. This page does not scan your repository.
Download exampleDownload and unzip the sample. From the folder containing maintainer-defense-example, run the command below.
Fixture based on the project test corpus · main@29ef246
Security policy, ownership, issue intake and dependency updates.
Token permissions, Action pins and untrusted input.
Destructive automation, identity proxies and appeal paths.
Preview local policy and workflow controls before applying. Kit assets support English, Vietnamese and Japanese.
Read-only PR analysis and job summary.
Adds a named failing status check; no comments, labels, closing or locking.
Adds dependency review and GitHub Actions static analysis.
maintainer-defense install --target . --profile observe --language enPreview is the default. Only explicit --apply writes kit files. Verify ownership before rolling back; modified files are preserved.
Read the kit guide