security-compliance - Security & Compliance Guardian
Establish comprehensive security scanning and compliance infrastructure from scratch.
Tags
Updated: 2026-09-15Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Create CodeQL security scanning workflow
- Configure Dependabot automated updates
- Create SECURITY.md policy file
- Add PR dependency review gate
- Generate SBOM and sign artifacts
Inputs
- GitHub repository
- Source code
- Project dependencies
Outputs
- CodeQL workflow file
- Dependabot configuration file
- SECURITY.md file
- SBOM file
- Signed release artifacts
Requirements
- GitHub Actions
- Security events write permission
- .NET SDK
