Skip to content
This repository has been archived by the owner on Nov 21, 2024. It is now read-only.

[security] audit repository tooling #74

Open
2 of 8 tasks
EjiroLaurelD opened this issue Oct 21, 2023 · 0 comments
Open
2 of 8 tasks

[security] audit repository tooling #74

EjiroLaurelD opened this issue Oct 21, 2023 · 0 comments

Comments

@EjiroLaurelD
Copy link

Hello,
The Security SIG is looking to ensure that security tooling is setup consistently across the organization. As a result, we're asking maintainers to ensure the following tools are enabled in each repository:

  • CodeQL enabled via GitHub Actions
  • Static code analysis tool (the collector uses govulncheck [https://pkg.go.dev/golang.org/x/vuln] on every build)
  • Repository security settings
    • Security Policy ✅
    • Security advisories ✅
    • Private vulnerability reporting ✅
    • Dependabot alerts ✅
    • Code scanning alerts ✅

Parent issue: open-telemetry/sig-security#12

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant