Skip to content
This repository was archived by the owner on Sep 22, 2025. It is now read-only.
David Samuel edited this page Dec 1, 2023 · 32 revisions

GitHub Policy

This repository attempts to demonstrate how colleagues can implement the GitHub Policy (Link to internal site, not accessible externally) created by ONS' Software Engineering Community.

Repository Management

Collaboration and Communication

Security and Compliance

6.1 Privacy Settings 6.2 Security

6.3 Compliance

Source todo link to sharepoint document

  1. Continuous Integration and Deployment (CI/CD) 6.1 CI/CD Pipelines: Where appropriate use GitHub Actions to implement CI/CD pipelines to automate testing, building, and deployment processes. Action for Daniel O’Brien: Provide recommendation/policy for using the GitHub Action.
  2. Reporting Issues 7.1 Reporting Security Concerns: Report security vulnerabilities or suspicious activities immediately to the appropriate contact within the Organization or follow the established incident reporting procedures. Action for Fahad: Link to Security (Depenabot alert is not included in it)
  3. Compliance and Enforcement 8.1 Policy Violations: Violations of this GitHub Usage Policy may result in consequences, including warnings, access revocation, or other disciplinary actions, as determined by the Organisation. 8.2 Policy Enforcement Teams: Designate a policy enforcement team or individual responsible for monitoring and enforcing policy compliance. 8.3 Periodic Audits: Conduct periodic audits of repositories, teams, and access permissions to ensure compliance. Use automation to assist in auditing and reporting.

Clone this wiki locally