Skip to content

DevSecOps workshop v0.1.0 — rehearsal prerelease

Pre-release
Pre-release

Choose a tag to compare

@frye frye released this 22 Sep 01:04
· 2 commits to main since this release

DevSecOps workshop v0.1.0 prerelease

The complete live and take-home kit is available for review and rehearsal. It is not yet event-ready: fresh browser-only walkthroughs, independent learner completion, and the 75-minute human timing budget remain unverified.

Create your application from the original Pets template. This companion supplies the guides, helper, workflows, fixtures, and solutions; it is not an application template.

Start with Step 0. It includes account selection, a version-pinned Git fetch/archive route, equivalent raw-file copying, security settings, and the initial PR. Only two workflows are installed during live prework. The third belongs to the facilitator and take-home release lab.

Version and integrity

The annotated v0.1.0 tag resolves to companion commit:

fac20d7cabc3bf7a1509b96f4e7e082e855d543e

Compare that value with git rev-parse 'FETCH_HEAD^{commit}' after fetching the tag as described in Step 0.

The uploaded devsecops-workshop-kit-0.1.0.zip has SHA-256:

820fe4a4ce9dacd615aa39f46227fdb338a09f3f892123c8bc81533ef418d6d9

The sidecar checksum and the kit's file inventory are included. The tested original Pets revision is d2437a6f3dbb1fe4bd5e97790ccc12c42cbfc03a.

Observed checks

The local suite passed 33 cases. Native Ubuntu and Windows Git Bash runs each passed 20 helper tests and three fetch/manifest tests. The starters passed actionlint, and the kit was built twice with identical bytes.

The authorized rehearsal observed the CodeQL debug finding and repair, dependency advisory failure and repair, an inactive GitHub Skills fixture blocked at push and repaired without bypass, enforced merge blocks, and an approved same-revision release receipt. Non-main release dispatch was rejected; manual-main execution repeated prerequisites and waited for approval.

See the readiness register for run links and remaining gates. The take-home index includes resume, merge-policy, release, dependency-maintenance, troubleshooting, and solution material.

The application and other workshops in github-samples/pets-workshop were not changed upstream. Existing dependency alerts are not claimed resolved by this workshop.