How ICTU uses GitHub.
ICTU projects and employees using GitHub should comply with the following guidelines:
- Users have GitHub 2FA authentication turned on.
- New users and users leaving are reported to Frank Niessink.
- Repositories have Dependabot alerts turned on and alerts are monitored.
- Repositories have Code scanning alerts turned on and alerts are monitored.
- Repositories have a
README.mdfile describing the project. - Repositories have a
LICENSEfile. - Repositories have a
SECURITY.mdfile in the root of the repository explaining the security status and point of contact for the project. See SECURITY.md for an example. - Inactive repositories (meaning no activity for over one year) are archived.
- Inactive forks (meaning no activity on the fork for over two years) are archived.