Automating the BIST Code Security Checklist #250
sumau
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Objective
Replace the manually maintained code security checklist with a centrally owned system in
uktrade/github-standardsthat automatically creates, maintains and validates it organisation-wide.Artefacts to build or configure
github-standardscode_security_checklist.mdand creates or updates a checklist PR. The checklist PR can only be merged when all mandatory controls pass.github-standardscode_security_enrolled = True.reusable_workflow_opt_in.CODEOWNERShave completed requirements (see below for more details). Ideally this should check against a learning provider' API but this is a flexible workaround that integrates easily with GitHub workflows.scs_portfoliocustom property is populated.SECURITY.mdfile.code_security_checklist.md)github-standardsMaintainer Compliance Check
(member × requirement)record as:Checklist items to skip
repository visibility = public.reusable_workflow_opt_in/code_security_enrolled = TrueAll reactions