Skip to content

Application security in CI #68

@smlx

Description

@smlx

This issue tracks the rollout of application security in CI.

Requires workflow updates:

  • Dependabot Version updates
  • dependency review
  • OpenSSF scorecard and best practices (badges in README)
  • release artifact attestation
  • release SBOMs
  • coverage, if possible (badge in README) Only integration tests available.
  • code linters

Requires repository config updates, after workflows updates are merged:

  • Dependabot Alerts
  • Dependabot Security updates
  • CodeQL
  • secret scanning and push protection
  • private vulnerability reporting

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions