Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Secure-by-default templates #2074

Open
3 tasks
varunsh-coder opened this issue Apr 12, 2023 · 1 comment
Open
3 tasks

Secure-by-default templates #2074

varunsh-coder opened this issue Apr 12, 2023 · 1 comment
Labels
enhancement New feature or request

Comments

@varunsh-coder
Copy link
Member

varunsh-coder commented Apr 12, 2023

In addition to fixing GitHub Actions workflows and Dockerfiles, we should also plan to show secure-by-default templates for common scenarios.

  • GitHub Actions for publishing scenarios that use OIDC, minimum token-permissions etc
  • Dockerfiles for common scenarios with security best practices implemented
  • OpenSSF SLSA Generator, recently released npm provenance generator

We can expand to secure-by-default templates for other as code files, Terraform/ CloudFormation etc in the future.

@varunsh-coder varunsh-coder added the enhancement New feature or request label Apr 12, 2023
@varunsh-coder
Copy link
Member Author

We could also auto-generate reusable workflows based on an organization's current workflows.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant