Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve supply chain security #49

Open
9 tasks
alpe opened this issue Jan 8, 2024 · 1 comment
Open
9 tasks

Improve supply chain security #49

alpe opened this issue Jan 8, 2024 · 1 comment

Comments

@alpe
Copy link
Contributor

alpe commented Jan 8, 2024

I found some nice examples in https://github.com/sozercan/aikit/tree/main/.github/workflows

Not related to supply chain security but code quality

  • add codeql GH action
  • add linter GH action
  • add gosec
@samos123
Copy link
Contributor

I'm all for security improvements, but at the same need to ensure that:

  • doesn't make it more painful to do releases and development on the project
  • doesn't hurt the UX
  • doesn't significantly increase complexity

I think all of your tasks make sense, except Harden Runner might make adding and updating GH workflows a bit more painful, but at the same time it does seem good to prevent malicious PRs as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants