Feature request : Add a security policy, add an easy way to track outdated templates
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 226
- Forks
- 451
- Avg merge
- 2d 17h
- Merged PRs (30d)
- 23
Description
As many people will use these templates for self-hosting public facing instance of templates in this repository we should add a security policy to help people report security problems with for example outdated templates or misconfigured ones.
Also, it probably would be nice to have a simple way for maintainers and contributors of this repository to have a script to check for outdated version of templates. This will allow contributors to know which templates require attention and need update in an easy way. It would be even better if this can be run with a github action and published in an md file in this repository.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the repository's templates and existing GitHub configuration to determine how template versions are represented and where an automated check could run. Define the security-reporting guidance and the outdated-template report format. Done means contributors can report security problems and a repeatable check identifies outdated templates and publishes its results in a Markdown file.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd, documentation, security, tooling
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 30/100