OWASP / OWASP/OpenCRE

Continuity runbook: Access inventory

Open
#1,061 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

existing-maintainers-only
Dominant language
Python
Stars
180
Forks
137
Avg merge
3d 23h
Merged PRs (30d)
21

Description

Task

A second existing maintainer can prove they have (or lack) every login needed to operate OpenCRE without Spyros — Heroku opencreorg, GitHub OWASP/OpenCRE, Actions environments, DNS for opencre.org — without dumping secrets.

Success criteria

  • Runbook docs/continuity/runbooks/access-inventory.md followed (Cursor skill continuity-access-inventory)
  • Issue comment: PASS/FAIL/UNKNOWN table for GitHub, Heroku prod, Heroku staging (tmp-cre), config names only, DNS, addons, local CLIs
  • No heroku config values, DATABASE_URL, or API keys in this issue
  • FAIL rows have an owner who can grant access (Heroku vs domain vs GitHub)

Context

  • Index: docs/continuity/README.md
  • Skill: .cursor/skills/continuity-access-inventory/SKILL.md
  • Team notes: second person on Heroku (keys live there); Rob checks opencre.org (reportedly Google)

Constraints

  • existing maintainers only — not GSoC, not drive-by
  • Do not add collaborators or change DNS until a maintainer explicitly asks after the report
  • Agent prompt is in the runbook — paste it into Cursor

Agent prompt

See Agent prompt in docs/continuity/runbooks/access-inventory.md.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with docs/continuity/runbooks/access-inventory.md and .cursor/skills/continuity-access-inventory/SKILL.md, using docs/continuity/README.md for context. Follow the runbook as an existing maintainer and record a PASS/FAIL/UNKNOWN table covering the named systems, config names, addons, and local CLIs without exposing secrets; completion also requires owners for FAIL rows.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
devops, documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.