envoyproxy / envoyproxy/java-control-plane

Install Security Policy App: Allstar

オープン
#170 コメント 6 件 リアクション 1 件 担当者 0 名 GitHub で見る
主要言語
Java
スター
312
フォーク
149
PR マージ指標
30日以内にマージされた PR はありません

説明

I'd like to install Allstar https://github.com/ossf/allstar https://github.com/apps/allstar-app on this repo as a trail for eventually enabling on all envoyproxy org repos.

Allstar checks repos for violations against configured security policies, and takes actions when out of compliance:

Policies:
- Branch Protection settings
- SECURITY.md present
- No non-org Admins (outside collaborators)
- No binary artifacts.

Actions:
- Create a GitHub Issue
- Fix the issue (being developed)

Which policies to enable and which action to take are configured via config files in either an org-level repo named `.allstar` or files in the individual repo. This lets org owners control the main repo to manage settings.

I'll work with the org-owners to get it installed and configured with settings appropriate for the Envoy community.
cc @lizan @htuch @mattklein123

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。