envoyproxy / envoyproxy/java-control-plane
Install Security Policy App: Allstar
- Ngôn ngữ chính
- Java
- Star
- 312
- Fork
- 149
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Mô tả
I'd like to install Allstar https://github.com/ossf/allstar https://github.com/apps/allstar-app on this repo as a trail for eventually enabling on all envoyproxy org repos.
Allstar checks repos for violations against configured security policies, and takes actions when out of compliance:
Policies:
- Branch Protection settings
- SECURITY.md present
- No non-org Admins (outside collaborators)
- No binary artifacts.
Actions:
- Create a GitHub Issue
- Fix the issue (being developed)
Which policies to enable and which action to take are configured via config files in either an org-level repo named `.allstar` or files in the individual repo. This lets org owners control the main repo to manage settings.
I'll work with the org-owners to get it installed and configured with settings appropriate for the Envoy community.
cc @lizan @htuch @mattklein123
Hướng dẫn đóng góp
Hướng nghiên cứu
Bắt đầu với repository Allstar và GitHub App được liên kết trong issue, sau đó xem xét cách cung cấp cấu hình thông qua repository .allstar ở cấp tổ chức hoặc các tệp riêng của từng repository. Phối hợp với các chủ sở hữu tổ chức về những policy và action cần bật. Công việc được xem là hoàn tất khi Allstar được cài đặt trên repository này và được cấu hình với các thiết lập phù hợp với cộng đồng Envoy.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- github
- Lĩnh vực
- security
- Loại issue
- Tính năng
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức độ hoạt động
- Đình trệ
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 35/100