Review github actions against ToC recommendations and update
- Dominant language
- C#
- Stars
- 8
- Forks
- 11
- Avg merge
- 5h 39m
- Merged PRs (30d)
- 1
Description
This project doesn't have a regular CVE scan configured and has not been updated in some time. Its Github actions should be reviewed against the current FINOS ToC standard and updated to the latest recommendations.
It does run CVE scans on PRs, but the action has not been updated in some time and is not scheduled to run against main. Other workflows are also likely in need of updates.
Contributor guide
Research direction
Start by inventorying the GitHub Actions workflows and reviewing the existing CVE scan configuration against the current FINOS ToC standard. Check which workflows need updates and how the scan currently runs on pull requests. Done means the actions follow the latest recommendations and the CVE scan also runs on a schedule against main.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd, devops, security
- Issue type
- Refactor
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100