R&D Security: Strengthen DevSecOps Practices
Open
- Dominant language
- No language data
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
Identify and address weak points in our CI/CD pipeline and overall DevSecOps posture. Include static analysis, secrets scanning, and RBAC audits.
Acceptance Criteria
- Enable GitHub Advanced Security (if applicable)
- Integrate SAST tools (e.g., Semgrep)
- Update onboarding/security checklists
Contributor guide
Assessment
This issue has not been assessed yet.