github-samples / github-samples/pets-workshop
GitHub security workshop: Add a safe secret scanning and push protection lab
Nessuno ha ancora preso questa issue.
- Lingua principale
- Python
- Stelle
- 80
- Fork
- 161
- Merge medio
- 31m
- PR unite (30g)
- 1
Descrizione
Goal
Let learners experience a blocked push and the secret alert workflow without creating or publishing a usable credential.
Scope
Use only a GitHub-documented, non-sensitive test pattern that is guaranteed to exercise push protection at the time the workshop is validated. The test value must be generated or copied during the exercise and must not be stored in the template history. Cover the blocked push, remediation, bypass governance, alert review, and cleanup.
Acceptance criteria
- Learners enable or verify secret scanning and push protection using current settings guidance.
- The exercise links to the authoritative source for an approved non-sensitive test pattern.
- No token-like test value is committed to this template repository.
- Learners attempt the demonstration on a disposable branch and observe a blocked push.
- The exercise explains why inventing an arbitrary fake string may not match a supported pattern.
- Learners remove the value and successfully push the cleaned commit.
- Bypass reasons, delegated bypass, alert ownership, and auditability are explained without requiring a bypass.
- A fallback path is provided when push protection cannot be enabled.
- Final verification confirms no secret or test pattern remains in branch history.
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Direzione di ricerca
Inizia individuando il contenuto del template del workshop in github-samples/pets-workshop e rivedendo la documentazione GitHub attuale su secret scanning, push protection, i pattern di test approvati, la governance dei bypass e gli alert. Convalida l’esercizio su un branch usa e getta, includendo il push bloccato, la pulizia, il percorso di fallback e il controllo finale della cronologia; è completato quando ogni criterio di accettazione funziona senza memorizzare una credenziale utilizzabile.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- github
- Ambito
- documentation, security
- Tipo di issue
- Documentazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Stato di attività
- Attiva
- Chiarezza
- Specificata chiaramente
- Idoneità per principianti
- 55/100