github-samples / github-samples/pets-workshop
GitHub security workshop: Add security overview, governance, and rollout exercise
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 80
- Forks
- 161
- Avg merge
- 31m
- Merged PRs (30d)
- 1
Description
Goal
Close the workshop by connecting repository alerts to triage operations and organization-wide security rollout decisions.
Scope
Teach alert ownership, prioritization, campaign or backlog planning, coverage visibility, metrics, exceptions, and rollout sequencing. Use organization Security Overview when available, with repository-level sample data and screenshots as a complete fallback for personal-account learners.
Acceptance criteria
- Learners review code scanning, secret scanning, and dependency findings in a unified triage exercise.
- The exercise prioritizes findings by exploitability, severity, exposure, and remediation availability rather than raw count alone.
- Learners assign an owner, target date, and disposition to a small sample backlog.
- Organization-level coverage and Security Overview concepts are explained with current entitlement requirements.
- A repository-level fallback provides equivalent learning when organization access is unavailable.
- The exercise covers staged enablement, developer communication, bypass and dismissal governance, remediation SLAs, and measuring adoption.
- Learners produce a concise rollout plan for a fictional shelter organization.
- Final cleanup confirms training alerts, vulnerable branches, test values, and temporary rulesets are removed.
- The workshop README includes a completion checklist and next-step resources.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the workshop README and its existing repository-level sample data and screenshots. Map the exercise to the listed security findings, triage and rollout topics, then add the completion checklist and next-step resources; done means every acceptance criterion is covered and training alerts, vulnerable branches, test values, and temporary rulesets are removed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100