github-samples / github-samples/pets-workshop

GitHub security workshop: Add security overview, governance, and rollout exercise

Open
#278 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

priority: deferred
Dominant language
Python
Stars
80
Forks
161
Avg merge
31m
Merged PRs (30d)
1

Description

Goal

Close the workshop by connecting repository alerts to triage operations and organization-wide security rollout decisions.

Scope

Teach alert ownership, prioritization, campaign or backlog planning, coverage visibility, metrics, exceptions, and rollout sequencing. Use organization Security Overview when available, with repository-level sample data and screenshots as a complete fallback for personal-account learners.

Acceptance criteria

  • Learners review code scanning, secret scanning, and dependency findings in a unified triage exercise.
  • The exercise prioritizes findings by exploitability, severity, exposure, and remediation availability rather than raw count alone.
  • Learners assign an owner, target date, and disposition to a small sample backlog.
  • Organization-level coverage and Security Overview concepts are explained with current entitlement requirements.
  • A repository-level fallback provides equivalent learning when organization access is unavailable.
  • The exercise covers staged enablement, developer communication, bypass and dismissal governance, remediation SLAs, and measuring adoption.
  • Learners produce a concise rollout plan for a fictional shelter organization.
  • Final cleanup confirms training alerts, vulnerable branches, test values, and temporary rulesets are removed.
  • The workshop README includes a completion checklist and next-step resources.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the workshop README and its existing repository-level sample data and screenshots. Map the exercise to the listed security findings, triage and rollout topics, then add the completion checklist and next-step resources; done means every acceptance criterion is covered and training alerts, vulnerable branches, test values, and temporary rulesets are removed.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.