jupyter / jupyter/security

Providing a Jupyter enterprise level Security Configuration for orgs to opt-in to

Open
#106 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Jupyter Notebook
Stars
27
Forks
12
Avg merge
3d 5h
Merged PRs (30d)
3

Description

It is possible to [create a Security Configuration](https://docs.github.com/en/enterprise-cloud@latest/admin/managing-code-security/securing-your-enterprise/creating-a-custom-security-configuration-for-your-enterprise) in the [Jupyter GitHub enterprise](https://github.com/enterprises/jupyter), that can be adopted within organizations.

However, only one such configuration can be adopted by repositories. Due to that, whatever we define ought to include as much as reasonable to be accepted by many orgs. In JupyterHub we are now piloting a "GitHub Recommended minus Code scanning with CodeQL" Security Configuration, after having piloted the "GitHub recommended" and [being unhappy about CodeQL](https://github.com/jupyter/security/issues/102#issuecomment-2808850179). JupyterHubs use of a Security Configuration is tracked in https://github.com/jupyterhub/team-compass/issues/768.

I think for now we can wait, but that we should define a Security Configuration on the enterprise level, and ask that orgs consider opting in to it.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.