-
Notifications
You must be signed in to change notification settings - Fork 17
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[security] audit repository tooling #52
Comments
Just a note, since there is no functional code in this repository, CodeQL will not apply (I tested what it would do and it results in the github action failing with the error |
This will validate changes to the code in this repo. Part of open-telemetry#52 Signed-off-by: Alex Boten <[email protected]>
This will validate changes to the code in this repo. Part of #52 Signed-off-by: Alex Boten <[email protected]>
I thought most Otel repos has moved to renovate from dependabot? Can either be used? |
This addresses one of the items in the checklist for open-telemetry#52 Signed-off-by: Alex Boten <[email protected]>
This is true for dependency management, dependabot is still used for security alerts though |
This addresses one of the items in the checklist for #52 --------- Signed-off-by: Alex Boten <[email protected]>
The last item (govulncheck) was addressed, marking this issue closed |
Hello,
The Security SIG is looking to ensure that security tooling is setup consistently across the organization. As a result, we're asking maintainers to ensure the following tools are enabled in each repository:
Parent issue: open-telemetry/sig-security#12
The text was updated successfully, but these errors were encountered: