Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Install Security Policy App: Allstar #170

Open
jeffmendoza opened this issue Jul 22, 2021 · 6 comments
Open

Install Security Policy App: Allstar #170

jeffmendoza opened this issue Jul 22, 2021 · 6 comments

Comments

@jeffmendoza
Copy link
Contributor

I'd like to install Allstar https://github.com/ossf/allstar https://github.com/apps/allstar-app on this repo as a trail for eventually enabling on all envoyproxy org repos.

Allstar checks repos for violations against configured security policies, and takes actions when out of compliance:

Policies:

  • Branch Protection settings
  • SECURITY.md present
  • No non-org Admins (outside collaborators)
  • No binary artifacts.

Actions:

  • Create a GitHub Issue
  • Fix the issue (being developed)

Which policies to enable and which action to take are configured via config files in either an org-level repo named .allstar or files in the individual repo. This lets org owners control the main repo to manage settings.

I'll work with the org-owners to get it installed and configured with settings appropriate for the Envoy community.
cc @lizan @htuch @mattklein123

@asraa
Copy link

asraa commented Jul 22, 2021

Thanks! Just to reiterate: as of right now these policies should be passing on envoy repos, so there shouldn't be any noise. It will alert on changes.

@htuch
Copy link
Member

htuch commented Jul 23, 2021

This seems reasonable to me. @snowp?

@asraa
Copy link

asraa commented Jul 28, 2021

friendly ping @snowp?

@snowp
Copy link
Contributor

snowp commented Jul 28, 2021

Already talked to @htuch on Slack about this, I'm in favor of this

@asraa
Copy link

asraa commented Jul 28, 2021

Awesome, sorry about that! @jeffmendoza and I can make a PR for the configuration YAML

@htuch
Copy link
Member

htuch commented Jul 29, 2021

I've installed the app, please update when it's functional at your end :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants