GSA / fedramp-automation

FedRAMP Automation
https://www.fedramp.gov/using-the-fedramp-oscal-resources-and-templates/
Other
277 stars 85 forks source link

Explicitly pin versions of tool dependencies #692

Open aj-stein-gsa opened 2 weeks ago

aj-stein-gsa commented 2 weeks ago

This is a ...

improvement - something could be better

This relates to ...

User Story

As a FedRAMP Automation Team developer, to have precise understanding and control of my how source code and data are processed, I would like the build tool and how it executes npx oscal ... to use pinned versions and explicitly define which version CI/CD uses and not just the most recent version by use of the npx oscal use latest alias.

Goals

Dependencies

N/A

Acceptance Criteria

Other information

N/A

aj-stein-gsa commented 2 weeks ago

Sorry I will be the source of unfun security nerd requests I am happy to discuss, but will ping specifically @wandmagic for awareness.