hashgraph / hedera-json-rpc-relay

Implementation of Ethereum JSON-RPC APIs for Hedera
Apache License 2.0
68 stars 72 forks source link

ci: [2024-Q3] CI/CD Audit Story #2732

Open rbarkerSL opened 3 months ago

rbarkerSL commented 3 months ago

Contents

Administrative Audit Criteria

Check Actions State

Check if Actions should be disabled

If actions have not been run in the previous 6 months they should be disabled:

Repository Settings Checks

App Integrations

If actions are enabled:

Security Checks

Custom Properties

Non-Administrative Audit Criteria

Dependabot

Workflow checks

Self Hosted Runners

CODEOWNERS

Other


Repository Settings


Acceptance Criteria

mishomihov00 commented 2 weeks ago

@andrewb1269hg @rbarkerSL In the image-build.yaml workflow on line 51 there is a hard-coded key. Also dependabot.yaml is not created as I'm not sure if that's enough to enable dependabot checks on this repo.

mishomihov00 commented 2 weeks ago

Non-administrative checks are done. @andrewb1269hg assigning over to you.