hashgraph / hedera-sdk-go

Hedera™ Hashgraph SDK for Go
https://docs.hedera.com/docs/hedera-sdks
Apache License 2.0
108 stars 65 forks source link

ci: [2024-Q3] CI/CD Audit Story #1007

Open rbarkerSL opened 3 months ago

rbarkerSL commented 3 months ago

Contents

Administrative Audit Criteria

Check Actions State

Check if Actions should be disabled

If actions have not been run in the previous 6 months they should be disabled:

Repository Settings Checks

App Integrations

If actions are enabled:

Security Checks

Custom Properties

Non-Administrative Audit Criteria

Dependabot

Workflow checks

Self Hosted Runners

CODEOWNERS

Other


Repository Settings


Acceptance Criteria

mishomihov00 commented 2 weeks ago

@rbarkerSL @andrewb1269hg In the build.yml and main.yml workflows there are multiple places with a hard-coded key.

mishomihov00 commented 2 weeks ago

The non-administrative checks are done. @andrewb1269hg assigning over to you.

rbarkerSL commented 4 days ago

@rbarkerSL @andrewb1269hg In the build.yml and main.yml workflows there are multiple places with a hard-coded key.

We will need to add the keys as secrets and then open up a freshdesk ticket for regenerating the keys with the appropriate repository owners.