open-telemetry / opentelemetry-configuration

JSON Schema definitions for OpenTelemetry file configuration
Apache License 2.0
36 stars 17 forks source link

[security] audit repository tooling #52

Closed EjiroLaurelD closed 1 month ago

EjiroLaurelD commented 1 year ago

Hello, The Security SIG is looking to ensure that security tooling is setup consistently across the organization. As a result, we're asking maintainers to ensure the following tools are enabled in each repository:

Parent issue: https://github.com/open-telemetry/sig-security/issues/12

jaydeluca commented 11 months ago

Just a note, since there is no functional code in this repository, CodeQL will not apply (I tested what it would do and it results in the github action failing with the error CodeQL did not detect any code written in languages supported by CodeQL.). The same for Static code analysis.

tsloughter commented 1 month ago

I thought most Otel repos has moved to renovate from dependabot? Can either be used?

codeboten commented 1 month ago

I thought most Otel repos has moved to renovate from dependabot? Can either be used?

This is true for dependency management, dependabot is still used for security alerts though

codeboten commented 1 month ago

The last item (govulncheck) was addressed, marking this issue closed