open-telemetry / opentelemetry-network

eBPF Collector
https://opentelemetry.io
Apache License 2.0
278 stars 46 forks source link

[security] audit repository tooling #236

Open sakshi-1505 opened 12 months ago

sakshi-1505 commented 12 months ago

Describe the issue you're reporting

The security SIG is looking to ensure that security tooling is setup consistently across the organization. As a result, we're asking maintainers to ensure the following tools are enabled in each repository:

Parent issue: https://github.com/open-telemetry/sig-security/issues/12

sakshi-1505 commented 12 months ago

@bjandras Please confirm if the dependabot alerts & scanning alerts are enabled for the repository. I do see trivy checks in the actions so I guess we can mark-out the static code analysis tool, I will raise a PR for codeQL check. Please let me know if the plan of action seems correct.

sakshi-1505 commented 12 months ago

\assign