strangelove-ventures / heighliner

Repository of docker images for the node software of Cosmos chains
Apache License 2.0
57 stars 51 forks source link

supplychainsecurity: apply supply chain security recommendations #66

Open odeke-em opened 1 year ago

odeke-em commented 1 year ago

Coming here from the results of a supply chain security analysis of this repository that we Orijtech Inc engaged Chainguard Inc, to perform on behalf of the Cosmos ecosystem. The report is at https://cyber.orijtech.com/scsec/cosmos-v1 or in PDF standalone https://cyber.orijtech.com/chainguard_cosmos_v1.pdf#page20

Tasks

agouin commented 1 year ago

Thanks @odeke-em !

We will take a look at these. To start:

odeke-em commented 1 year ago

Thank you @agouin! Great to see. One thing I can also request is ensuring code reviews and approvals of PRs before merge per https://github.com/strangelove-ventures/heighliner/settings/branch_protection_rules/new?branch_name=main

Screen Shot 2022-11-29 at 12 12 57 AM