Skip to content

Project and validate the public-repository security baseline #60

Description

@jmcte

Problem statement

Current security projection is incomplete and GitHub Actions are not uniformly pinned to immutable SHAs.

Desired outcome

Managed public repositories receive the full v1 security baseline and clear plan-capability results.

Scope

  • Secret, dependency, code scanning; SBOM; private reporting; security contact/response policy.
  • Immutable action pins and update automation.
  • Fork-safe permissions and no secret exposure.

Non-goals

  • Purchasing GitHub features or weakening requirements silently.

Acceptance criteria

  • Required controls are projected and validated.
  • All third-party actions use immutable SHAs with readable update metadata.
  • Fork tests prove secrets are unavailable.
  • Unsupported plan features are reported distinctly with remediation.

Test expectations

Begin with failing unpinned-action, permission, missing-control, SBOM, and fork-event fixtures.

Security implications

Independent security review and threat-focused workflow testing are required.

Documentation implications

Generate security model and response targets.

Dependencies

Projection and conformance issues.

Human decision points

Security waivers and exposure of previously private data.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions