Skip to content

New page idea: Security #808

Description

@henryiii

I think we should probably add a page on security. I think it could include the following for starters:

  • GitHub Actions security feat: add security page, zizmor #798
    • New check family
    • Some reasoning for zizmor checks
    • Maybe we could upstream, or mention, my secure-ci skill
  • Pre-commit security (warning about hash pinning being something you can spoof)
  • Discussion of lock files and latest install dates
  • Discussion of cooldowns (dependabot supports them) docs: add cooldown #820
  • Pip audit and uv audit
  • Eventually: SBOMs

Open to ideas!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions