Skip to content

Commit

Permalink
chore: auto-update content
Browse files Browse the repository at this point in the history
  • Loading branch information
actions-user authored and UlisesGascon committed Dec 18, 2024
1 parent e602ad0 commit 18dc946
Show file tree
Hide file tree
Showing 72 changed files with 144 additions and 144 deletions.
4 changes: 2 additions & 2 deletions docs/details/MFAImpersonationDefense.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,6 @@ Use Multi Factor Authentication (MFA) Methods that Defend Against Impersonation
- Mitre: [CWE-290](https://cwe.mitre.org/data/definitions/290.html)
- Sources: [OpenSSF Best Practices Badge Gold Level [secure_2FA]](https://www.bestpractices.dev/en/criteria/2#2.secure_2FA)
- How To: [Github Docs](https://docs.github.com/en/authentication/securing-your-account-with-two-factor-authentication-2fa)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/PRsBeforeMerge.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,6 @@ Require Pull Requests before Merging
- Mitre: [CWE-778](https://cwe.mitre.org/data/definitions/778.html)
- Sources: [OpenSSF Scorecard](https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection)
- How To: [Github Docs](https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/about-protected-branches#require-pull-request-reviews-before-merging)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/SSHKeysRequired.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,6 @@ Use SSH keys for developer access to source code repositories and use a passphra
- Mitre: [CWE-309](https://cwe.mitre.org/data/definitions/309.html)
- Sources: [CNCF SSCP v1.0 #192](https://github.com/cncf/tag-security/blob/main/supply-chain-security/supply-chain-security-paper/sscsp.md#use-ssh-keys-to-provide-developers-access-to-source-code-repositories)
- How To: [Github Docs](https://docs.github.com/en/authentication/connecting-to-github-with-ssh/about-ssh)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/activeAdminsSixMonths.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ Github Organization Admins Should Have Activity In The Last 6 Months
- Priority Group: R3
- Mitre: [M1026](https://attack.mitre.org/mitigations/M1026/)
- Sources: [OpenSSF SCM Best Practices](https://best.openssf.org/SCM-BestPractices/github/member/stale_admin_found.html)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/activeWritersSixMonths.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ Github Organization Members with Write Permissions Should Have Activity In The L
- Priority Group: R3
- Mitre: [M1026](https://attack.mitre.org/mitigations/M1026/)
- Sources: [OpenSSF SCM Best Practices](https://best.openssf.org/SCM-BestPractices/github/member/stale_member_found.html)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/adminRepoCreationOnly.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,6 @@ Only Admins Should Be Able To Create Public Repositories
- Mitre: [CAPEC-122](https://capec.mitre.org/data/definitions/122.html)
- Sources: [OpenSSF SCM Best Practices](https://best.openssf.org/SCM-BestPractices/github/organization/non_admins_can_create_public_repositories.html)
- How To: [Github Docs](https://docs.github.com/en/organizations/managing-organization-settings/restricting-repository-creation-in-your-organization)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/annualDependencyRefresh.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ A new release to refresh dependencies occurs at least annually
- C-SCRM: true
- Priority Group: P14
- Sources: [OpenSSF Best Practices Badge Passing Level [maintained]](https://www.bestpractices.dev/en/criteria?details=true&rationale=true#0.maintained)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/assignCVEForKnownVulns.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ All Known Security Vulnerabilities are Issued a CVE
- C-SCRM: true
- Priority Group: P7
- Sources: [OpenSSF Best Practices Badge Passing Level [release_notes_vulns]](https://www.bestpractices.dev/en/criteria?details=true&rationale=true#0.release_notes_vulns)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/automateDependencyManagement.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ Automated Process is Used to Monitor for and Maintain a List of Out of Date Depe
- Priority Group: P14
- Sources: [OWASP SCVS L1 5.7](https://scvs.owasp.org/scvs/v5-component-analysis/)
- How To: [Socket.Dev](https://socket.dev/)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/automateVulnDetection.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,6 @@ An automated process to identify dependencies with publicly disclosed vulnerabil
- Mitre: [CWE-1395](https://cwe.mitre.org/data/definitions/1395.html)
- Sources: [OWASP SCVS L1 5.4](https://scvs.owasp.org/scvs/v5-component-analysis/)
- How To: [Github Docs](https://docs.github.com/en/code-security/dependabot/dependabot-security-updates/configuring-dependabot-security-updates#managing-dependabot-security-updates-for-your-repositories)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/blockWorkflowPRApproval.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,6 @@ Workflows are not Allowed To Create or Approve Pull Requests
- Mitre: [CWE-250](https://cwe.mitre.org/data/definitions/250.html)
- Sources: [OpenSSF Scorecard](https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions)
- How To: [Github Docs](https://docs.github.com/en/enterprise-cloud@latest/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise#preventing-github-actions-from-creating-or-approving-pull-requests)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/ciAndCdPipelineAsCode.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ CI/CD steps should all be automated through a pipeline defined as code
- Priority Group: P12
- Sources: [CNCF SSCP 1.0 #158](https://github.com/cncf/tag-security/blob/main/supply-chain-security/supply-chain-security-paper/sscsp.md#build-and-related-continuous-integrationcontinuous-delivery-steps-should-all-be-automated-through-a-pipeline-defined-as-code)
- How To: [Github Docs](https://docs.github.com/en/actions/publishing-packages/publishing-nodejs-packages)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/commitSignoffForWeb.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ Github Org Requires Commit Signoff for Web-Based Commits
- Priority Group: R4
- Sources: [CNCF SSCP 1.0 #325](https://github.com/cncf/tag-security/blob/main/supply-chain-security/supply-chain-security-paper/sscsp.md#require-signed-commits)
- How To: [Github Docs](https://docs.github.com/en/organizations/managing-organization-settings/managing-the-commit-signoff-policy-for-your-organization#managing-compulsory-commit-signoffs-for-your-organization)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/commitStatusChecks.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,6 @@ All Required Commit Status Checks must pass before Merging
- Mitre: [CWE-358](https://cwe.mitre.org/data/definitions/358.html)
- Sources: [OpenSSF Scorecard](https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection)
- How To: [Github Docs](https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/about-protected-branches#require-status-checks-before-merging)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/consistentBuildProcessDocs.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ Consistent and Automated Build Process is Documented and Used
- C-SCRM: true
- Priority Group: P12
- Mitre: [CWE-1068](https://cwe.mitre.org/data/definitions/1068.html)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/defaultTokenPermissionsReadOnly.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ Github Org Default Workflow Token Permissions are Set to Read Only
- C-SCRM: true
- Priority Group: P9
- Mitre: [CWE-250](https://cwe.mitre.org/data/definitions/250.html)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/defineFunctionalRoles.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,6 @@ Define roles aligned to functional responsibilities
- Mitre: [CAPEC-122](https://capec.mitre.org/data/definitions/122.html)
- Sources: [CNCF SSCP v1.0 #188](https://github.com/cncf/tag-security/blob/main/supply-chain-security/supply-chain-security-paper/sscsp.md#define-roles-aligned-to-functional-responsibilities)
- How To: [Github Docs](https://docs.github.com/en/organizations/managing-user-access-to-your-organizations-repositories/managing-repository-roles/repository-roles-for-an-organization)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/forkWorkflowApproval.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ Limit changes from forks to workflows by requiring approval for all outside coll
- Priority Group: R2
- Mitre: [CAPEC-180](https://capec.mitre.org/data/definitions/180.html)
- Sources: [Github Docs](https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository#controlling-changes-from-forks-to-workflows-in-public-repositories)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/githubOrgMFA.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,6 @@ We use the field `two_factor_requirement_enabled` from the GitHub Organization A
- Mitre: [CWE-308](https://cwe.mitre.org/data/definitions/308.html)
- Sources: [OpenSSF SCM Best PracticesOpenSSF Best Practices Badge Gold Level [require_2FA]](https://best.openssf.org/SCM-BestPractices/github/enterprise/enterprise_enforce_two_factor_authentication.html)
- How To: [Github Docs](https://docs.github.com/en/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/requiring-two-factor-authentication-in-your-organization)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/githubWebhookSecrets.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,6 @@ Github Webhooks Use Secrets
- Mitre: [CWE-306](https://cwe.mitre.org/data/definitions/306)
- Sources: [OpenSSF Scorecard](https://github.com/ossf/scorecard/blob/main/docs/checks.md#webhooks)
- How To: [Github Docs](https://docs.github.com/en/actions/security-guides/using-secrets-in-github-actions)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/githubWriteAccessRoles.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,6 @@ Define Individuals/Teams who Write Access to a Github Repo
- Mitre: [CAPEC-180](https://capec.mitre.org/data/definitions/180.html)
- Sources: [CNCF SSCP v1.0 #185](https://github.com/cncf/tag-security/blob/main/supply-chain-security/supply-chain-security-paper/sscsp.md#define-individualsteams-that-are-responsible-for-code-in-a-repository-and-associated-coding-conventions)
- How To: [Github Docs](https://docs.github.com/en/organizations/managing-user-access-to-your-organizations-repositories/managing-repository-roles/repository-roles-for-an-organization)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/identifyModifiedDependencies.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ Modified dependencies are uniquely identified and distinct from origin dependenc
- C-SCRM: true
- Priority Group: P14
- Sources: [OWASP SCVS L2 6.5](https://scvs.owasp.org/scvs/v6-pedigree-and-provenance/)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/incidentResponsePlan.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ Establish a Clear Communication and Incident Response Plan
- C-SCRM: false
- Priority Group: P7
- Sources: [OpenSSF SCM Best Practices](https://best.openssf.org/SCM-BestPractices/#operations)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/includeCVEInReleaseNotes.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ Release Notes must Include the CVE ID of Patched Security Vulnerabilities
- C-SCRM: false
- Priority Group: P7
- Sources: [OpenSSF Best Practices Badge Passing Level [release_notes_vulns]](https://www.bestpractices.dev/en/criteria?details=true&rationale=true#0.release_notes_vulns)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/includePackageLock.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ slug: /details/includePackageLock
- Priority Group: R5
- Sources: [OpenSSF Scorecard](https://github.com/ossf/scorecard/blob/main/docs/checks.md#sbom)
- How To: [npm Docs](https://docs.npmjs.com/cli/v10/commands/npm-sbom)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/injectedSecretsAtRuntime.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,6 @@ Secrets are injected at runtime, such as environment variables or as a file (eg:
- Mitre: [CWE-538](https://cwe.mitre.org/data/definitions/538.html)
- Sources: [CNCF CNSWP 2.0 #195](https://github.com/cncf/tag-security/blob/main/security-whitepaper/v2/cloud-native-security-whitepaper.md#secrets-encryption)
- How To: [Github Docs](https://docs.github.com/en/actions/security-guides/using-secrets-in-github-actions#creating-secrets-for-an-organization)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/limitOrgOwners.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ Limit Number of Github Org Owners (ideally Fewer Than Three)
- Priority Group: R7
- Mitre: [M1026](https://attack.mitre.org/mitigations/M1026/)
- Sources: [OpenSSF SCM Best Practices](https://best.openssf.org/SCM-BestPractices/github/member/organization_has_too_many_admins.html)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/limitRepoAdmins.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ Limit Number of Github Repository Admins (ideally Fewer Than Three)
- Priority Group: R7
- Mitre: [CAPEC-180](https://capec.mitre.org/data/definitions/180.html)
- Sources: [OpenSSF SCM Best Practices](https://best.openssf.org/SCM-BestPractices/github/repository/repository_has_too_many_admins.html)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/limitWorkflowWritePermissions.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,6 @@ Only Allow Workflows Write Permissions at the Job-Level
- Mitre: [CWE-250](https://cwe.mitre.org/data/definitions/250.html)
- Sources: [OpenSSF Scorecard](https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions)
- How To: [Github Docs](https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/machineReadableDependencies.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ slug: /details/machineReadableDependencies
- Priority Group: P14
- Sources: [OWASP SCVS L1 1.3](https://scvs.owasp.org/scvs/v1-inventory/#verification-requirements)
- How To: [Github Docs](https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-supply-chain-security#what-is-the-dependency-graph)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/noArbitraryCodeInPipeline.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ Build Pipeline Cannot Execute Arbitrary Code from Outside of a Build Script
- Priority Group: P11
- Mitre: [CWE-94](https://cwe.mitre.org/data/definitions/94.html)
- Sources: [OpenSSF Scorecard](https://github.com/ossf/scorecard/blob/main/docs/checks.md#dangerous-workflow)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/noForcePushDefaultBranch.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ Prevent Force Push on Default Branch
- Priority Group: P9
- Sources: [OpenSSF Scorecard](https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection)
- How To: [Github Docs](https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/about-protected-branches)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/noSelfHostedRunners.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,6 @@ Disable use of Self-Hosted Runners in Github Org
- Mitre: [CAPEC-439](https://capec.mitre.org/data/definitions/439.html)
- Sources: [Github Action Hardening Docs](https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#hardening-for-self-hosted-runners)
- How To: [Github Docs](https://docs.github.com/en/organizations/managing-organization-settings/disabling-or-limiting-github-actions-for-your-organization#limiting-the-use-of-self-hosted-runners)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/noSensitiveInfoInRepositories.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,6 @@ No Secrets and Credentials in Source Code
- Mitre: [CWE-540](https://cwe.mitre.org/data/definitions/540.html)
- Sources: [OpenSSF Best Practices Badge Passing Level [no_leaked_credentials]](https://www.bestpractices.dev/en/criteria#0.no_leaked_credentials)
- How To: [Github Docs](https://docs.github.com/en/code-security/secret-scanning/about-secret-scanning)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/npmOrgMFA.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,6 @@ Multi Factor Authentication (MFA) Enforced Across the npm Organization
- Mitre: [CWE-308](https://cwe.mitre.org/data/definitions/308.html)
- Sources: [OpenSSF npm Best Practices](https://github.com/ossf/package-manager-best-practices/blob/main/published/npm.md)
- How To: [npm Docs](https://docs.npmjs.com/requiring-two-factor-authentication-in-your-organization)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/npmPublicationMFA.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ Publish to npm using an MFA-enabled account rather than single factor legacy or
- Priority Group: P3
- Mitre: [CWE-308](https://cwe.mitre.org/data/definitions/308.html)
- Sources: [npm Docs](https://docs.npmjs.com/creating-and-viewing-access-tokens)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/details/orgToolingMFA.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ Multi Factor Authentication (MFA) Enforced in All Tools Wherever Techncially Fea
- Priority Group: P1
- Mitre: [CWE-308](https://cwe.mitre.org/data/definitions/308.html)
- Sources: [CNCF CNSWP v1.0](https://github.com/cncf/tag-security/blob/main/security-whitepaper/v2/cloud-native-security-whitepaper.md)
- Created at 2024-12-11T23:03:52.941Z
- Updated at 2024-12-11T23:03:52.941Z
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
<!-- DETAILS:END -->
Loading

0 comments on commit 18dc946

Please sign in to comment.