Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Proposal for Baseline GH Rulesets Alignment w/ Minder #39

Open
eddie-knight opened this issue Nov 5, 2024 · 2 comments
Open

Proposal for Baseline GH Rulesets Alignment w/ Minder #39

eddie-knight opened this issue Nov 5, 2024 · 2 comments
Assignees

Comments

@eddie-knight
Copy link
Contributor

eddie-knight commented Nov 5, 2024

Dropping some notes here following a discussion with @mrbobbytables.

  • GitHub Rulesets are entering maturity, and may soon be recommended from a CNCF perspective as a way to streamline security across projects
  • Some discussion (I forget where) has proposed the integration of rulesets in the Minder context
  • Can we collaborate in the Minder context to maintain an OSPS Baseline ruleset that can be optionally ingested directly or by Minder?
  • Need to ensure that the CNCF TOC is 100% on board with the OSPS Baseline criteria, so that the ruleset is immediately useful

cc / @puerco

@TheFoxAtWork
Copy link

If the OSPS baseline are incorporated into the passing level of best practices badging, they will become criteria for projects moving levels.

if they're not capable of being incorporated into best practices badging, the TOC will need to decide at what level these would be required, in whole or in part, and then update the criteria for new projects applying moving forward.

@puerco
Copy link
Member

puerco commented Nov 5, 2024

Absolutely, Minder can help projects in two ways:

  • Minder is able to remediate projects missing the recommended rulesets, ensuring they are always present.
  • Minder can also create minder rule types that protect in the same way without relying on GitHub rules at all.

Once we finalize the criteria, we can create the minder rule types (for either scenario, or both) and we can host them in the baseline repo with instructions on how to use them.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants