Review and implement pipeline security best practices #1512
Labels
epic
A high-level objective issue encompassing multiple issues instead of a specific unit of work
Milestone
Description
ScubaGear development leverages a continuous integration pipeline to ensure high code quality throughout the development process. The purpose of this epic is to review current pipeline workflows along with CI/CD security best practices and ensure all reasonable security measures and mitigations are in place to safeguard ScubaGear development.
Initiative / Goal
The goal is to improve ScubaGear code quality through the use of security best practices applied through automated processes.
Relevant Issues
Hypothesis
By improving the security of the development pipeline, ScubaGear security results will be more transparent and provide more assurance in the overall development process.
Acceptance criteria
Criteria that are considered in-scope for this epic include:
Stakeholders / Resources
Include CISA decision makers and dev team members in discussions about this epic. Resources needed for this epic include access to development pipeline to test possible solutions.
Timeline
TBD
The text was updated successfully, but these errors were encountered: