-
Notifications
You must be signed in to change notification settings - Fork 6
Open
Labels
audience/operationsIssue of operations managementIssue of operations managementaudience/technicalIssue primarily for technical review and service.Issue primarily for technical review and service.kind/administrativeAdministrative issuesAdministrative issueskind/documentationImprovements or additions to documentationImprovements or additions to documentationkind/security-vulnerabilityPublicly disclosable security vulnerabilityPublicly disclosable security vulnerabilitykind/stabilitytraige/good first issueGood for newcomersGood for newcomerstriage/high-prioritytriage/required
Description
Kind of issue: Process Change
After viewing a recent security tutorial and other sources, I am seeing that some frameworks require a local GPG signature for commits [1] before a commit can be merged in. We need to add to the CICD SOP or SOP-0001 a requirement that this setting be applied. The setting to create these signatures is easy to apply [2].
[1] https://garantir.io/three-frameworks-software-supply-chain-security/
[2] https://docs.github.com/en/authentication/managing-commit-signature-verification/signing-commits
Metadata
Metadata
Assignees
Labels
audience/operationsIssue of operations managementIssue of operations managementaudience/technicalIssue primarily for technical review and service.Issue primarily for technical review and service.kind/administrativeAdministrative issuesAdministrative issueskind/documentationImprovements or additions to documentationImprovements or additions to documentationkind/security-vulnerabilityPublicly disclosable security vulnerabilityPublicly disclosable security vulnerabilitykind/stabilitytraige/good first issueGood for newcomersGood for newcomerstriage/high-prioritytriage/required