Roger Barker
Roger Barker
# CI/CD Quarterly Audit - Description: Perform quarterly CI/CD audit ## Audit Criteria - [ ] All workflow items are using pinned actions - [ ] Appropriate permissions are set...
## Contents - [CI/CD Repository Audit](#cicd-repository-audit) - [Contents](#contents) - [Administrative Audit Criteria](#administrative-audit-criteria) - [Check Actions State](#check-actions-state) - [Check if Actions should be disabled](#check-if-actions-should-be-disabled) - [Repository Settings Checks](#repository-settings-checks) - [App Integrations](#app-integrations)...
# CI/CD Repository Audit **Description**: Perform repository audit. **If there has not been a significant commit in the last year, add a note indicating so.** **Skip to `Acceptance Criteria` section...
# CI/CD Repository Audit **Description**: Perform repository audit. **If there has not been a significant commit in the last year, add a note indicating so.** **Skip to `Acceptance Criteria` section...
# CI/CD Repository Audit **Description**: Perform repository audit. **If there has not been a significant commit in the last year, add a note indicating so.** **Skip to `Acceptance Criteria` section...
# CI/CD Repository Audit **Description**: Perform repository audit. **If there has not been a significant commit in the last year, add a note indicating so.** **Skip to `Acceptance Criteria` section...
# CI/CD Repository Audit **Description**: Perform repository audit. **If there has not been a significant commit in the last year, add a note indicating so.** **Skip to `Acceptance Criteria` section...
- Remove reliance on ${GITHUB_WORKSPACE}/changeProjectsReferencesToRepo.sh - Remove reliance on the docker-bookworm image for node:20. - Use the standard setup-node action
# CI/CD Repository Audit **Description**: Perform repository audit. **If there has not been a significant commit in the last year, add a note indicating so.** **Skip to `Acceptance Criteria` section...
I noticed that the yq project isn't requiring commits to be signed from internal or external contributors. I would recommend enforcing gpg signing on all commits so that the consumers...