Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3,602 changes: 1,801 additions & 1,801 deletions data/checks.json

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions docs/checks/MFAImpersonationDefense.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ slug: /checks/MFAImpersonationDefense
- Mitre: [CWE-290](https://cwe.mitre.org/data/definitions/290.html)
- Sources: [OpenSSF Best Practices Badge Gold Level [secure_2FA]](https://www.bestpractices.dev/en/criteria/2#2.secure_2FA)
- How To: [Github Docs](https://docs.github.com/en/authentication/securing-your-account-with-two-factor-authentication-2fa)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/PRsBeforeMerge.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ slug: /checks/PRsBeforeMerge
- Mitre: [CWE-778](https://cwe.mitre.org/data/definitions/778.html)
- Sources: [OpenSSF Scorecard](https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection)
- How To: [Github Docs](https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/about-protected-branches#require-pull-request-reviews-before-merging)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/SSHKeysRequired.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ slug: /checks/SSHKeysRequired
- Mitre: [CWE-309](https://cwe.mitre.org/data/definitions/309.html)
- Sources: [CNCF SSCP v1.0 #192](https://github.com/cncf/tag-security/blob/main/supply-chain-security/supply-chain-security-paper/sscsp.md#use-ssh-keys-to-provide-developers-access-to-source-code-repositories)
- How To: [Github Docs](https://docs.github.com/en/authentication/connecting-to-github-with-ssh/about-ssh)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/activeAdminsSixMonths.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ slug: /checks/activeAdminsSixMonths
- Priority Group: R3
- Mitre: [M1026](https://attack.mitre.org/mitigations/M1026/)
- Sources: [OpenSSF SCM Best Practices](https://best.openssf.org/SCM-BestPractices/github/member/stale_admin_found.html)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/activeWritersSixMonths.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ slug: /checks/activeWritersSixMonths
- Priority Group: R3
- Mitre: [M1026](https://attack.mitre.org/mitigations/M1026/)
- Sources: [OpenSSF SCM Best Practices](https://best.openssf.org/SCM-BestPractices/github/member/stale_member_found.html)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/adminRepoCreationOnly.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ slug: /checks/adminRepoCreationOnly
- Mitre: [CAPEC-122](https://capec.mitre.org/data/definitions/122.html)
- Sources: [OpenSSF SCM Best Practices](https://best.openssf.org/SCM-BestPractices/github/organization/non_admins_can_create_public_repositories.html)
- How To: [Github Docs](https://docs.github.com/en/organizations/managing-organization-settings/restricting-repository-creation-in-your-organization)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/annualDependencyRefresh.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,6 @@ slug: /checks/annualDependencyRefresh
- C-SCRM: true
- Priority Group: P14
- Sources: [OpenSSF Best Practices Badge Passing Level [maintained]](https://www.bestpractices.dev/en/criteria?details=true&rationale=true#0.maintained)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/assignCVEForKnownVulns.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,6 @@ slug: /checks/assignCVEForKnownVulns
- C-SCRM: true
- Priority Group: P7
- Sources: [OpenSSF Best Practices Badge Passing Level [release_notes_vulns]](https://www.bestpractices.dev/en/criteria?details=true&rationale=true#0.release_notes_vulns)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/automateDependencyManagement.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ slug: /checks/automateDependencyManagement
- Priority Group: P14
- Sources: [OWASP SCVS L1 5.7](https://scvs.owasp.org/scvs/v5-component-analysis/)
- How To: [Socket.Dev](https://socket.dev/)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/automateVulnDetection.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ slug: /checks/automateVulnDetection
- Mitre: [CWE-1395](https://cwe.mitre.org/data/definitions/1395.html)
- Sources: [OWASP SCVS L1 5.4](https://scvs.owasp.org/scvs/v5-component-analysis/)
- How To: [Github Docs](https://docs.github.com/en/code-security/dependabot/dependabot-security-updates/configuring-dependabot-security-updates#managing-dependabot-security-updates-for-your-repositories)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/blockWorkflowPRApproval.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ slug: /checks/blockWorkflowPRApproval
- Mitre: [CWE-250](https://cwe.mitre.org/data/definitions/250.html)
- Sources: [OpenSSF Scorecard](https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions)
- How To: [Github Docs](https://docs.github.com/en/enterprise-cloud@latest/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise#preventing-github-actions-from-creating-or-approving-pull-requests)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/ciAndCdPipelineAsCode.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ slug: /checks/ciAndCdPipelineAsCode
- Priority Group: P12
- Sources: [CNCF SSCP 1.0 #158](https://github.com/cncf/tag-security/blob/main/supply-chain-security/supply-chain-security-paper/sscsp.md#build-and-related-continuous-integrationcontinuous-delivery-steps-should-all-be-automated-through-a-pipeline-defined-as-code)
- How To: [Github Docs](https://docs.github.com/en/actions/publishing-packages/publishing-nodejs-packages)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/commitSignoffForWeb.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ slug: /checks/commitSignoffForWeb
- Priority Group: R4
- Sources: [CNCF SSCP 1.0 #325](https://github.com/cncf/tag-security/blob/main/supply-chain-security/supply-chain-security-paper/sscsp.md#require-signed-commits)
- How To: [Github Docs](https://docs.github.com/en/organizations/managing-organization-settings/managing-the-commit-signoff-policy-for-your-organization#managing-compulsory-commit-signoffs-for-your-organization)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/commitStatusChecks.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ slug: /checks/commitStatusChecks
- Mitre: [CWE-358](https://cwe.mitre.org/data/definitions/358.html)
- Sources: [OpenSSF Scorecard](https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection)
- How To: [Github Docs](https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/about-protected-branches#require-status-checks-before-merging)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/consistentBuildProcessDocs.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,6 @@ slug: /checks/consistentBuildProcessDocs
- C-SCRM: true
- Priority Group: P12
- Mitre: [CWE-1068](https://cwe.mitre.org/data/definitions/1068.html)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/defaultTokenPermissionsReadOnly.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,6 @@ slug: /checks/defaultTokenPermissionsReadOnly
- C-SCRM: true
- Priority Group: P9
- Mitre: [CWE-250](https://cwe.mitre.org/data/definitions/250.html)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/defineFunctionalRoles.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ slug: /checks/defineFunctionalRoles
- Mitre: [CAPEC-122](https://capec.mitre.org/data/definitions/122.html)
- Sources: [CNCF SSCP v1.0 #188](https://github.com/cncf/tag-security/blob/main/supply-chain-security/supply-chain-security-paper/sscsp.md#define-roles-aligned-to-functional-responsibilities)
- How To: [Github Docs](https://docs.github.com/en/organizations/managing-user-access-to-your-organizations-repositories/managing-repository-roles/repository-roles-for-an-organization)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/forkWorkflowApproval.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ slug: /checks/forkWorkflowApproval
- Priority Group: R2
- Mitre: [CAPEC-180](https://capec.mitre.org/data/definitions/180.html)
- Sources: [Github Docs](https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository#controlling-changes-from-forks-to-workflows-in-public-repositories)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/githubOrgMFA.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,6 @@ We use the field `two_factor_requirement_enabled` from the GitHub Organization A
- Mitre: [CWE-308](https://cwe.mitre.org/data/definitions/308.html)
- Sources: [OpenSSF SCM Best PracticesOpenSSF Best Practices Badge Gold Level [require_2FA]](https://best.openssf.org/SCM-BestPractices/github/enterprise/enterprise_enforce_two_factor_authentication.html)
- How To: [Github Docs](https://docs.github.com/en/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/requiring-two-factor-authentication-in-your-organization)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/githubWebhookSecrets.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ slug: /checks/githubWebhookSecrets
- Mitre: [CWE-306](https://cwe.mitre.org/data/definitions/306)
- Sources: [OpenSSF Scorecard](https://github.com/ossf/scorecard/blob/main/docs/checks.md#webhooks)
- How To: [Github Docs](https://docs.github.com/en/actions/security-guides/using-secrets-in-github-actions)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/githubWriteAccessRoles.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ slug: /checks/githubWriteAccessRoles
- Mitre: [CAPEC-180](https://capec.mitre.org/data/definitions/180.html)
- Sources: [CNCF SSCP v1.0 #185](https://github.com/cncf/tag-security/blob/main/supply-chain-security/supply-chain-security-paper/sscsp.md#define-individualsteams-that-are-responsible-for-code-in-a-repository-and-associated-coding-conventions)
- How To: [Github Docs](https://docs.github.com/en/organizations/managing-user-access-to-your-organizations-repositories/managing-repository-roles/repository-roles-for-an-organization)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/identifyModifiedDependencies.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,6 @@ slug: /checks/identifyModifiedDependencies
- C-SCRM: true
- Priority Group: P14
- Sources: [OWASP SCVS L2 6.5](https://scvs.owasp.org/scvs/v6-pedigree-and-provenance/)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/incidentResponsePlan.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,6 @@ slug: /checks/incidentResponsePlan
- C-SCRM: false
- Priority Group: P7
- Sources: [OpenSSF SCM Best Practices](https://best.openssf.org/SCM-BestPractices/#operations)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/includeCVEInReleaseNotes.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,6 @@ slug: /checks/includeCVEInReleaseNotes
- C-SCRM: false
- Priority Group: P7
- Sources: [OpenSSF Best Practices Badge Passing Level [release_notes_vulns]](https://www.bestpractices.dev/en/criteria?details=true&rationale=true#0.release_notes_vulns)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/includePackageLock.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ slug: /checks/includePackageLock
- Priority Group: R5
- Sources: [OpenSSF Scorecard](https://github.com/ossf/scorecard/blob/main/docs/checks.md#sbom)
- How To: [npm Docs](https://docs.npmjs.com/cli/v10/commands/npm-sbom)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/injectedSecretsAtRuntime.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ slug: /checks/injectedSecretsAtRuntime
- Mitre: [CWE-538](https://cwe.mitre.org/data/definitions/538.html)
- Sources: [CNCF CNSWP 2.0 #195](https://github.com/cncf/tag-security/blob/main/security-whitepaper/v2/cloud-native-security-whitepaper.md#secrets-encryption)
- How To: [Github Docs](https://docs.github.com/en/actions/security-guides/using-secrets-in-github-actions#creating-secrets-for-an-organization)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/limitOrgOwners.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ slug: /checks/limitOrgOwners
- Priority Group: R7
- Mitre: [M1026](https://attack.mitre.org/mitigations/M1026/)
- Sources: [OpenSSF SCM Best Practices](https://best.openssf.org/SCM-BestPractices/github/member/organization_has_too_many_admins.html)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/limitRepoAdmins.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ slug: /checks/limitRepoAdmins
- Priority Group: R7
- Mitre: [CAPEC-180](https://capec.mitre.org/data/definitions/180.html)
- Sources: [OpenSSF SCM Best Practices](https://best.openssf.org/SCM-BestPractices/github/repository/repository_has_too_many_admins.html)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/limitWorkflowWritePermissions.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ slug: /checks/limitWorkflowWritePermissions
- Mitre: [CWE-250](https://cwe.mitre.org/data/definitions/250.html)
- Sources: [OpenSSF Scorecard](https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions)
- How To: [Github Docs](https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/machineReadableDependencies.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ slug: /checks/machineReadableDependencies
- Priority Group: P14
- Sources: [OWASP SCVS L1 1.3](https://scvs.owasp.org/scvs/v1-inventory/#verification-requirements)
- How To: [Github Docs](https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-supply-chain-security#what-is-the-dependency-graph)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/noArbitraryCodeInPipeline.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ slug: /checks/noArbitraryCodeInPipeline
- Priority Group: P11
- Mitre: [CWE-94](https://cwe.mitre.org/data/definitions/94.html)
- Sources: [OpenSSF Scorecard](https://github.com/ossf/scorecard/blob/main/docs/checks.md#dangerous-workflow)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/noForcePushDefaultBranch.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ slug: /checks/noForcePushDefaultBranch
- Priority Group: P9
- Sources: [OpenSSF Scorecard](https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection)
- How To: [Github Docs](https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/about-protected-branches)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/noSelfHostedRunners.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ slug: /checks/noSelfHostedRunners
- Mitre: [CAPEC-439](https://capec.mitre.org/data/definitions/439.html)
- Sources: [Github Action Hardening Docs](https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#hardening-for-self-hosted-runners)
- How To: [Github Docs](https://docs.github.com/en/organizations/managing-organization-settings/disabling-or-limiting-github-actions-for-your-organization#limiting-the-use-of-self-hosted-runners)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/noSensitiveInfoInRepositories.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ slug: /checks/noSensitiveInfoInRepositories
- Mitre: [CWE-540](https://cwe.mitre.org/data/definitions/540.html)
- Sources: [OpenSSF Best Practices Badge Passing Level [no_leaked_credentials]](https://www.bestpractices.dev/en/criteria#0.no_leaked_credentials)
- How To: [Github Docs](https://docs.github.com/en/code-security/secret-scanning/about-secret-scanning)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/npmOrgMFA.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ slug: /checks/npmOrgMFA
- Mitre: [CWE-308](https://cwe.mitre.org/data/definitions/308.html)
- Sources: [OpenSSF npm Best Practices](https://github.com/ossf/package-manager-best-practices/blob/main/published/npm.md)
- How To: [npm Docs](https://docs.npmjs.com/requiring-two-factor-authentication-in-your-organization)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/npmPublicationMFA.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ slug: /checks/npmPublicationMFA
- Priority Group: P3
- Mitre: [CWE-308](https://cwe.mitre.org/data/definitions/308.html)
- Sources: [npm Docs](https://docs.npmjs.com/creating-and-viewing-access-tokens)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/orgToolingMFA.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ slug: /checks/orgToolingMFA
- Priority Group: P1
- Mitre: [CWE-308](https://cwe.mitre.org/data/definitions/308.html)
- Sources: [CNCF CNSWP v1.0](https://github.com/cncf/tag-security/blob/main/security-whitepaper/v2/cloud-native-security-whitepaper.md)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/owaspTop10Training.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@ slug: /checks/owaspTop10Training
- Priority Group: P0
- Mitre: [M1013](https://attack.mitre.org/mitigations/M1013/)
- Sources: [OpenSSF Best Practices Badge Passing Level [know_common_errors]](https://www.bestpractices.dev/en/criteria?details=true&rationale=true#0.know_common_errors)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
4 changes: 2 additions & 2 deletions docs/checks/patchCriticalVulns30Days.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,6 @@ slug: /checks/patchCriticalVulns30Days
- C-SCRM: false
- Priority Group: P5
- Sources: [OpenSSF Best Practices Badge Passing Level [vulnerabilities_critical_fixed]](https://www.bestpractices.dev/en/criteria#0.vulnerabilities_critical_fixed)
- Created at 2024-12-18T20:19:27.410Z
- Updated at 2024-12-18T20:19:27.410Z
- Created at 2024-12-22T04:04:30.161Z
- Updated at 2024-12-22T04:04:30.161Z
<!-- DETAILS:END -->
Loading