CI/CD Repository Audit
Description:
Perform repository audit.
If there has not been a significant commit in the last year, add a note indicating so.
Skip to Acceptance Criteria section at the bottom to complete close this issue.
Administrative Audit Criteria
Actions State
If actions have not been run in the previous 6 months they should be disabled:
If actions have run in the last 6 months then actions shall remain enabled:
Settings Window
General Tab
Features Section:
Pull Requests Section:
Pushes Section:
Collaborators and Teams Tab
Branches Tab
Tags Tab
Rules/Rulesets Tab
Actions Tab
If actions are enabled:
Webhooks Tab
Code Security Tab
Secrets and Variables Tab
GitHub Apps
App Integrations
Code Formatting
CODEOWNERS
Workflow Audit Criteria
Security Checks in Workflows
Workflow checks
Self Hosted Runners
Other
Acceptance Criteria
Custom Properties - Marking Complete
Update the repo-properties.json file in the ORG/governance repository
Note: assumes ORG/governance is a valid repository in the Github Organization being audited
CI/CD Repository Audit
Description:
Perform repository audit.
If there has not been a significant commit in the last year, add a note indicating so.
Skip to
Acceptance Criteriasection at the bottom to complete close this issue.Administrative Audit Criteria
Actions State
If actions have not been run in the previous 6 months they should be disabled:
If actions have run in the last 6 months then actions shall remain enabled:
Settings Window
General Tab
Features Section:
Pull Requests Section:
Pushes Section:
Collaborators and Teams Tab
Branches Tab
Tags Tab
Rules/Rulesets Tab
Actions Tab
If actions are enabled:
Webhooks Tab
Code Security Tab
Secrets and Variables Tab
GitHub Apps
App Integrations
dependabot.yamlfile)Code Formatting
CODEOWNERS
.github/CODEOWNERSis valid and up-to-dateWorkflow Audit Criteria
Security Checks in Workflows
/.github/workflows/)npx playwright install depsis used to install OS dependencies instead ofaptitudeWorkflow checks
Self Hosted Runners
runs-onstanzaOther
Acceptance Criteria
Custom Properties - Marking Complete
Update the
repo-properties.jsonfile in theORG/governancerepositoryinitial-ci-review-by-teamis setinitial-ci-review-dateis set (Use format:YYYY-MM-DD)last-ci-review-by-teamis setlast-ci-review-dateis set (Use format:YYYY-MM-DD)Note: assumes
ORG/governanceis a valid repository in the Github Organization being audited