Signed-off-by: Bryan Frimin <bryan@frimin.fr>
This commit is contained in:
gearnode
2025-01-08 11:13:58 +01:00
parent 3d923033f2
commit 99d32ca49d
8 changed files with 70 additions and 68 deletions

View File

@@ -5,17 +5,17 @@ revision-version: 1
revision-date: "2024-01-07"
estimate-time: "15m"
frameworks:
- name: "soc2"
sections: ["CC1.4", "CC5.2", "CC8.1"]
- name: "soc2"
sections: ["CC1.4", "CC5.2", "CC8.1"]
---
## Purpose
Requiring pull requests and code reviews ensures higher code quality
and security by allowing multiple team members to catch bugs,
inefficiencies, and potential vulnerabilities before code is
merged. It also promotes collaboration, knowledge sharing, and
accountability within the team. This process helps prevent issues in
production and maintains adherence to coding standards.
Requiring pull requests and code reviews ensures higher code quality and
security by allowing multiple team members to catch bugs, inefficiencies, and
potential vulnerabilities before code is merged. It also promotes collaboration,
knowledge sharing, and accountability within the team. This process helps
prevent issues in production and maintains adherence to coding standards.
## Implementation
@@ -23,8 +23,7 @@ production and maintains adherence to coding standards.
1. Open your GitHub repository and go to settings.
2. In "Branche"s, click "Add Rule".
3. Enter the branch name (e.g. "main") in the branch name pattern
field.
3. Enter the branch name (e.g. "main") in the branch name pattern field.
4. Enable: "Require a pull request before merging"
5. Click Create or Save to apply the rule

View File

@@ -5,14 +5,14 @@ revision-version: 1
revision-date: "2024-01-07"
estimate-time: "15m"
frameworks:
- name: "soc2"
sections: ["CC4.1", "CC8.1"]
- name: "soc2"
sections: ["CC4.1", "CC8.1"]
---
## Purpose
It ensures that potential security flaws are detected early. This
proactive approach strengthens your security posture and helps
maintain high code quality.
It ensures that potential security flaws are detected early. This proactive
approach strengthens your security posture and helps maintain high code quality.
## Implementation
@@ -23,8 +23,8 @@ maintain high code quality.
3. Select "Set up this workflow" under "CodeQL Analysis".
4. Review the YAML file and commit it to your repository.
Code scanning will now run every time code is pushed to the
repository, and results will appear in the Security tab.
Code scanning will now run every time code is pushed to the repository, and
results will appear in the Security tab.
## Evidence

View File

@@ -5,14 +5,15 @@ revision-version: 1
revision-date: "2024-01-07"
estimate-time: "15m"
frameworks:
- name: "soc2"
sections: ["CC4.1", "CC8.1"]
- name: "soc2"
sections: ["CC4.1", "CC8.1"]
---
## Purpose
It ensures your project stays secure and up-to-date without manual
tracking of dependencies. It also reduces the risk of using outdated
or insecure libraries in your codebase.
It ensures your project stays secure and up-to-date without manual tracking of
dependencies. It also reduces the risk of using outdated or insecure libraries
in your codebase.
## Implementation
@@ -21,13 +22,13 @@ or insecure libraries in your codebase.
1. Go to your repository on GitHub.
2. Click on the "Settings" tab.
3. On the left sidebar, click "Security & analysis".
4. Under "Dependabot alerts", ensure "Dependency graph" and
"Dependabot security updates" are enabled.
5. GitHub will now alert you to any vulnerable dependencies and
automatically open pull requests to fix them.
4. Under "Dependabot alerts", ensure "Dependency graph" and "Dependabot security
updates" are enabled.
5. GitHub will now alert you to any vulnerable dependencies and automatically
open pull requests to fix them.
## Evidence
- Screenshot of Dependabot configuration screen
- Sample of dependency update PRs
- Vulnerability alert history

View File

@@ -5,21 +5,20 @@ revision-version: 1
revision-date: "2024-01-08"
estimate-time: "1h"
frameworks:
- name: "soc2"
sections: ["CC1.4", "CC5.2", "CC8.1"]
- name: "soc2"
sections: ["CC1.4", "CC5.2", "CC8.1"]
---
## Purpose
Formalizing a proper development lifecycle helps your engineer in
their jobs and helps you to scale your team. It reduces the chances of
human error.
Formalizing a proper development lifecycle helps your engineer in their jobs and
helps you to scale your team. It reduces the chances of human error.
## Implementation
Write a document with your development lifecycle. It should include:
planning, analysis, design, coding, testing, and maintenance. Don’t
forget secure coding practices (eg code review) and quality.
Write a document with your development lifecycle. It should include: planning,
analysis, design, coding, testing, and maintenance. Don’t forget secure coding
practices (eg code review) and quality.
## Evidence