Skip to content

Enable secret scanning org-wide, and align security/quality settings across reshapr repos #3

Description

@yada

Context

While preparing reShapr's AAIF Sandbox application, I checked security settings across
the whole reshaprio GitHub organization, not just the main repo. Two things stood out:

1. Secret scanning is disabled everywhere.

secret_scanning, secret_scanning_push_protection, and secret_scanning_validity_checks
are disabled on all 7 repos: reshapr, reshapr-controllers, reshapr-helm-charts,
reshapr-demos, reshapr-agent-skills, .github, community.

Proposal

  1. Enable secret scanning + push protection org-wide (free for public repos, no code
    changes).
  2. Beyond that single setting: agree on a baseline security/quality configuration every
    reshaprio repo should have at minimum.

Why now

  • Concrete, verifiable evidence for "current security posture" in the AAIF Sandbox
    application.
  • Baseline hygiene the OpenSSF Best Practices badge's no_leaked_credentials a
    criteria care about — and something we'd want regardless of AAIF.
  • Cheap to fix now, before the org has more repos/contributors to retrofit late

Decision needed

@reshaprio/maintainers -> agreed on enabling secret scanning org-wide?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions