Context
While preparing reShapr's AAIF Sandbox application, I checked security settings across
the whole reshaprio GitHub organization, not just the main repo. Two things stood out:
1. Secret scanning is disabled everywhere.
secret_scanning, secret_scanning_push_protection, and secret_scanning_validity_checks
are disabled on all 7 repos: reshapr, reshapr-controllers, reshapr-helm-charts,
reshapr-demos, reshapr-agent-skills, .github, community.
Proposal
- Enable secret scanning + push protection org-wide (free for public repos, no code
changes).
- Beyond that single setting: agree on a baseline security/quality configuration every
reshaprio repo should have at minimum.
Why now
- Concrete, verifiable evidence for "current security posture" in the AAIF Sandbox
application.
- Baseline hygiene the OpenSSF Best Practices badge's
no_leaked_credentials a
criteria care about — and something we'd want regardless of AAIF.
- Cheap to fix now, before the org has more repos/contributors to retrofit late
Decision needed
@reshaprio/maintainers -> agreed on enabling secret scanning org-wide?
Context
While preparing reShapr's AAIF Sandbox application, I checked security settings across
the whole
reshaprioGitHub organization, not just the main repo. Two things stood out:1. Secret scanning is disabled everywhere.
secret_scanning,secret_scanning_push_protection, andsecret_scanning_validity_checksare disabled on all 7 repos:
reshapr,reshapr-controllers,reshapr-helm-charts,reshapr-demos,reshapr-agent-skills,.github,community.Proposal
changes).
reshapriorepo should have at minimum.Why now
application.
no_leaked_credentialsacriteria care about — and something we'd want regardless of AAIF.
Decision needed
@reshaprio/maintainers -> agreed on enabling secret scanning org-wide?