Skip to content

Review and implement pipeline security best practices #1512

Description

@schrolla

Description

ScubaGear development leverages a continuous integration pipeline to ensure high code quality throughout the development process. The purpose of this epic is to review current pipeline workflows along with CI/CD security best practices and ensure all reasonable security measures and mitigations are in place to safeguard ScubaGear development.

Initiative / Goal

The goal is to improve ScubaGear code quality through the use of security best practices applied through automated processes.

Relevant Issues

Hypothesis

By improving the security of the development pipeline, ScubaGear security results will be more transparent and provide more assurance in the overall development process.

Acceptance criteria

Criteria that are considered in-scope for this epic include:

  • Existing processes, privileges, and secrets reviewed for needed changes
  • Unnecessary permissions have been removed
  • Secrets are maintained in key vault, either directly or as backup

Stakeholders / Resources

Include CISA decision makers and dev team members in discussions about this epic. Resources needed for this epic include access to development pipeline to test possible solutions.

Timeline

TBD

Metadata

Metadata

Labels

epicA high-level objective issue encompassing multiple issues instead of a specific unit of work

Type

Fields

No fields configured for Bundle.

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions