
Jump to: navigation, search


96 bytes added, 13:09, 25 October 2018
no edit summary
* The signature verification will eventually become a requirement to shipping a release to staging & prod: the tag being deployed in the pipeline must have a matching tag in git signed by a project owner. This control is designed to reduce the risk of a 3rd party GitHub integration from compromising our source code.
* [ ] enable security scanning of 3rd-party libraries and dependencies
* For node.js, use [`npm audit`]( with [audit-filter]( to review and handle exception exceptions (see example in [speech-proxy](
* For Python, enable pyup security updates:
* Add a pyup config to your repo (example config:
* notify to enable the integration in pyup
* [ ] Keep 3rd-party libraries up to date (in addition to the security updates)
* For NodeJS applications, use [dependabot](, [renovate]( , or [GreenKeeper](
* For Python, use ``pip list --outdated`` or []( or pyup outdated checks
* For Rust, use `cargo update` and [cargo upgrade]( when changing versions

Navigation menu