-
Notifications
You must be signed in to change notification settings - Fork 125
Closed
Labels
priority-2High priority, address soonHigh priority, address soonscriptsPowerShell, Bash, or Python scriptsPowerShell, Bash, or Python scriptssecuritySecurity-related changes or concernsSecurity-related changes or concerns
Description
Issue Description
The repository needs PowerShell scripts for security scanning, including SHA pinning validation, staleness checking, and automated updates for GitHub Actions.
Additional Context
Files to add:
scripts/security/Test-DependencyPinning.ps1- Validate dependencies are pinned to SHAsscripts/security/Test-SHAStaleness.ps1- Check for stale SHA referencesscripts/security/Update-ActionSHAPinning.ps1- Update action references to latest SHAs
Priority: Wave 2 (Priority 2) - Depends on Wave 1 completion
Dependencies: Requires scripts/README.md from repository foundation issue
Testing: Execute each script, verify JSON output format, test with sample workflow files
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
priority-2High priority, address soonHigh priority, address soonscriptsPowerShell, Bash, or Python scriptsPowerShell, Bash, or Python scriptssecuritySecurity-related changes or concernsSecurity-related changes or concerns