Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Ensignia workflow #1

Merged
merged 1 commit into from
Feb 23, 2024
Merged

Conversation

ensignia-security-development[bot]
Copy link
Contributor

This Pull Request introduces the Ensignia Security Workflow into your repository, aiming to significantly bolster its security framework. The key features and implications of this integration are outlined below:

Workflow Operations

  • Initial Baseline: The workflow creates an initial baseline of the repository's packages, which is used to detect any future changes.
  • Vulnerability Scanning: It meticulously examines any new direct or transient dependencies introduced, identifying known vulnerabilities that could compromise repository integrity.
  • Scorecard: It creates a security scorecard for the repository, which is used to track its security posture over time.

Opting Out

  • No Obligation to Merge: The adoption of Ensignia is entirely at your discretion. If you decide against incorporating Ensignia into this repository, you can opt out by simply closing this PR.

Your feedback and queries are welcome; we're here to assist with the integration process or to provide further information about the benefits and operations of Ensignia.

@ivanvanderbyl ivanvanderbyl merged commit 617157a into main Feb 23, 2024
1 check passed
@ivanvanderbyl ivanvanderbyl deleted the ensignia/add-baseline-workflow branch February 23, 2024 20:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant