GitHub security workshop: Add security overview, governance, and rollout exercise
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 45/100
- Issue 类型
- 文档
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- github
调研方向
首先查看 workshop README 以及现有的仓库级示例数据和屏幕截图。将练习与列出的 security findings、triage 和 rollout 主题对应起来,然后添加完成检查清单和后续步骤资源;完成意味着每项验收标准都已覆盖,并且训练告警、存在漏洞的分支、测试值和临时 ruleset 均已移除。
由索引模型根据 Issue 内容生成。
描述
Goal
Close the workshop by connecting repository alerts to triage operations and organization-wide security rollout decisions.
Scope
Teach alert ownership, prioritization, campaign or backlog planning, coverage visibility, metrics, exceptions, and rollout sequencing. Use organization Security Overview when available, with repository-level sample data and screenshots as a complete fallback for personal-account learners.
Acceptance criteria
- Learners review code scanning, secret scanning, and dependency findings in a unified triage exercise.
- The exercise prioritizes findings by exploitability, severity, exposure, and remediation availability rather than raw count alone.
- Learners assign an owner, target date, and disposition to a small sample backlog.
- Organization-level coverage and Security Overview concepts are explained with current entitlement requirements.
- A repository-level fallback provides equivalent learning when organization access is unavailable.
- The exercise covers staged enablement, developer communication, bypass and dismissal governance, remediation SLAs, and measuring adoption.
- Learners produce a concise rollout plan for a fictional shelter organization.
- Final cleanup confirms training alerts, vulnerable branches, test values, and temporary rulesets are removed.
- The workshop README includes a completion checklist and next-step resources.
- 主要语言
- Python
- 星标
- 80
- 派生
- 169
- 平均合并
- 31 分钟
- 30 天内合并 PR
- 1
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
github-samples/pets-workshop 的其他 Issue
-
priority: P0
难度 2/5 1-2 天 新手友好度 78/100
github-samples/pets-workshop#268 · 1 条评论 ·
-
priority: P0
难度 1/5 1-3 小时 新手友好度 88/100
github-samples/pets-workshop#267 · 1 条评论 ·
-
priority: P1
难度 1/5 1-3 小时 新手友好度 92/100
github-samples/pets-workshop#261 · 1 条评论 ·
-
priority: P1
难度 2/5 1-3 小时 新手友好度 78/100
github-samples/pets-workshop#257 · 1 条评论 ·
-
priority: deferred
难度 4/5 3-5 天 新手友好度 68/100
github-samples/pets-workshop#277 · 1 条评论 ·
查看 github-samples/pets-workshop 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 68/100
维护者通常 3 天内回复
-
难度 2/5 1-3 小时 新手友好度 88/100
modelcontextprotocol/python-sdk#3648 ·
维护者通常 1 天内回复
-
docs good first issue
难度 2/5 1-3 小时 新手友好度 78/100
VenetoStato/giorgio#6 ·
-
难度 1/5 1 小时以内 新手友好度 70/100
EclipseFdn/open-vsx.org#13831 ·
维护者通常 1 天内回复
-
feature request
难度 2/5 1-3 小时 新手友好度 68/100
维护者通常 2 天内回复