mindersec/minder-rules-and-profiles
A repository containing Minder rules and profiles recommended by your friends at Stacklok
GoApache-2.0
Issues
- 1
The dockerfile no latest tag rule does not support dockerfiles in places other than the root directory
#102 opened by jhrozek - 1
- 0
- 1
Fix "no open security advisories" rule
#74 opened by teodor-yanev - 0
- 2
Trusty rule type should support rust and java
#67 opened by ethomson - 1
- 2
Implement checking if the workflow that built the artifact is part of the allowed list
#124 opened by rdimitrov - 0
Add a remediation for the no_pull_request_target rule
#201 opened by jhrozek - 4
Remove the required field from the schema for ruletypes that can automatically guess the default branch for a repo.
#178 opened by rdimitrov - 1
- 0
- 3
Create rule which enforces the "Require status checks to pass before merging" branch protection rule in Github
#49 opened by dmjb - 0
RuleType to check for dangerous workflows
#175 opened by puerco - 1
Update SECURITY_INSIGHTS.yaml with latest release data
#174 opened by puerco - 0
Populate SECURITY_INSIGHTS.yaml from known data
#173 opened by puerco - 0
Remove enabled property from rule types
#156 opened by eleftherias - 0
- 1
Update the release phase field in all ruletypes by setting it to the correct value
#143 opened by rdimitrov - 1
- 0
- 0
- 0
Populate display names for all rule types
#144 opened by eleftherias - 0
Create rule type for checking LICENSE file for GitLab
#151 opened by JAORMX - 0
- 0
Include enablement for autofix in CodeQL rule type
#150 opened by meganbruce - 0
- 0
Update all upstream ruletypes by adding the state field and populating it with alpha
#142 opened by blkt - 1
- 0
The artifact_attestation_slsa rule type does not work after GH attestations went from beta to GA
#128 opened by jhrozek - 0
- 0
No remediation support for default_workflow_permissions (part of the healthcheck profile)
#77 opened by rdimitrov - 1
Handle the repository ecosystems correctly in the CodeQL ruletype - codeql_enabled
#73 opened by rdimitrov - 0
Populate the Severity for all rule types
#64 opened by rdimitrov - 0
- 0
As a Minder user, I'd like a rule that tells me if I'm using a set of allowed GitHub actions
#19 opened by JAORMX