Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Policy violation Branch Protection #820

Open
ghost opened this issue Oct 25, 2024 · 3 comments
Open

Security Policy violation Branch Protection #820

ghost opened this issue Oct 25, 2024 · 3 comments

Comments

@ghost
Copy link

ghost commented Oct 25, 2024

This issue was automatically created by Allstar.

Security Policy Violation
No protection found for branch master


Issue created by GSA Allstar. See remediation hints in the README.

This issue will auto resolve when the policy is in compliance.

Issue created by Allstar. See https://github.com/ossf/allstar/ for more information. For questions specific to the repository, please contact the owner or maintainer.

@ghost ghost added the allstar-gsa label Oct 25, 2024
@aj-stein-gsa aj-stein-gsa moved this from 🆕 New to 🔖 Ready in FedRAMP Automation Oct 25, 2024
@aj-stein-gsa
Copy link
Contributor

I need to investigate this because given all the protections we have I am not sure why this Allstar report is indicating the branch isn't protected, perhaps GItHub Rulesets are not currently supported (as opposed to the OG branch protection rules; the former is new to me).

@allstar-gsa
Copy link

allstar-gsa bot commented Nov 19, 2024

Updating issue after ping interval. See its status below.


No protection found for branch master

@aj-stein-gsa
Copy link
Contributor

aj-stein-gsa commented Nov 19, 2024

@nateprice18f, I see that you are a frequent committer to the controlling GSA/.allstar repository. Can you confirm if the Allstar checks and rules as configured can detect the new Rulesets feature, not just branch protections? We use the former not the latter and they are more robust and specific. It seems Allstar does not understand this configuration.

If possible, I am happy to work with you and others in your team, if there are others that are maintainers I must coordinate with, if such a new or changed rule is supported. I dabble, but a lot of these GH features are new (oh do, I know 😆).

@aj-stein-gsa aj-stein-gsa self-assigned this Nov 19, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: 🔖 Ready
Development

No branches or pull requests

1 participant