Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve security practices for carbon-react-native #164

Closed
7 tasks done
Tracked by #15091
tay1orjones opened this issue Nov 2, 2023 · 2 comments
Closed
7 tasks done
Tracked by #15091

Improve security practices for carbon-react-native #164

tay1orjones opened this issue Nov 2, 2023 · 2 comments
Assignees

Comments

@tay1orjones
Copy link
Member

tay1orjones commented Nov 2, 2023

Hey there, Carbon team member here! 👋 We'd like to ensure the security practices for packages published from the carbon-design-system GitHub org are in place and up to date. We'd like to work with you to get the following security practices implemented:

Tasks

Preview Give feedback

Most of these can be found under the Security tab for this repository. You may already have most of these implemented and turned on - if so, awesome!

For establishing a security policy, the existing security policy for the Carbon monorepo can be used as a template if you'd like. It can be modified to include proper version(s) for your package and any other attributes unique to your project that you may want to highlight.

I'm happy to meet up and chat about this if you'd like, just let me know. Thanks in advance for your help in ensuring security and stability across the Carbon ecosystem! 🙏 💙

@dabrad26
Copy link
Member

dabrad26 commented Nov 7, 2023

All items are added. However, provenance is not yet published. Currently Github Actions has some issues (see #150 ).

The other items are complete and I have gone ahead and set the package.json file to provenance; so need to run from GitHub actions to have the standard approach npm ERR! Automatic provenance generation not supported outside of GitHub Actions
Screenshot 2023-11-07 at 01 04 41

@tay1orjones if you have some time could you help me with the GitHub action issue #150?

@dabrad26 dabrad26 self-assigned this Nov 7, 2023
@dabrad26 dabrad26 moved this from Todo to In Progress in Carbon for React Native Nov 7, 2023
dabrad26 added a commit that referenced this issue Nov 9, 2023
@dabrad26
Copy link
Member

dabrad26 commented Nov 9, 2023

Added provenance statement and verified on NPM
Screenshot 2023-11-09 at 13 26 15

All items on this ticket are complete; so closing it. Let me know if you need it opened or if something is not right.

@dabrad26 dabrad26 closed this as completed Nov 9, 2023
@github-project-automation github-project-automation bot moved this from In Progress to Done in Carbon for React Native Nov 9, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Development

No branches or pull requests

2 participants