- Introduced multiple guides for workflows including Evidence Pack Validation, Incident Response, Model Validation, Performance & HIL, Release Signing, SBOM Validation, Secret Scanning, and Supply Chain Attestation. - Created dynamic badges for each workflow to reflect their status and compliance. - Implemented a checklist for validating CI/CD workflows and evidence packs. - Developed scripts for building firmware, testing, collecting evidence, and generating audit reports. - Added tools for generating community, documentation, quality, and security badges based on various reports. - Established endpoints for dynamic badges to be integrated into documentation and README files. - Enhanced the overall structure and traceability of CI/CD processes with evidence packs and automated checks.
844 B
844 B
Guide Workflow Incident Response & Security Policy
Objectif
Préparer et automatiser la gestion des incidents de sécurité et la conformité aux politiques de sécurité.
Outils utilisés
- Fichier SECURITY.md
- Scripts custom de notification
Logique du workflow
- Vérification de la présence et conformité du fichier SECURITY.md
- Automatisation de la notification en cas d’incident
- Publication des rapports d’incident
Critères de conformité
- Politique de sécurité accessible et à jour
- Evidence pack mis à jour
Badge dynamique
- Endpoint JSON : docs/badges/incident_response_badge.json
- Intégration dans README
Vérification
- Le badge doit afficher le statut de conformité et incident
- Les rapports sont accessibles dans les artefacts CI