Skip to content

Navigation Menu

Sign in
Sign up

Update security-repository.md - #285

Open
LouPritch wants to merge 1 commit into
NHSDigital:main from
LouPritch:patch-1
Open

Update security-repository.md #285
LouPritch wants to merge 1 commit into
NHSDigital:main from
LouPritch:patch-1

Conversation

@LouPritch

@LouPritch LouPritch commented Dec 13, 2022

Copy link
Copy Markdown

The guidance around Teams setup is incorrect.

  • Child teams cannot have their visibility set to secret.
  • CODEOWNERS file will not work with secret teams.

Altered markdown to reflect the above.

The guidance around Teams setup is incorrect. 
- Child teams cannot have their visibility set to secret.
- CODEOWNERS file will not work with secret teams.
LouPritch requested a review from a team as a code owner December 13, 2022 17:13

Copy link
Copy Markdown

- Create one child team within the team, for admins only (e.g. `Engineering Quality Framework Admins`). Add admins only to this team. Set the visibility of the team to `Secret`.
- Create a second child team, for code owners (e.g. `Engineering Quality Framework Code Owners`). Add relevant members to this team, and reference in the CODEOWNERS file (example [here](https://github.com/NHSDigital/software-engineering-quality-framework/blob/master/.github/CODEOWNERS)). Set the visibility of the team to `Secret`.
- Create another team, for admins only (e.g. `Engineering Quality Framework Admins`). Add admins only to this team. Set the visibility of the team to `Secret`.
- Create another team, for code owners (e.g. `Engineering Quality Framework Code Owners`). Set the parent of this team to be your programme team. Add relevant members to this team, and reference in the CODEOWNERS file (example [here](https://github.com/NHSDigital/software-engineering-quality-framework/blob/master/.github/CODEOWNERS)).

@stefaniuk stefaniuk Dec 19, 2022

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we lost here the requirement for the code owners team to be a secret team. Is this intentional?

@LouPritch LouPritch Dec 19, 2022

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi, this is intentional as the CODEOWNERS file doesn't support secret teams:
"...When the code owner is a team, that team must be visible..." https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/customizing-your-repository/about-code-owners

@stefaniuk stefaniuk Aug 11, 2023

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @LouPritch, sorry it took a while to get here.

I'm reviewing the content of the ./practices/securing-repositories.md file and have relised that some changes that you requested have already been made there. Please, could you check if you are happy with it so we can close this PR?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

@stefaniuk stefaniuk stefaniuk requested changes

Requested changes must be addressed to merge this pull request.

Assignees

No one assigned

Labels

None yet

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

AltStyle によって変換されたページ (->オリジナル) /