Skip to content

Harden Repository Configuration - opentonapi #73

Description

@stepsecurity-app

StepSecurity has identified repository-level hardening opportunities in TLMSLLC/opentonapi based on your organization's Policy-Driven PR configuration.

Dependabot configuration should cover the configured package ecosystems

  • Status: Failed
  • Severity: Medium
  • Description: This check fails if the repository has no .github/dependabot.yml or it does not cover the package ecosystems configured by the organization.
  • Resolution: Add or update .github/dependabot.yml to include version updates for the configured package ecosystems.
  • Details: dependabot configuration does not cover configured package ecosystems: *

Suggested changes

Create or update .github/dependabot.yml:

version: 2
updates:
  - package-ecosystem: "*"
    directory: "/"
    schedule:
      interval: "daily"

Pre-commit configuration should include the configured hooks

  • Status: Failed
  • Severity: Low
  • Description: This check fails if the repository has no .pre-commit-config.yaml or it is missing hooks the organization has configured. Pre-commit hooks enforce code quality and detect security issues before commit.
  • Resolution: Add or update .pre-commit-config.yaml to include the configured hooks.
  • Details: pre-commit configuration is missing configured hooks: eslint, php-lint-all

Enabling Pull Requests mode for these controls lets StepSecurity remediate them automatically via a pull request.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions