Giter Site home page Giter Site logo

fossabot / ghas-bootcamp Goto Github PK

View Code? Open in Web Editor NEW

This project forked from cmboling/ghas-bootcamp

0.0 1.0 0.0 28.13 MB

This bootcamp is designed to get you familiar with GitHub Advanced Security (GHAS) so that you can better understand how to use it in your own repositories.

Dockerfile 1.14% Shell 0.73% Python 3.79% JavaScript 8.26% HTML 0.95% Vue 9.92% Less 20.20% Go 24.72% Java 30.29%

ghas-bootcamp's Introduction

GitHub Advanced Security Bootcamp

Prerequisites โ€ข Resources

This bootcamp is designed to get you familiar with GitHub Advanced Security (GHAS) so that you can better understand how to use it in your own repositories.

๐Ÿ“ฃ Prerequisites

FOSSA Status

To participate in the workshop you need a GitHub account and need to be invited to the workshop organization ghas-bootcamp. If your repository hasn't been automatically created in the workshop organization, either click Use this template and create a repository under this organization, or create a new repository and push a copy of the ghas-bootcamp repository.

git clone https://github.com/ghas-bootcamp/ghas-bootcamp.git
cd ghas-bootcamp
git remote set-url origin [email protected]:{org-or-username}/{repo-name}.git

๐Ÿซ Agenda

We will go over the following topics:

Day One

Day One Learning

  • Comprenhensive overview of GHAS
  • Securing your supply chain with Dependency management
  • Secret scanning
  • Rolling out GHAS in your organization
  • Q&A

Day One: Secret Scanning and Dependabot Exercises

Secret scanning
  • Enabling secret scanning
  • Viewing and managing results
  • Excluding files from secret scanning
  • Custom patterns for secret scanning
  • Managing access to alerts
Dependabot
  • Enabling Dependabot alerts
  • Reviewing the dependency graph
  • Viewing and managing results
  • Enabling Dependabot security updates
  • Configuring Dependabot security updates
  • Working with Dependency Review
Day Two

Day Two Learning

  • Explore how code scanning works
  • What is Security Overview?
  • CodeQL Demo
  • Final Q&A

Day Two: Code Scanning + CodeQL Demo

Code scanning
  • Enabling code scanning
  • Reviewing any failed analysis job
  • Using context and expressions to modify build
  • Reviewing and managing results
  • Triaging a result in a PR
  • Customizing CodeQL Configuration
  • Adding your own code scanning suite to exclude rules
  • Understanding how to add a custom query
  • CodeQL Demo

๐Ÿ“š Resources

License

FOSSA Status

ghas-bootcamp's People

Contributors

fossabot avatar jenniferkerns avatar knewbury01 avatar tinywizard avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.