@@ -380,7 +380,13 @@ Build and Deployment:
380
380
usefulness : 4
381
381
level : 2
382
382
implementation :
383
- - signing-of-commits-protection :
383
+ - argocd :
384
+ uuid : fdb0e7cc-d3dd-4a2b-9f45-7d403001294f
385
+ name : argoCD
386
+ tags :
387
+ - deployment
388
+ url : https://argo-cd.readthedocs.io/en/stable/
389
+ signing-of-commits-protection :
384
390
uuid : 86c6bdba-73c0-4c99-bbda-81b85c9fe2a4
385
391
name : Enforcement of commit signing
386
392
tags :
@@ -1828,6 +1834,42 @@ Build and Deployment:
1828
1834
comments : " "
1829
1835
tags :
1830
1836
- patching
1837
+ Automated deployment of automated PRs :
1838
+ uuid : 08f27c26-2c6a-47fe-9458-5e88f188085d
1839
+ description : Automated merges of automated created PRs for outdated dependencies.
1840
+ risk : Even if automated dependencies PRs are merged, they might not be deployed.
1841
+ This results in vulnerabilities in running artifacts stay for too long and
1842
+ might get exploited.
1843
+ measure : |
1844
+ After merging of an automated dependency PR, automated deployment is needed,
1845
+ difficultyOfImplementation :
1846
+ knowledge : 3
1847
+ time : 3
1848
+ resources : 1
1849
+ usefulness : 3
1850
+ level : 3
1851
+ dependsOn :
1852
+ - Automated merge of automated PRs
1853
+ implementation :
1854
+ - uuid : 0d63f907-37fe-4375-88a5-a5e252732618
1855
+ name : terraform
1856
+ tags :
1857
+ - IaC
1858
+ url : https://www.terraform.io/
1859
+ description : |
1860
+ Terraform enables infrastructure automation for provisioning, compliance, and management of any cloud, datacenter, and service.
1861
+ - uuid : fdb0e7cc-d3dd-4a2b-9f45-7d403001294f
1862
+ name : argoCD
1863
+ tags :
1864
+ - deployment
1865
+ url : https://argo-cd.readthedocs.io/en/stable/
1866
+ references :
1867
+ samm2 : []
1868
+ iso27001-2017 : []
1869
+ iso27001-2022 : []
1870
+ comments : " "
1871
+ tags :
1872
+ - patching
1831
1873
Automated merge of automated PRs :
1832
1874
uuid : f2594f8f-1cd6-45f9-af29-eaf3315698eb
1833
1875
description : Automated merges of automated created PRs for outdated dependencies.
@@ -1842,6 +1884,8 @@ Build and Deployment:
1842
1884
resources : 1
1843
1885
usefulness : 3
1844
1886
level : 2
1887
+ dependsOn :
1888
+ - Automated PRs for patches
1845
1889
implementation :
1846
1890
- uuid : d6292c7d-aab7-43d3-a7c6-1e443b5c1aa4
1847
1891
name : dependabot
@@ -6040,7 +6084,13 @@ Test and Verification:
6040
6084
- 8.32
6041
6085
- 8.29
6042
6086
implementation :
6043
- - signing-of-commits-protection :
6087
+ - argocd :
6088
+ uuid : fdb0e7cc-d3dd-4a2b-9f45-7d403001294f
6089
+ name : argoCD
6090
+ tags :
6091
+ - deployment
6092
+ url : https://argo-cd.readthedocs.io/en/stable/
6093
+ signing-of-commits-protection :
6044
6094
uuid : 86c6bdba-73c0-4c99-bbda-81b85c9fe2a4
6045
6095
name : Enforcement of commit signing
6046
6096
tags :
@@ -7112,7 +7162,13 @@ Test and Verification:
7112
7162
url : https://thehackernews.com/2022/11/top-5-api-security-myths-that-are.html
7113
7163
description : |
7114
7164
There are several myths and misconceptions about API security. These myths about securing APIs are crushing your business
7115
- - signing-of-commits-protection :
7165
+ - argocd :
7166
+ uuid : fdb0e7cc-d3dd-4a2b-9f45-7d403001294f
7167
+ name : argoCD
7168
+ tags :
7169
+ - deployment
7170
+ url : https://argo-cd.readthedocs.io/en/stable/
7171
+ signing-of-commits-protection :
7116
7172
uuid : 86c6bdba-73c0-4c99-bbda-81b85c9fe2a4
7117
7173
name : Enforcement of commit signing
7118
7174
tags :
@@ -8702,7 +8758,13 @@ Test and Verification:
8702
8758
tags :
8703
8759
- ide
8704
8760
- sast
8705
- - signing-of-commits-protection :
8761
+ - argocd :
8762
+ uuid : fdb0e7cc-d3dd-4a2b-9f45-7d403001294f
8763
+ name : argoCD
8764
+ tags :
8765
+ - deployment
8766
+ url : https://argo-cd.readthedocs.io/en/stable/
8767
+ signing-of-commits-protection :
8706
8768
uuid : 86c6bdba-73c0-4c99-bbda-81b85c9fe2a4
8707
8769
name : Enforcement of commit signing
8708
8770
tags :
@@ -9860,10 +9922,10 @@ Test and Verification:
9860
9922
are performed.
9861
9923
difficultyOfImplementation :
9862
9924
knowledge : 1
9863
- time : 2
9925
+ time : 3
9864
9926
resources : 1
9865
9927
usefulness : 5
9866
- level : 1
9928
+ level : 2
9867
9929
dependsOn :
9868
9930
- Defined build process
9869
9931
implementation :
@@ -10067,10 +10129,10 @@ Test and Verification:
10067
10129
dataflow analysis.
10068
10130
difficultyOfImplementation :
10069
10131
knowledge : 2
10070
- time : 3
10132
+ time : 2
10071
10133
resources : 1
10072
10134
usefulness : 4
10073
- level : 2
10135
+ level : 3
10074
10136
implementation :
10075
10137
- uuid : 6a0948a7-4781-4858-9766-f4303971b28b
10076
10138
name : eslint
@@ -10184,6 +10246,7 @@ Test and Verification:
10184
10246
name : PMD
10185
10247
tags : []
10186
10248
dependsOn :
10249
+ - Automated PRs for patches
10187
10250
- Defined build process
10188
10251
references :
10189
10252
samm2 :
@@ -10230,7 +10293,7 @@ Test and Verification:
10230
10293
- patching
10231
10294
url : https://github.com/renovatebot/renovate
10232
10295
dependsOn :
10233
- - Defined build process
10296
+ - Automated PRs for patches
10234
10297
references :
10235
10298
samm2 :
10236
10299
- V-ST-2-A
0 commit comments