Post #1579423
2026-04-22 17:46 UTC
Replies (1)
-
@aschmitz@ostatus.lardbucket.org 2026-04-23 03:19
@phildini I have some differences of opinion with some of their things, but you could do worse than the OpenSSF checks as a start: https://github.com/ossf/scorecard/blob/main/docs/checks.md . A nontrivial thing not listed there is to require "secure" 2FA on the organization level: https://docs.github.com/en/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/requiring-two-factor-authentication-in-your-organization#requiring-secure-methods-of-two-factor-authentication-in-your-organization Unfortunately, GitHub doesn't provide good org-level controls for less than $$$$, but on an individual basis you should also minimize the SSH keys, access tokens, and authorized apps on your account as much as possible.