Repository navigation
Update OSPS-BR-01.03 - #559
Satarupa22-SD wants to merge 1 commit into
Conversation
Signed-off-by: Satarupa22-SD <satarupa2212@gmail.com>
|
This seems like a good example of where the "and" rule in the styleguide may be going too far. The CI running untrusted code must be prevented from accessing either type of secure content:
Does this technically mean two separate checks, one for each type of content? Possibly, but that seems inconvenient, so I'm inclined to keep the scope of the rule. |
|
I agree with Evan. I think we're fine to leave it as-is, but we could also say something like
although, arguably, the control should stop at "content" and the rest belongs in the recommendation. |
|
@eddie-knight @evankanderson @funnelfiasco Should I close this PR then? |
|
I'm fine with either closing this, or using Ben's wording. |
|
I think this is fine to close on account of the "and" being nested within privileged CI/CD elements. |
Removes from the requirement description.
CC: @funnelfiasco @eddie-knight