GitLab Internal Inventory controls
Problem to solve
Refer epic for more details &16620 (closed)
The compliance centre does not currently provide all the controls that are required to cover all of the GitLab Internal Inventory checks. Therefore we can not provide a template for this standard.
Proposal
Add all controls required to be able to provide this standard as a template.
All controls can be found here https://docs.google.com/spreadsheets/d/1Wdksot38os84xk9XtuERYc3Ako6GmLprtjFlqE1NP2E/edit?gid=1349415651#gid=1349415651
- default_branch_protected_from_direct_push (default_branch_users_can_push) - !185177 (merged)
- push_protection_enabled
- ci_config_valid - !185177 (merged)
- project_marked_for_deletion
- scanner_sast_running - !184182 (merged)
- merge_request_prevent_author_approval - !177981 (merged)
- project_visibility_not_internal
- project_archived
- default_branch_users_can_merge
- merge_request_commit_reset_approvals
- merge_request_prevent_committers_approval - !177981 (merged)
- project_visibility_not_public
- package_hunter_no_findings_untriaged
- project_pipelines_not_public
- vulnerabilities_slo_days_180
- default_branch_protected - !177981 (merged)
- scanner_secret_detection_running - !184182 (merged)
- merge_requests_approval_rules_prevent_editing
- project_user_defined_variables_restricted
- merge_requests_require_code_owner_approval
- scanner_container_scanning_running - !184182 (merged)
- scanner_dep_scanning_running - !184182 (merged)
- cicd_job_token_scope_enabled
Edited by Andrew Jung