Skip to content

GitHub security workshop: Add security overview, governance, and rollout exercise #278

Description

@softchris

Goal

Close the workshop by connecting repository alerts to triage operations and organization-wide security rollout decisions.

Scope

Teach alert ownership, prioritization, campaign or backlog planning, coverage visibility, metrics, exceptions, and rollout sequencing. Use organization Security Overview when available, with repository-level sample data and screenshots as a complete fallback for personal-account learners.

Acceptance criteria

  • Learners review code scanning, secret scanning, and dependency findings in a unified triage exercise.
  • The exercise prioritizes findings by exploitability, severity, exposure, and remediation availability rather than raw count alone.
  • Learners assign an owner, target date, and disposition to a small sample backlog.
  • Organization-level coverage and Security Overview concepts are explained with current entitlement requirements.
  • A repository-level fallback provides equivalent learning when organization access is unavailable.
  • The exercise covers staged enablement, developer communication, bypass and dismissal governance, remediation SLAs, and measuring adoption.
  • Learners produce a concise rollout plan for a fictional shelter organization.
  • Final cleanup confirms training alerts, vulnerable branches, test values, and temporary rulesets are removed.
  • The workshop README includes a completion checklist and next-step resources.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions