Skip to content

GitHub security workshop: Add security overview, governance, and rollout exercise #278

Description

@softchris

Goal

Close the workshop by connecting repository alerts to triage operations and organization-wide security rollout decisions.

Scope

Teach alert ownership, prioritization, campaign or backlog planning, coverage visibility, metrics, exceptions, and rollout sequencing. Use organization Security Overview when available, with repository-level sample data and screenshots as a complete fallback for personal-account learners.

Acceptance criteria

  • Learners review code scanning, secret scanning, and dependency findings in a unified triage exercise.
  • The exercise prioritizes findings by exploitability, severity, exposure, and remediation availability rather than raw count alone.
  • Learners assign an owner, target date, and disposition to a small sample backlog.
  • Organization-level coverage and Security Overview concepts are explained with current entitlement requirements.
  • A repository-level fallback provides equivalent learning when organization access is unavailable.
  • The exercise covers staged enablement, developer communication, bypass and dismissal governance, remediation SLAs, and measuring adoption.
  • Learners produce a concise rollout plan for a fictional shelter organization.
  • Final cleanup confirms training alerts, vulnerable branches, test values, and temporary rulesets are removed.
  • The workshop README includes a completion checklist and next-step resources.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority: deferredDeferred pending scope, audience, or entitlement decisions

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions