Topic route
Search all reviews →Security & Compliance
2 vendor-neutral ToolsPilot guides in this topic.
GitHub Dependency Review Policy: Lockfile, License, and Rollback Checklist (2026)
Build a pull-request dependency review policy that checks lockfile changes, vulnerability severity, license rules, exceptions, and rollback evidence.
8 min
GitHub Actions Artifact Attestations: Build, Verify, and Release Evidence Checklist for 2026
A practical guide to generating and verifying GitHub Actions artifact attestations, binding releases to workflow identity and digest, and avoiding provenance overclaims.
8 min