C
Controls enabled 12/18
- Mr approval rules cover all branches
- Mr approval rules min approvals
- Pipeline must not contains hardcoded jobs
- Security policy project
- Branch must be protected
- Cicd variables masked
- Cicd variables protected
- Container images must come from authorized sources
- Container images must not use forbidden reference
- Includes must not use ambiguous tag/branch refs
- Mr approval settings
- Mr settings
- Pipeline must not enable debug trace
- Pipeline must not execute unverified scripts
- Pipeline must not override job variables
- Pipeline must not use Docker-in-Docker
- Pipeline must not use forbidden ref in includes
- Pipeline must not use unsafe variable expansion
- Pipeline must use only up-to-date includes
- Pipelines must include components
- Pipelines must include templates
- Security jobs must not be weakened
- CI/CD variables must be maskednot in this analysis
- CI/CD variables must be protectednot in this analysis
- MR approval rules must cover all protected branchesnot in this analysis
- MR approval rules must require a minimum number of approvalsnot in this analysis
- MR approval settings must be compliantnot in this analysis
This is a custom Plumber score, computed from this repository's own Plumber configuration, not an official Plumber-validated score.