Skip to content

Latest commit

 

History

History
34 lines (26 loc) · 923 Bytes

File metadata and controls

34 lines (26 loc) · 923 Bytes

GitHub-native Control Checklist

Repository package: v0.9.5

This checklist helps teams review GitHub-native controls around VCP adoption. It does not claim that VCP enables these controls automatically.

Checklist areas

  • GitHub Actions PR Gate
  • branch protection
  • required reviews
  • CODEOWNERS
  • issue templates
  • PR templates
  • release notes
  • Dependabot
  • CodeQL if available/enabled
  • secret scanning if available/enabled
  • security policy
  • topics/about/description
  • Discussions if community building is intended

When to use

Use this checklist before a pilot, before a client rollout, and before a team claims GitHub-side governance is actually in place.

Boundaries

  • VCP does not auto-configure GitHub settings.
  • VCP does not publish a Marketplace action.
  • VCP does not certify branch protection, CodeQL, or secret scanning.
  • VCP helps teams review and document whether those controls exist.