CIS GitHub Benchmark v1.0.0

Ensure Provide a Digitally Signed SBOM for Software Deliverables
Profile Applicability: Level 1 Description: A Software Bill of Materials (SBOM) listing all components, libraries, and dependencies used in the software mu...
Thu, 29 May, 2025 at 3:55 AM
EnsureDefine and Prioritize Trusted Package Managers and Repositories
Profile Applicability: Level 1 Description: Organizations must establish and maintain a list of trusted package managers and repositories that are authoriz...
Thu, 29 May, 2025 at 3:57 AM
Ensure Monitor and Manage Dependencies Among Open-Source Components
Profile Applicability: Level 1 Description: All open-source components and their interdependencies must be actively monitored to identify security vulnerab...
Thu, 29 May, 2025 at 3:57 AM
Ensure Require and Verify Digital Signatures on Build Metadata
Profile Applicability: Level 1 Description: All metadata generated during the build process—such as build logs, configuration files, and artifact manifests...
Thu, 29 May, 2025 at 3:58 AM
Ensure Mandate SBOM Submission from Third-Party Software Suppliers
Profile Applicability: Level 1 Description: All third-party software suppliers must provide a comprehensive Software Bill of Materials (SBOM) detailing the...
Thu, 29 May, 2025 at 3:59 AM
Ensure Authenticity and Integrity of Third-Party Artifacts and Open-Source Libraries
Profile Applicability: Level 1 Description: All third-party software artifacts and open-source libraries used in the development process must be verified f...
Thu, 29 May, 2025 at 3:59 AM
Enforce Digital Signing of SBOMs Within Build Pipelines
Profile Applicability: Level 1 Description: Build and release pipelines must include steps to digitally sign the Software Bill of Materials (SBOM) generate...
Thu, 22 May, 2025 at 4:17 AM
Ensure Generate Software Bill of Materials (SBOM) During Build Pipeline
Profile Applicability: Level 1 Description: Build and release pipelines must include automated steps to generate a Software Bill of Materials (SBOM) that d...
Thu, 29 May, 2025 at 4:01 AM
Ensure Enforce Reproducible Builds in the Build Pipeline
Profile Applicability: Level 1 Description: The build pipeline must be designed and configured to produce reproducible artifacts, meaning that given the sa...
Thu, 29 May, 2025 at 4:02 AM
Ensure Validate Software Dependencies Prior to Integration
Profile Applicability: Level 1 Description: All software dependencies must be validated for authenticity, integrity, and security before being incorporated...
Thu, 29 May, 2025 at 4:03 AM