Google's new GitHub app provides automated enforcement of best security practices

GitHub Webpage
(Image credit: Gil C / Shutterstock)

Google and OpenSSF have released a new app called Allstar which provides automated continuous enforcement of security best practices for GitHub projects.

As a member of the open source software (OSS) community, the search giant is well aware of the growing threat posed by software supply chain attacks against open source projects and Allstar is its latest effort to improve their security.

With Allstar, GitHub project owners can check for security policy adherence, set desired enforcement actions and continuously enact those enforcements when triggered b a setting or file change in the organization or project repository according to a new blog post from OpenSFF.

By using this new GitHub app, the open source community can proactively reduce security risk while adding as little friction as possible to their workflows.

Allstar app

Allstar is a companion to Google and the OpenSFF's automated tool Scorecards which assesses risks to a repository and its dependencies.

While Security Scorecards check a number of important heuristics to provide a score to help users understand specific areas to improve in order to strengthen the security posture of their projects, Allstar allows maintainers to opt into automated enforcement of specific checks. However, if a repository fails an enabled check, Allstar intervenes to make the necessary changes to remediate the issue.

Allstar itself works by continuously checking expected GitHub API states and repository file contents such as repository settings, branch settings and workflow settings against defined security policies and applying enforcement actions (filing issues, changing settings) when expected states do not match the policies.

Although OpenSFF runs its own Allstar instance that anyone can install and use, GitHub project owners can also create and run their own instances for security or customization reasons.

To get started with Allstar, GitHub project owners can install the Allstar app here and use these quick start instructions to configure it.

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
GitHub Webpage
GitHub has a major problem with fake rankings, which could put users at risk of attack
An Android phone being held in the hand
Google is ramping up Android security protection with new Android app safety tools
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
Cyber-security
Empowering developers with cutting-edge security training
A hand reaching out to touch a futuristic rendering of an AI processor.
Google Cloud unveils new AI Protection security tools, no matter which model you use
An abstract image of digital security.
Hundreds of GitHub repositories hijacked to trick users into downloading malware
Latest in Security
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content
3d rendering of a submarine power cable on the seabed
Subsea internet cables can now ‘listen’ for sabotage using irregular pulses of light
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
person at a computer
Many workers are overconfident at spotting phishing attacks
Latest in News
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content
A Starfew Valley theme on Wear OS
Someone made a Stardew Valley theme for Wear OS and it's perfect
3d rendering of a submarine power cable on the seabed
Subsea internet cables can now ‘listen’ for sabotage using irregular pulses of light
Google Pixel 9 front and back
The Google Pixel 9a has gone up for sale and it’s not even out yet
Panos Panay and Alexa Plus
Amazon's Panos Panay teases future Alexa+ devices from speakers to possible wearables
Metroid Prime 4
I reckon the Nintendo Switch 2 could launch with Metroid Prime 4 – here’s why