logoalt Hacker News

badgersnakeyesterday at 4:45 PM1 replyview on HN

Lots of teams embraced actions to run their CI/CD, and GitHub reviews as part of their merge process. And copilot. Basically their SOC2 (or whatever) says they have to use GitHub.

I’m guessing they’re regretting it.


Replies

swiftcoderyesterday at 4:59 PM

> Basically their SOC2 (or whatever) says they have to use GitHub

Our SOC2 doesn't specify GitHub by name, but it does require we maintain a record of each PR having been reviewed.

I guess in extremis we could email each other patch diffs, and CC the guy responsible for the audit process with the approval...

show 3 replies