Rare find

Bad Practices Catalog. A collection of security practices that are dangerously risky and should be avoided.

cisa.gov/BadPractices

Vaya's read on this project

Problem, audience, market, and the verdict — sign in to see it.

Updates

March 2026
  • Merge pull request #96 from cisagov/lineage/skeleton
  • Merge https://github.com/cisagov/skeleton-generic into lineage/skeleton
  • Merge pull request #259 from cisagov/maintenance/update_pre-commit_hooks
  • Merge pull request #256 from cisagov/improvement/add_pre-commit_hook_…
  • Merge pull request #255 from cisagov/improvement/update_flake8_config…
  • Merge pull request #254 from cisagov/bug/adjust_gocritic_install
  • Merge pull request #253 from cisagov/improvement/remove_bandit_config…
  • Revert version bump of the `ansible-lint` pre-commit hook
  • Update pre-commit hook versions
  • Merge pull request #251 from cisagov/dependabot/github_actions/crazy-…
  • Merge pull request #252 from cisagov/dependabot/github_actions/hashic…
  • Merge pull request #258 from cisagov/ignore-pygments-vuln
  • Correct reference to ticket in TODO comment
  • Ignore a vulnerability originating from pygments
  • Add pre-commit hook to lock Terraform providers automatically
  • Update ignore comment in the flake8 configuration
  • Update a reference URL
  • Use `https://` instead of `http://` in referenced URLs
  • Remove the bandit configuration file
  • Install the `go-critic` command instead of `gocritic`
April 2025
  • Release —v1.0.0