Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enable OpenSSF Scorecard Action #1379

Closed
joycebrum opened this issue Sep 6, 2023 · 3 comments · Fixed by #1382
Closed

Enable OpenSSF Scorecard Action #1379

joycebrum opened this issue Sep 6, 2023 · 3 comments · Fixed by #1382

Comments

@joycebrum
Copy link
Contributor

Hi again, I'd like to suggest the adoption of the OpenSSF Scorecard Action. It is a tool developed by the Open Source Security Foundation that analyse the project looking for possible improvements regarding supply-chain security practices.

It generates warnings with the findings that (optionally) can be seen in the security dashboard. The project's score can also be optionally shared through a badge.
image

Let me know if you are interesting on the tool and I can submit a PR configuring it.

Thanks!

@JakeChampion
Copy link
Owner

@joycebrum I'm happy to try out this tool, if you supply a PR configuring it that'd be great 🙇

@Mertz22
Copy link

Mertz22 commented Sep 11, 2023

How does this tool work can you put me through it

@joycebrum
Copy link
Contributor Author

Sure! It uses the GitHub APIs and GraphQL to gather information about the project and understand possible improvements considering a set of criteria.

These criteria are ways to mitigate known supply-chain attack vectors.

The tool is an Open Source Security Foundation initiative to fight the increasing on supply-chain attack incidents.

JakeChampion pushed a commit that referenced this issue Sep 16, 2023
Closes #1379

Badge score on the badge will be probably be 5.5 (which is a good score).
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Sep 16, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants