Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

add OpenSSF scorecard workflow #284

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

viveksahu26
Copy link
Contributor

Fixes issue:
#283

Description:
This is the workflow, which triggers every Saturday and updates the OpenSSF scorecard, which is currently static in nature btw.

Please verify and check that the pull request fulfills the following
requirements:

  • Tests have been added for the bug fix or new feature
  • Docs have been added for the bug fix or new feature

Signed-off-by: Vivek Kumar Sahu <vivekkumarsahu650@gmail.com>
@viveksahu26
Copy link
Contributor Author

viveksahu26 commented Nov 22, 2023

Hey @adityasaky, this workflow requires a github token(SCORECARD_TOKEN) in order to check rules for branch protection. Branch protection is one of the evaluation points that is looked up by the OpenSSF scorecard for evaluation score. For more read here.

Copy link
Member

@pxp928 pxp928 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants