Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add the OpenSSF Scorecard Action #4296

Closed
pnacht opened this issue Jun 23, 2023 · 1 comment · Fixed by #4300
Closed

Add the OpenSSF Scorecard Action #4296

pnacht opened this issue Jun 23, 2023 · 1 comment · Fixed by #4300

Comments

@pnacht
Copy link
Contributor

pnacht commented Jun 23, 2023

I'm back (see #4191, #4194 and #4273) with another security suggestion!

I managed to detect all of these possible improvements by using the OpenSSF Scorecard. It's a tool that runs a sort of "meta-analysis" of the repo's security-posture and gives actionable suggestions on how to improve.

The tool is also available as a workflow Action that scans the repo after every commit to make sure there aren't any hiccups. Anything it detects gets sent to the project's Security Panel for easy access and management.

Spoiler alert: harfbuzz currently gets a 7.1/10, which puts it in the top 10% of relevant projects!

@behdad
Copy link
Member

behdad commented Jun 23, 2023

Sounds good to me. :D

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants