Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve OpenSSF Scorecard report #763

Open
4 of 15 tasks
mbrandenburger opened this issue May 16, 2024 · 0 comments
Open
4 of 15 tasks

Improve OpenSSF Scorecard report #763

mbrandenburger opened this issue May 16, 2024 · 0 comments
Labels
help wanted Extra attention is needed

Comments

@mbrandenburger
Copy link
Contributor

mbrandenburger commented May 16, 2024

Currently, the FPC repo has a scorecard of 4.3 (see https://scorecard.dev/viewer/?uri=github.com/hyperledger/fabric-private-chaincode)

This issue is about improving our scorecard value by applying best practices as suggested by OpenSSF

TODOS:

  • Dangerous-Workflows
  • Token-Permissions Restrict actions permission #764
  • Vulnerabilities Add Dependabot #759
  • Maintained
  • Code-Review
  • Binary-Artifacts
  • Fuzzing (TBD)
  • SAST
  • Pinned-Dependencies
  • Security-Policy
  • CII-Best-Practices
  • License
  • Branch-Protection
  • Packaging
  • Signed-Releases
@mbrandenburger mbrandenburger added the help wanted Extra attention is needed label May 17, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
help wanted Extra attention is needed
Projects
None yet
Development

No branches or pull requests

1 participant