OpenSSF Scorecard finding: Fuzzing
Add Go fuzz targets using testing.F for input-parsing logic (e.g. dependency version parsing, webhook payload handling). OSS-Fuzz integration gets full credit; native Go fuzzing in CI gets partial credit.
References:
OpenSSF Scorecard finding: Fuzzing
Add Go fuzz targets using testing.F for input-parsing logic (e.g. dependency version parsing, webhook payload handling). OSS-Fuzz integration gets full credit; native Go fuzzing in CI gets partial credit.
References: