Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

BUG: Unrecognized CI/CDs #4050

Open
gabibguti opened this issue Apr 24, 2024 · 4 comments
Open

BUG: Unrecognized CI/CDs #4050

gabibguti opened this issue Apr 24, 2024 · 4 comments
Labels
kind/bug Something isn't working

Comments

@gabibguti
Copy link
Contributor

Describe the bug
This bug describes CI/CD tools that repositories may use to perform tests and/or releases. These CI/CDs could be detected by Scorecard when evaluating not only checks such as CI-Tests, Packaging and Signed-Releases, but also, Dangerous-Workflow (as suggested in #3630), Pinned-Dependencies and Token-Permissions.

Reproduction steps

Expected behavior
Scorecard identifies CI/CDs tools other than GitHub Actions when evaluating repository pipelines.

Additional context
This CI Detector gem in Ruby can provide some insights on some CI/CDs used by the community:
https://github.com/ruby/ruby/blob/master/lib/rubygems/ci_detector.rb#L11-L25

@gabibguti gabibguti added the kind/bug Something isn't working label Apr 24, 2024
@spencerschrock
Copy link
Member

is this issue intended to organize related issues? Should we use a project board status instead?

@gabibguti
Copy link
Contributor Author

is this issue intended to organize related issues?

Yes.

Should we use a project board status instead?

Can be, if that's easier for organization.

@emaste
Copy link

emaste commented May 2, 2024

Added #4075 for Cirrus-CI

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/bug Something isn't working
Projects
Status: No status
Development

No branches or pull requests

3 participants