Skip to content

task: Scorecard — add ossf-scorecard.yml workflow to remaining public repos #276

@mirzakopic

Description

@mirzakopic

Description

Five public, non-archived repos in the platform-mesh org are missing the ossf-scorecard.yml workflow, so they have no Scorecard data. We're flying blind on these repos.

The .github repo or any repo using the standard workflow can be used as a template.

Repos that need a Scorecard workflow

  • kube-bind-provider
  • example-httpbin-operator
  • example-mongodb-multiclusterruntime
  • samples-opendesk-ocm-landscaper
  • poc-kcp-observability

Repos to skip (intentional)

These are docs/community/config repos where Scorecard adds little signal:

  • architecture — design docs
  • community — meeting notes / governance
  • backlog — issue tracker (this repo)
  • coderabbit — central reviewer config

Steps (per repo)

  1. Copy .github/workflows/ossf-scorecard.yml from a repo that already has it (e.g. account-operator).
  2. Open a PR against the repo's default branch.
  3. After merge, wait for the next scheduled run, then verify at https://api.securityscorecards.dev/projects/github.com/platform-mesh/<repo>.

Objectives

  • All five repos publish Scorecard results.
  • New issues filed in this epic for any high-severity findings that turn up.

Demo Required

None

Demo Steps

No response


Epic: #278

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    Backlog

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions