Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add OpenSSF Scorecard to the project CI #3481

Open
gpshead opened this issue Jan 5, 2023 · 0 comments
Open

Add OpenSSF Scorecard to the project CI #3481

gpshead opened this issue Jan 5, 2023 · 0 comments
Labels
C: maintenance Related to project maintenance, e.g. CI, testing, policy changes, releases T: enhancement New feature or request

Comments

@gpshead
Copy link
Contributor

gpshead commented Jan 5, 2023

Please consider adopting https://github.com/ossf/scorecard in your project CI.

TL;DR - It scans CI configs for token permission overreach security issues and looks at transitive deps with issues to surface potential problems. (running it will give you a better idea than I can list off the top of my head)

@gpshead gpshead added the T: enhancement New feature or request label Jan 5, 2023
@ichard26 ichard26 added the C: maintenance Related to project maintenance, e.g. CI, testing, policy changes, releases label Jan 5, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
C: maintenance Related to project maintenance, e.g. CI, testing, policy changes, releases T: enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants