Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Integrate OpenSSF's Scorecard GitHub Action #308

Closed
lm-cribl opened this issue Sep 6, 2024 · 0 comments · Fixed by #310
Closed

Integrate OpenSSF's Scorecard GitHub Action #308

lm-cribl opened this issue Sep 6, 2024 · 0 comments · Fixed by #310
Assignees
Labels
enhancement New feature or request

Comments

@lm-cribl
Copy link

lm-cribl commented Sep 6, 2024

Use case

Integrating the OpenSSF GitHub action enables the project to automatically run through a series of automated security checks and produce an artifact that will assist folks who integrate the package assess it's security posture.

Describe the solution you'd like

It would be amazing if the team would enable the GitHub Action for the OpenSSF scorecard

Describe the alternatives you've considered

As an alternative users have the ability to run this manually themselves however I think implementing this will help users understand the security posture of the project and assess the risks the dependency introduces.

@lm-cribl lm-cribl added the enhancement New feature or request label Sep 6, 2024
@juliojimenez juliojimenez self-assigned this Sep 12, 2024
@juliojimenez juliojimenez linked a pull request Sep 12, 2024 that will close this issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants