Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add OpenSSF Scorecard Github Action and Badge #3140

Closed
lucacome opened this issue Oct 12, 2022 · 0 comments · Fixed by #3132
Closed

Add OpenSSF Scorecard Github Action and Badge #3140

lucacome opened this issue Oct 12, 2022 · 0 comments · Fixed by #3132
Assignees
Labels
proposal An issue that proposes a feature request

Comments

@lucacome
Copy link
Member

Is your feature request related to a problem? Please describe.
I'd like to improve the security of the project, especially against supply-chain attacks. Scorecard will help us track and resolve security risks in our repository and the badge can be a good way to show our users and contributors our commitment to increase the security of the project.

Describe the solution you'd like
The Scorecard system combines dozens of automated checks to let maintainers better understand their project's supply-chain security posture. It is developed by the OpenSSF, with direct support from GitHub.

The OpenSSF has also developed the Scorecard GitHub Action, which adds the results of its checks to the project's security dashboard, as well as suggestions on how to solve any issues (see examples in the Additional context). This Action has been adopted by 1600+ projects already.

I'd like to see the Scorecard GitHub Action and badge added to the project.

Additional context
These are examples of alerts and not from this repo.

image

image

@lucacome lucacome added the proposal An issue that proposes a feature request label Oct 12, 2022
@lucacome lucacome self-assigned this Oct 12, 2022
@lucacome lucacome linked a pull request Oct 12, 2022 that will close this issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
proposal An issue that proposes a feature request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant