Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Determine Sub-Scores for Scorecard Results of this Repo and Assess if Any Actions Should Be Taken #192

Open
jspeed-meyers opened this issue Jun 29, 2024 · 8 comments
Labels

Comments

@jspeed-meyers
Copy link
Collaborator

These is now a Scorecard score on the README. I'd be curious to run the tool on this repo and assess what the different sub-scores are. Additionally, I'd be curious if there is anything this project could do to improve the scores and, finally, if any of those possible actions are "worth" it.

@jspeed-meyers
Copy link
Collaborator Author

The results of Scorecard for this repo can be viewed in a UI here.

@jspeed-meyers
Copy link
Collaborator Author

One of the low-hanging fruit appears to be adding a SECURITY.md file. I've done that in PR #195. Feedback welcome.

@jspeed-meyers
Copy link
Collaborator Author

https://github.com/stacklok/frizbee could could be useful for pinning the versions of the GitHub Actions.

@jspeed-meyers
Copy link
Collaborator Author

PR #206 is yet another small step in pursuing a higher OpenSSF Scorecards score.

@jspeed-meyers
Copy link
Collaborator Author

The next step is to work on reducing the permissions of the GitHub Actions to read-only.

@jspeed-meyers
Copy link
Collaborator Author

Some relevant documentation related to oss-fuzz: https://google.github.io/oss-fuzz/getting-started/accepting-new-projects/

@jspeed-meyers
Copy link
Collaborator Author

Related to assessing GitHub Actions, this tool might be helpful: https://github.com/woodruffw/zizmor

@jspeed-meyers
Copy link
Collaborator Author

I wonder if I should add this: https://google.github.io/osv-scanner/github-action/#scan-on-pull-request

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant