Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve OpenSSF Scorecard Score #214

Open
pjbgf opened this issue Jan 11, 2022 · 6 comments
Open

Improve OpenSSF Scorecard Score #214

pjbgf opened this issue Jan 11, 2022 · 6 comments

Comments

@pjbgf
Copy link
Member

pjbgf commented Jan 11, 2022

"The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects."

As of 3rd January, fluxcd/pkg scores 6.2/10. For latest score check deps.dev or manually execute scorecard.

image

Areas to focus on:

@hiddeco
Copy link
Member

hiddeco commented Jan 11, 2022

The statistics shown there are outdated, as we moved from <semver> to <module>/<semver> after the creation of the repository. See e.g. https://deps.dev/go/github.com%2Ffluxcd%2Fpkg%2Fruntime

@pjbgf
Copy link
Member Author

pjbgf commented Jan 11, 2022

@hiddeco the security advisories is indeed out of date. But the OpenSSF scorecard is at GitHub repository level, so should be the same across all modules.

@justaugustus
Copy link

Hey folks, (new) Scorecard maintainer here!
I see @pjbgf on OpenSSF, but just wanted to invite you all to file feature requests/bugs on https://github.com/ossf/scorecard/issues and we'll take a peek. :)

@laurentsimon
Copy link

There's an easy way to keep track of scorecard issues using the action https://github.com/ossf/scorecard-action
It's integrated in the GitHub scanning dashboard.
Don't forget that the hard work you put it could be rewarded via sos.dev!

@pjbgf
Copy link
Member Author

pjbgf commented Jan 31, 2022

@justaugustus okie dokie, I previously reported issues by email. From now on will do via that repo. Thanks for the heads up. 👍

@pjbgf
Copy link
Member Author

pjbgf commented Jan 31, 2022

There's an easy way to keep track of scorecard issues using the action https://github.com/ossf/scorecard-action

@laurentsimon nice one, I will take a look at the action.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants