Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Suggest Adoption of Scorecard GitHub Action #3363

Closed
diogoteles08 opened this issue Aug 9, 2023 · 3 comments
Closed

Suggest Adoption of Scorecard GitHub Action #3363

diogoteles08 opened this issue Aug 9, 2023 · 3 comments
Assignees
Milestone

Comments

@diogoteles08
Copy link
Contributor

diogoteles08 commented Aug 9, 2023

Hey, I'm Diogo and I've raised the issues #2973 and #3151 contributing with some security enhancements. I'll happily continue contributing with such improvements (it's literally my job, see my profile), but this time I come to suggest the tool that I used myself to find those security issues.

I'd like to suggest that the project add the OpenSSF Scorecard Action. The OpenSSF Scorecard uses GitHub's public API to gather public informations about your project and runs a sort of "meta-analysis" of the project's security posture. The Action then populates the project's Security Panel with possible improvements to its security posture. It's specially helpful to ensure you won't regress on the security measures you have already adopted 😄.

Additionally, the tool integrates with the OSV Scanner, which evaluates a project's transitive dependencies looking for known vulnerabilities.

When working on the Security enhancements pointed by Scorecard, you're also able to apply for the OpenSSF's Secure Open Source Rewards program, which financially rewards developers for improving the security of important open source projects

This tool is developed by the OpenSSF in partnership with GitHub and it's already been adopted by 1800+ projects, including TensorflowPyTorchAngular, and Flutter.

If you're interested, let me know and I'll send a PR!

@derobins derobins self-assigned this Aug 10, 2023
@derobins
Copy link
Member

Hi Diogo! Thanks! I'll give you a tentative 'yes' but let me take a look later today.

@derobins
Copy link
Member

We've added this to CI

@derobins derobins added this to the 1.14.3 milestone Oct 17, 2023
@diogoteles08
Copy link
Contributor Author

Great! Will be happy to hear any future feedback =)

Cheers,

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants