Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ossf/scorecard vulnerabilities fix tracking issue #482

Closed
developer-guy opened this issue Oct 26, 2021 · 1 comment
Closed

ossf/scorecard vulnerabilities fix tracking issue #482

developer-guy opened this issue Oct 26, 2021 · 1 comment
Labels
enhancement New feature or request

Comments

@developer-guy
Copy link
Contributor

developer-guy commented Oct 26, 2021

What would you like to be added:

We recently ran the ossf/scorecard1 over the Grype project, found some vulnerabilities, here is the output of the scan:

$ docker run -e GITHUB_AUTH_TOKEN=$GITHUB_TOKEN gcr.io/openssf/scorecard:stable --repo https://github.com/developer-guy/grype

Screen Shot 2021-10-26 at 01 05 31
Screen Shot 2021-10-26 at 01 05 42

Why is this needed:

To make Grype more secure.

Additional context:

cc: @wagoodman @luhring @Dentrax

Footnotes

  1. https://github.com/ossf/scorecard

@kzantow
Copy link
Contributor

kzantow commented Nov 29, 2022

We have since added scorecard and have individual issues to address the lower scores, so I'm going to close this one. Please reopen if you deem it necessary!

@kzantow kzantow closed this as completed Nov 29, 2022
@kzantow kzantow moved this to Done in OSS Nov 29, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
Archived in project
Development

No branches or pull requests

2 participants