-
Notifications
You must be signed in to change notification settings - Fork 406
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(ci): introduces OSSF Scorecard #2512
chore(ci): introduces OSSF Scorecard #2512
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@heitorlessa just a comment before merge.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
APPROVED!
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM!
Co-authored-by: Leandro Damascena <[email protected]>
Issue number: #2203
Summary
Introduces Open-source Security Foundation Scorecard checks.
It also gives us a score that we can publish as a GitHub Badge later. At first, it'll complain about our lack of provenance (SLSA) and binary signing - these are depending GitHub investigation to ensure published release notes don't disappear with git tags being created from our release workflow.
Changes
User experience
OSSF Scorecard should create new security alerts that could affect supply chain here: https://github.com/aws-powertools/powertools-lambda-python/security
Checklist
If your change doesn't seem to apply, please leave them unchecked.
Is this a breaking change?
RFC issue number:
Checklist:
Acknowledgment
By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.
Disclaimer: We value your time and bandwidth. As such, any pull requests created on non-triaged issues might not be successful.