Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

.github: Add Scorecard workflow #16

Merged
merged 3 commits into from
Jun 28, 2024
Merged

.github: Add Scorecard workflow #16

merged 3 commits into from
Jun 28, 2024

Conversation

cisco-service
Copy link
Contributor

👋 This pull request was generated using the installer tool for OpenSSF Scorecard's GitHub Action.

Scorecard helps open source maintainers improve security best practices by running a series of automated checks. As part of ongoing efforts to improve Cisco's open source security posture, we are requiring the Scorecard Action to be installed on all cisco-open member repositories.

🚨 This PR will be merged by an administrator within the next 24-48 hours to ensure full compliance across the organization.

💡 If you have any questions, or would like to learn more about open source security, feel free to reach out to Cisco's Open Source Program Office (OSPO) internally!

@lelia
Copy link
Contributor

lelia commented Jun 28, 2024

FYI — the static code analysis tool being used on this codebase is likely not suitable for correctly interpreting GitHub workflows. It is flagging the presence of the word "secrets" on L26 as being an actual secret.

Per the provided documentation, attempting to mark it as a false positive by adding the inline comment # pragma: allowlist secret to the worfklow does not resolve the issue.

@lelia lelia merged commit 11c9669 into main Jun 28, 2024
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants