You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Scorecard is becoming a central starting point for developers new to supply chain security who want to learn how to improve their projects, but the docs don’t have a resource for people who land here and don’t know where to start to understand the basic concepts about why Scorecard exists.
I’d propose a “New to Supply Chain Security? Start Here!” type of guide that could have its own page, pointing maintainers to the checks they may way to prioritize first:
Brief intro to supply chain risks generally as applied to open source developers
Three sections talking about the general development workflow for open source and how to protect against common risks
Setting up your project / contributing to your own source code
These sections would be written in a casual, conversational tone and would explain why we suggest starting with the following checks:
Branch protection
Code Review
CI Tests
Token Permissions
Vulnerabilities
Dependency Update Tools
Packaging
@ariathaker has offered to take on writing this page with me; @pnacht has already provided SME guidance. If there's support for adding this page, we'll get right to work!
The text was updated successfully, but these errors were encountered:
Scorecard is becoming a central starting point for developers new to supply chain security who want to learn how to improve their projects, but the docs don’t have a resource for people who land here and don’t know where to start to understand the basic concepts about why Scorecard exists.
I’d propose a “New to Supply Chain Security? Start Here!” type of guide that could have its own page, pointing maintainers to the checks they may way to prioritize first:
These sections would be written in a casual, conversational tone and would explain why we suggest starting with the following checks:
@ariathaker has offered to take on writing this page with me; @pnacht has already provided SME guidance. If there's support for adding this page, we'll get right to work!
The text was updated successfully, but these errors were encountered: