Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OpenSSF Scorecard Incubating application #390

Merged
merged 2 commits into from
Oct 21, 2024

Conversation

justaugustus
Copy link
Member

@justaugustus justaugustus commented Oct 3, 2024

cc: @ossf/tac @ossf/wg-best-practices @ossf/scorecard
xref: ossf/scorecard#4200

@justaugustus justaugustus requested a review from a team as a code owner October 3, 2024 22:57
Copy link
Contributor

@mlieberman85 mlieberman85 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

Copy link
Contributor

@SecurityCRob SecurityCRob left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I stronlgy voice my support of our Scorecard team moving up to our Incubating level

@marcelamelara marcelamelara added the TI Lifecycle Issue/PR related to TIs' lifecycle status. Needs 5 approvals, 10d review. label Oct 11, 2024
Copy link
Contributor

@marcelamelara marcelamelara left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Really exciting to see Scorecards reach this stage!

Copy link
Member

@steiza steiza left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have a clarification question around Scorecard and Allstar (that maybe was just a copy-paste error)?

Otherwise, I strongly support OpenSSF Scorecard becoming incubating. Its adoption is well past the point of a sandbox project.

README.md Outdated Show resolved Hide resolved
- Raghav Kaul, Google, [@raghavkaul](https://github.com/raghavkaul)
- Jeff Mendoza, Kusari, [@jeffmendoza](https://github.com/jeffmendoza)
- Spencer Schrock, Google, [@spencerschrock](https://github.com/spencerschrock)
- Laurent Simon, Independent, [@laurentsimon](https://github.com/laurentsimon)
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I thought Laurent was still at Google, is that really accurate?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.


The mission of OpenSSF Scorecard is to automate analysis on the security posture of open source projects.

The current charter of the OpenSSF Scorecard project can be found [here](https://github.com/ossf/scorecard/blob/main/CHARTER.md).
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please, don't use "here" as a link anchor. That's an anti-pattern (and a pet peeve of mine: https://lehors.wordpress.com/2009/01/29/linking-the-proper-way/ :-)

@lehors
Copy link
Contributor

lehors commented Oct 15, 2024

I too support the gist of this request but also expect allstar to be handled separately so, awaiting clarification on the situation on that front to approve.
Also, although we have yet to update our template accordingly our process now has the following requirement (see Incubating):

For code development, follows security best practices (as recommended by the OpenSSF and others), including achieving a Silver OpenSSF Best Practices badge.

Is that requirement met?

Thanks.

@jeffmendoza
Copy link
Member

I know the Allstar and Scorecard projects are closely related, but I think since today they are separate projects they should have their own project lifecycle?

but also expect allstar to be handled separately so

Allstar became a part of the Scorecard project back in May, they are no longer separate. This was included in the TAC update on May 14th for the SCP WG: https://docs.google.com/presentation/d/1l6VlRD4L4vUZ_6ogsBYTvRcfT0lZYpYE_O-0bdSksoQ/edit#slide=id.p1

Some prs:
https://github.com/ossf/allstar/pull/517/files
https://github.com/ossf/wg-securing-critical-projects/pull/91/files

Co-authored-by: Zach Steindler <[email protected]>
Signed-off-by: CRob <[email protected]>
Copy link
Contributor

@sevansdell sevansdell left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve

@steiza steiza merged commit 2530162 into ossf:main Oct 21, 2024
1 check passed
@steiza
Copy link
Member

steiza commented Oct 21, 2024

Scorecard is now officially incubating - congrats!

@justaugustus
Copy link
Member Author

Very cool!
Thanks for the reviews, @ossf/tac!!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
TI Lifecycle Issue/PR related to TIs' lifecycle status. Needs 5 approvals, 10d review.
Projects
None yet
Development

Successfully merging this pull request may close these issues.