Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add OpenSSF Scorecard badge #3658

Merged
merged 1 commit into from
Aug 10, 2023
Merged

Add OpenSSF Scorecard badge #3658

merged 1 commit into from
Aug 10, 2023

Conversation

securitykernel
Copy link
Collaborator

Adds an OpenSSF Scorecard badge to the ReadMe. Scorecard results are increasingly used to assess the trustworthiness of open source software, e.g., in Google's https://deps.dev.

Botan currently scores 7/10, and has some smaller things to improve on. The results can be viewed when following the badge's link or on deps.dev. The checks are documented fairly detailed.

Adds an OpenSSF Scorecard badge to the ReadMe. Scorecard results are increasingly used to assess the trustworthiness of open source software, e.g., in Google's https://deps.dev.

Botan currently scores 7/10, and has some smaller things to improve on. The results can be viewed when following the badge's link or on [deps.dev](https://deps.dev/project/github/randombit%2Fbotan).
@randombit
Copy link
Owner

Fine to merge. Some I do not understand:

Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.
badge detected: passing
5/10

???

The automated helper for pinning etc looks pretty slick! https://app.stepsecurity.io (#3662 adds CodeQL which has been on the todo ever since LGTM got sunset)

@randombit
Copy link
Owner

Oh I see we get 5 for as passing badge and need the "gold" badge to score 10/10

@securitykernel securitykernel merged commit 897f107 into master Aug 10, 2023
33 checks passed
@randombit randombit deleted the sk/scorecard-badge branch August 10, 2023 19:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants