Skip to content

Enable OpenSSF Scorecard Github Action and Badge #47202

Open
@joycebrum

Description

@joycebrum

Hi, I am Joyce and I'm working on behalf of Google and the Open Source Security Foundation (OpenSSF) to help essential open-source projects improve their supply-chain security.

I would like to suggest the adoption of an OpenSSF, in partnership with GitHub, tool called Scorecard. It runs dozens of automated security checks to help maintainer to better understand their project's supply-chain security posture.

To make it easier to use the Scorecard, the OpenSSF has also developed the Scorecard Github Action, which runs the scorecard checks on every push on the main branch and make the result avaiable in the security dashboard, also with proposed solutions (see examples below).

Although the Julia project already scored a great score on the security checks, there are some checks that would be interesting to work on and also the action would help to guarantee that the already followed ones would still be followed.

Would you be interested in a PR which adds this Action? Optionally, it can also publish your results to the OpenSSF REST API, which allows a badge with the project's score to be added to its README.

In case of doubts or concerns you can try to check Scorecards FAQ. Anyway, feel free to reach me out.

Code scanning dashboard with multiple alerts, including Code-Review and Token-Permissions

Detail of a Token-Permissions alert, indicating the specific file and remediation steps

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitySystem security concerns and vulnerabilities

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions