Skip to content

Improve OpenSSF Scorecard report #763

@mbrandenburger

Description

@mbrandenburger

Currently, the FPC repo has a scorecard of 4.3 (see https://scorecard.dev/viewer/?uri=github.com/hyperledger/fabric-private-chaincode)

This issue is about improving our scorecard value by applying best practices as suggested by OpenSSF

TODOS:

  • Dangerous-Workflows
  • Token-Permissions Restrict actions permission #764
  • Vulnerabilities Add Dependabot #759
  • Maintained
  • Code-Review
  • Binary-Artifacts
  • Fuzzing (TBD)
  • SAST
  • Pinned-Dependencies
  • Security-Policy
  • CII-Best-Practices
  • License
  • Branch-Protection
  • Packaging
  • Signed-Releases

Metadata

Metadata

Assignees

No one assigned

    Labels

    help wantedExtra attention is needed

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions