Skip to content

multi-scorecard experiment #4502

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 7 commits into
base: main
Choose a base branch
from
Open

multi-scorecard experiment #4502

wants to merge 7 commits into from

Conversation

justaugustus
Copy link
Member

@justaugustus justaugustus commented Jan 25, 2025

THIS IS NOT READY FOR REVIEW

I'm opening this PR to get feedback from CI as I work to integrate this functionality on a feature branch.

What kind of change does this PR introduce?

(Is it a bug fix, feature, docs update, something else?)

What is the current behavior?

Adds the multi-scorecard tool that was featured in @jeffmendoza and my SOSS Fusion talk, "Scorecard at Scale: Old and New Possibilities for Lifting Security on All Repositories": https://sched.co/1hcPq, https://youtu.be/-XZqbO3hGcw?si=eGicz0sjgiIRhol4

What is the new behavior (if this is a feature change)?**

  • Tests for the changes have been added (for bug fixes/features)

Which issue(s) this PR fixes

Special notes for your reviewer

Accompanying subproject PRs: ossf/scorecard-monitor#90, ossf/scorecard-visualizer#453

Does this PR introduce a user-facing change?

For user-facing changes, please add a concise, human-readable release note to
the release-note

(In particular, describe what changes users might need to make in their
application as a result of this pull request.)


Co-authored-by: Jeff Mendoza <jlm@jlm.name>
Signed-off-by: Stephen Augustus <foo@auggie.dev>
@justaugustus justaugustus requested a review from a team as a code owner January 25, 2025 02:51
@justaugustus justaugustus requested review from spencerschrock and raghavkaul and removed request for a team January 25, 2025 02:51
Signed-off-by: Stephen Augustus <foo@auggie.dev>
Signed-off-by: Stephen Augustus <foo@auggie.dev>
Signed-off-by: Stephen Augustus <foo@auggie.dev>
Signed-off-by: Stephen Augustus <foo@auggie.dev>
Signed-off-by: Stephen Augustus <foo@auggie.dev>
Copy link

github-actions bot commented Feb 5, 2025

This pull request has been marked stale because it has been open for 10 days with no activity

Signed-off-by: Stephen Augustus <foo@auggie.dev>
Copy link

This pull request has been marked stale because it has been open for 10 days with no activity

@github-actions github-actions bot added the Stale label Mar 25, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
Status: No status
Development

Successfully merging this pull request may close these issues.

2 participants