Skip to content

Add OpenSSF Scorecard GitHub Action #608

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
pnacht opened this issue Nov 7, 2022 · 0 comments
Closed

Add OpenSSF Scorecard GitHub Action #608

pnacht opened this issue Nov 7, 2022 · 0 comments

Comments

@pnacht
Copy link

pnacht commented Nov 7, 2022

Hey, I'm Pedro and I'm working for Google and the OpenSSF to improve the security of critical open-source infrastructure. Given ua-parser-js' popularity, it's been considered one of the 100 most critical open-source projects.

I'd like to suggest the Scorecards GitHub Action, which runs multiple checks to help maintainers understand the project's security posture and warns if there are any accidental missteps, along with actionable suggestions of how to fix any issues.

In fact, I saw PR #583, which was based off the Scorecard system.

Would you be interested in a PR to implement this Action? See an example suggestion (from another project) below:

Detail of a Token-Permissions alert, indicating the specific file and remediation steps

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant