Enable OSSF Scorecard Code-Scanning for this Repository through scorecard.yml
Workflow
#92
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Enable OSSF Scorecard Code-Scanning for this Repository through
scorecard.yml
WorkflowProblem
It is good to record the results of the OSSF scorecard scan for maintainability reasons as well as to create value in other areas such as the upcoming PyCon poster. Currently we are not using OSFF scorecard code-scanning.
Solution
I have enabled OSSF scorecard scanning through the GitHub UI. This workflow will carry out the OSSF code-scanning and upload it to the GitHub code-scanning dashboard. It will also carry out the optional branch-protection check. Currently, the workflow is also set to publish the results of the scan to the OSSF api.
Result
A new workflow is added that runs on push to main as well as on a regular interval set by a cron job. OSSF scorecard code-scanning is carried out by this job.