Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add the OpenSSF Scorecard Action workflow #1108

Closed
pnacht opened this issue Sep 15, 2023 · 3 comments · Fixed by #1109
Closed

Add the OpenSSF Scorecard Action workflow #1108

pnacht opened this issue Sep 15, 2023 · 3 comments · Fixed by #1109

Comments

@pnacht
Copy link
Contributor

pnacht commented Sep 15, 2023

Hey, it's Pedro (see #844, #953, and #1103) and I've got a new security suggestion:

Would you be interested in the Scorecard Action? It'll frequently run Scorecard and populate jackson-core's Security Panel with actionable suggestions to improve its supply-chain security. In this way, it'll also alert you if a misstep accidentally weakens your security.

I'll send a PR with the Action for you to take a look.

By the way, I saw you've added the Scorecard badge (congrats on the 7.4/10! That puts you in the top 5% of important projects!).

@cowtowncoder
Copy link
Member

Sounds good to me -- we can try it out and see how it works. My only concern is that some tools/actions are spammy etc; but it is nice to be notified of regressions to be sure.

@pnacht
Copy link
Contributor Author

pnacht commented Sep 19, 2023

The Action shouldn't be too spammy: it'll warn you whenever something new comes up, but not keep repeating the same things over and over again.

If you have any problems with it (or just feedback more generally), let me know!

@cowtowncoder
Copy link
Member

Thank you again, @pnacht !

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants