-
Notifications
You must be signed in to change notification settings - Fork 6
Description
Following the addition of scorecards to liboqs (pending some final doc updates) we should roll-out to other relevant repositories within oqs.
For oqs - especially as it's the most active repo - we decided to not just add the scorecard generation, but also address the findings.
For rollout, there is ongoing discussion about which repos are production/supported. One option is to at least add scorecard generation to them all. Including publishing. It is just a data point. So merge the capture. Then, how we prioritize any fixes is another matter.
Proposed list (will update based on comments)
- Scorecard for liboqs (until merged)
- Scorecard for oqs-provider
- Scorecard for liboqs-rust
- Scorecard for ci-containers
- Scorecard for liboqs-cpp
- Scorecard for liboqs-go
- Scorecard for liboqs-python
I've not included docs, demos, dotnet, java, libssh, profiling for now as these are stale or less relevant. demos is worth a discussion ,but as it's an aggregate set of contributions I'd skip for now. I did include ci-containers as it's part of our build pipeline.
I'm happy to work through these if there's consensus - specifically on the scan/pr/merge. mitigations later.
An extra task
- Add more docs on scorecard to www