Skip to content

Rollout scorecards across more repos #27

@planetf1

Description

@planetf1

Following the addition of scorecards to liboqs (pending some final doc updates) we should roll-out to other relevant repositories within oqs.

For oqs - especially as it's the most active repo - we decided to not just add the scorecard generation, but also address the findings.

For rollout, there is ongoing discussion about which repos are production/supported. One option is to at least add scorecard generation to them all. Including publishing. It is just a data point. So merge the capture. Then, how we prioritize any fixes is another matter.

Proposed list (will update based on comments)

  • Scorecard for liboqs (until merged)
  • Scorecard for oqs-provider
  • Scorecard for liboqs-rust
  • Scorecard for ci-containers
  • Scorecard for liboqs-cpp
  • Scorecard for liboqs-go
  • Scorecard for liboqs-python

I've not included docs, demos, dotnet, java, libssh, profiling for now as these are stale or less relevant. demos is worth a discussion ,but as it's an aggregate set of contributions I'd skip for now. I did include ci-containers as it's part of our build pipeline.

I'm happy to work through these if there's consensus - specifically on the scan/pr/merge. mitigations later.

An extra task

  • Add more docs on scorecard to www

Metadata

Metadata

Assignees

No one assigned

    Labels

    Low priorityCould be dealt with at a later time

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions