DISCUSSION: improvements needed by tools scorecard uses or recommends #1620
Replies: 9 comments 2 replies
-
SARIF dashboard: Display vulnerabilities that are ignored in pull requests github/codeql-action#811 |
Beta Was this translation helpful? Give feedback.
-
I think I mentioned this elsewhere but since this issue is supposed to track issues in tools scorecard recommends I'd add a link to a couple of Dependabot issues that have been open for a long time and are unlikely to be fixed anytime soon in hopes it could maybe affect anything: systemd/systemd#21343 (comment) |
Beta Was this translation helpful? Give feedback.
-
Make CodeQl or scanning results publicly available, maybe via an opt-in option #1427 (comment) |
Beta Was this translation helpful? Give feedback.
-
Add pinning variable to GitHub starter workflows actions/starter-workflows#1301 |
Beta Was this translation helpful? Give feedback.
-
It's a long shot but it would be great if LGTM could be used to analyze projects that aren't hosted on GitHub. From https://sourceware.org/bugzilla/show_bug.cgi?id=28659:
I'm not sure if it helps but that was the "elfutils" project, which I think is pretty critical since it's one of those dependencies that's basically everywhere (including systemd as it turned out :-)) |
Beta Was this translation helpful? Give feedback.
-
actions/starter-workflows#1299, which may be on the way to be fixed by @varunsh-coder |
Beta Was this translation helpful? Give feedback.
-
If it still isn't possible to figure out whether the workflow permissions are set to "Read repository contents permission" using GH API I think it should be added to the list so that scorecard wouldn't penalize projects without explicit permissions but with that flag on much. |
Beta Was this translation helpful? Give feedback.
-
@justaugustus I'm not sure why it was moved to the discussions since most of the "ideas" outlined here are real issues either producing false positives or preventing scorecard from being used in really collaborative projects. It's true they can't be fixed by the scorecard project but issues in the dependencies are issues in scorecard as well so I don't think they should be hidden here. |
Beta Was this translation helpful? Give feedback.
-
another relevant issue (for the action) for SARIF github/codeql-action#986 |
Beta Was this translation helpful? Give feedback.
-
This thread is a collection of issues and improvements we'd like to see in the tools scorecard uses or recommends. It was suggested by @evverx
Beta Was this translation helpful? Give feedback.
All reactions