Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature: incorporate CLOMonitor-style exemptions #2614

Open
lizrice opened this issue Jan 24, 2023 · 15 comments
Open

Feature: incorporate CLOMonitor-style exemptions #2614

lizrice opened this issue Jan 24, 2023 · 15 comments
Assignees
Labels
kind/enhancement New feature or request Stale
Milestone

Comments

@lizrice
Copy link

lizrice commented Jan 24, 2023

As a CNCF project we've been encouraged to add both CLOMonitor and OpenSSF Scorecard badges, and there's quite a lot of overlap between the security-related checks that CLOMonitor runs, and the Scorecard checks. We reviewed the results from CLOMonitor and found some false positives, for which we've been able to document exemptions so that they don't appear as failed tests. (We really don't want to display a badge that portrays the project as a lot less secure than it really is!)

It would be great if those same exemptions could be pulled in by Scorecard as well. Ideally there would be just one exemptions file per repo acting as the source of truth (i.e. scorecard could re-use the checks that it finds in a .clomonitor file).

@lizrice lizrice added the kind/enhancement New feature or request label Jan 24, 2023
@laurentsimon
Copy link
Contributor

Hey, we've been thinking of creating a config file as well. Thanks for the link, I was not aware of CLOMonitor. Is it a CNCF project?

@lizrice
Copy link
Author

lizrice commented Jan 27, 2023

@lizrice
Copy link
Author

lizrice commented Feb 1, 2023

Seems that CLOmonitor pulls in the tests from Scorecards, so maybe that's where the exemptions should live too. Would be great if the schema for documenting those exemptions could be reused though to save reinventing the wheel

@laurentsimon laurentsimon added this to the Policy file milestone Feb 1, 2023
@github-actions
Copy link

Stale issue message - this issue will be closed in 7 days

@github-actions github-actions bot closed this as not planned Won't fix, can't repro, duplicate, stale Sep 25, 2023
@lizrice
Copy link
Author

lizrice commented Sep 25, 2023

Can I reopen this to get comment from the team?

@spencerschrock
Copy link
Member

Hmm, thought we had disabled the auto close in #3493

@spencerschrock
Copy link
Member

@gabibguti something to consider with the maintainer annotation work

Copy link

This issue is stale because it has been open for 60 days with no activity.

@github-actions github-actions bot added the Stale label Nov 25, 2023
@sandipanpanda
Copy link

Hi, have there been any updates on this issue? I am working on adding the OpenSSF Scorecard badge to Cilium README, and fixing this would help address the issues mentioned here.

cc @spencerschrock

@spencerschrock
Copy link
Member

Hi, have there been any updates on this issue? I am working on adding the OpenSSF Scorecard badge to Cilium README, and fixing this would help address the issues mentioned here.

It's on our roadmap for this quarter. We haven't entirely decided how this will display in terms of the badge.

@github-actions github-actions bot removed the Stale label Jan 20, 2024
Copy link

This issue has been marked stale because it has been open for 60 days with no activity.

@github-actions github-actions bot added the Stale label Mar 22, 2024
@justaugustus justaugustus self-assigned this Mar 28, 2024
@justaugustus
Copy link
Member

FYI @caniszczyk

@caniszczyk
Copy link

cncf/clomonitor#1466

@justaugustus
Copy link
Member

For those tracking this issue, we're getting conversations on the books with the CLOMonitor maintainers to decide on the best integration path for folks leveraging either or both tools.

Stay tuned!

Copy link

This issue has been marked stale because it has been open for 60 days with no activity.

@github-actions github-actions bot added the Stale label May 28, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/enhancement New feature or request Stale
Projects
Status: No status
Development

No branches or pull requests

6 participants