Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add support for OpenSSF Scorecard Score #4673

Open
1 task
ivankatliarchuk opened this issue Aug 12, 2024 · 0 comments
Open
1 task

Add support for OpenSSF Scorecard Score #4673

ivankatliarchuk opened this issue Aug 12, 2024 · 0 comments
Labels
kind/feature Categorizes issue or PR as related to a new feature.

Comments

@ivankatliarchuk
Copy link
Contributor

ivankatliarchuk commented Aug 12, 2024

What would you like to be added:

Example coredns https://github.com/coredns/coredns/blob/master/.github/workflows/scorecards.yml

Example helm helm/helm#13243

OpenSSFF Scorecard https://github.com/ossf/scorecard

Add github action https://github.com/ossf/scorecard-action

Maintainters need to add PAT token https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md

Current Score is 5.0 https://scorecard.dev/viewer/?uri=github.com/gofogo/k8s-sigs-external-dns-fork

Why is this needed:

This project is a collaborative effort between the CNCF and Google's Open Source Security Team to improve security practices across various CNCF projects. The focus is identifying and addressing security vulnerabilities, integrating security tools like OSS-Fuzz, and enhancing build and release security processes. The goal is to get all CNCF projects to use scorecards (focusing on graduated/incubating projects first) and to remediate some of the findings.

Tasks

@ivankatliarchuk ivankatliarchuk added the kind/feature Categorizes issue or PR as related to a new feature. label Aug 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/feature Categorizes issue or PR as related to a new feature.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant