-
-
Notifications
You must be signed in to change notification settings - Fork 4.6k
ci: add dep review, OSSF scorecard actions #7063
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Signed-off-by: Mohammed Al Sahaf <[email protected]>
Signed-off-by: Mohammed Al Sahaf <[email protected]>
Signed-off-by: Mohammed Al Sahaf <[email protected]>
Signed-off-by: Mohammed Al Sahaf <[email protected]>
|
We need to go through these (https://scorecard.dev/) and the scorecard to improve the scoring: |
mholt
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Ah, thanks! This should tick some boxes in our list.
Hopefully the permissions don't break releases, but it doesn't look like they would. (We can always test with a RC or something.)
* ci: add dep review action Signed-off-by: Mohammed Al Sahaf <[email protected]> * sprinkle permissions on Actions jobs Signed-off-by: Mohammed Al Sahaf <[email protected]> * README: add OpenSSF best practices badge Signed-off-by: Mohammed Al Sahaf <[email protected]> * add draft OpenSSF Scorecard workflow Signed-off-by: Mohammed Al Sahaf <[email protected]> --------- Signed-off-by: Mohammed Al Sahaf <[email protected]>
It helps avoid conflicting licenses amongst other benefits.
This is a draft until I configure it to our liking (knobs).