Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve OpenSSF Scorecard Score #291

Open
pjbgf opened this issue Jan 11, 2022 · 0 comments
Open

Improve OpenSSF Scorecard Score #291

pjbgf opened this issue Jan 11, 2022 · 0 comments
Labels
area/security Security related issues and PRs help wanted Extra attention is needed

Comments

@pjbgf
Copy link
Member

pjbgf commented Jan 11, 2022

"The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects."

As of 16th November, fluxcd/image-automation-controller scores 7.8/10. For latest score check deps.dev or manually execute scorecard.

image

Areas to focus on:

  • Token-Permissions
  • Dependency-Update-Tool
  • Pinned-Dependencies
@pjbgf pjbgf added help wanted Extra attention is needed area/security Security related issues and PRs labels Nov 21, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/security Security related issues and PRs help wanted Extra attention is needed
Projects
Status: No status
Development

No branches or pull requests

1 participant