-
Notifications
You must be signed in to change notification settings - Fork 12.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add OSSF Scorecard security workflow #2973
Comments
Thanks for opening the issue and reporting this! I installed the OSSF scorecard workflow on a number of projects last year and found it to be too noisy and reports some questionable or non-applicable best practises and ended up removing it. I don't think we should install the OSSF scorecard workflow on H5BP projects but we can review the results of the scan you've provided above and see if there is any action we can take to improve things. |
I can understand that security notifications can become noisy. Then again, possibly they have to be, to be of any use?! I think the best things to improve first might be:
|
I tested this project using OSSF Scorecard by the Open Source Security Foundation. Their aim is:
Unfortunately, this project only received a value of 7.5/10
Please follow these steps to add the Action to the codescanning suite to ensure this project continues to stays safe
Steps to install the workflow
Results of the scan
The text was updated successfully, but these errors were encountered: