Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open SSF Scorecard #3107

Open
moonmeister opened this issue Apr 25, 2024 · 0 comments
Open

Open SSF Scorecard #3107

moonmeister opened this issue Apr 25, 2024 · 0 comments
Labels
Type: Chore (updating CI tasks etc; no production code change) Type: Enhancement New feature or request

Comments

@moonmeister
Copy link
Collaborator

What problem does this address?

My feeling is we do a reasonable job of security. That said I'm no expert and it would be good to have a tool to validate we're staying secure and help communicate those intentions and practices to our users.

What is your proposed solution?

https://securityscorecards.dev/

OSSF scorecard checks your security practices and scores the project based on your use of security tools and best practices. Runs on a GitHub Action and the badge can be added to our readme or site as desired. Here's our current scorecard:

https://securityscorecards.dev/viewer/?uri=github.com/wp-graphql/wp-graphql

What alternatives have you considered?

none.

Additional Context

They mention a couple projects who use it: https://github.com/ossf/scorecard?tab=readme-ov-file#prominent-scorecard-users
The CISA seems to recommend it: https://www.cisa.gov/resources-tools/services/openssf-scorecard of

@jasonbahl jasonbahl added Type: Enhancement New feature or request Type: Chore (updating CI tasks etc; no production code change) labels Apr 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Type: Chore (updating CI tasks etc; no production code change) Type: Enhancement New feature or request
Projects
Status: 🆕 New
Development

No branches or pull requests

2 participants