Skip to content

add OpenSSF scorecard workflow#284

Open
viveksahu26 wants to merge 1 commit intoin-toto:masterfrom
viveksahu26:scorecard_workflow
Open

add OpenSSF scorecard workflow#284
viveksahu26 wants to merge 1 commit intoin-toto:masterfrom
viveksahu26:scorecard_workflow

Conversation

@viveksahu26
Copy link
Copy Markdown
Contributor

Fixes issue:
#283

Description:
This is the workflow, which triggers every Saturday and updates the OpenSSF scorecard, which is currently static in nature btw.

Please verify and check that the pull request fulfills the following
requirements:

  • Tests have been added for the bug fix or new feature
  • Docs have been added for the bug fix or new feature

@viveksahu26
Copy link
Copy Markdown
Contributor Author

viveksahu26 commented Nov 22, 2023

Hey @adityasaky, this workflow requires a github token(SCORECARD_TOKEN) in order to check rules for branch protection. Branch protection is one of the evaluation points that is looked up by the OpenSSF scorecard for evaluation score. For more read here.

Copy link
Copy Markdown
Member

@pxp928 pxp928 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Thanks!

@shibumi
Copy link
Copy Markdown
Collaborator

shibumi commented Sep 5, 2024

@viveksahu26 Can you take a look at the PR and update it + rebase it? Sorry for the delay :) I am more active again, so we can get this merged if you want.

@adityasaky can you get us a SCORECARD_TOKEN?

Signed-off-by: Vivek Kumar Sahu <vivekkumarsahu650@gmail.com>
@coveralls
Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 11070616105

Details

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage increased (+0.06%) to 71.437%

Totals Coverage Status
Change from base Build 11055149363: 0.06%
Covered Lines: 2316
Relevant Lines: 3242

💛 - Coveralls

@viveksahu26
Copy link
Copy Markdown
Contributor Author

@shibumi, it's ready now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants