-
Notifications
You must be signed in to change notification settings - Fork 3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Adopt Secure Software Development Best Practices of OpenSSF Scorecard #8922
Comments
Below are the scan results showing the current state of the repository. Low hanging fruits seem to be
Results:
|
The opaque |
@okeuday I understand from #8295 that downloading a binary is problematic. That binary has a sha256 and a sha1, so they are fixed.
I do not think we have the resources to port Alternatively, the documentation can also be inspected from the emulator, I am going to close this issue as we have improved the main issues in this ticket, and there are some other issues that are hardly fixable, like our ways of merging @okeuday feel free to submit a PR with your suggestion, and we can take it into account. |
Is your feature request related to a problem? Please describe.
This feature request proposes to evaluate and (selectively) adopt secure software development best practices recommended by the Open Source Security Foundation (OpenSSF) [1]. The OpenSSF Scorecard project checks various development best practices of open source projects hosted on GitHub and provides guidance on how to improve those practices [2]. The overall goal of this issue is to strengthen the (supply chain) security posture of the CodeChecker project.
Describe the solution you'd like
The proposed solution is:
[1] https://openssf.org/
[2] https://github.com/ossf/scorecard/tree/main#scorecard-checks
The text was updated successfully, but these errors were encountered: