Title: Add the OpenSSF Scorecard GitHub Action · Issue #99668 · python/cpython · GitHub
Open Graph Title: Add the OpenSSF Scorecard GitHub Action · Issue #99668 · python/cpython
X Title: Add the OpenSSF Scorecard GitHub Action · Issue #99668 · python/cpython
Description: Feature or enhancement Add the OpenSSF Scorecard GitHub Action, which performs dozens of automated checks to ensure the project's security posture is solid. The Scorecard is a form of project "meta analysis"; it doesn't detect vulnerabil...
Open Graph Description: Feature or enhancement Add the OpenSSF Scorecard GitHub Action, which performs dozens of automated checks to ensure the project's security posture is solid. The Scorecard is a form of project "meta...
X Description: Feature or enhancement Add the OpenSSF Scorecard GitHub Action, which performs dozens of automated checks to ensure the project's security posture is solid. The Scorecard is a form of project &...
Opengraph URL: https://github.com/python/cpython/issues/99668
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Add the OpenSSF Scorecard GitHub Action","articleBody":"# Feature or enhancement\r\n\r\nAdd the [OpenSSF][ossf] [Scorecard GitHub Action][sc], which performs dozens of automated [checks][checks] to ensure the project's security posture is solid. The Scorecard is a form of project \"meta analysis\"; it doesn't detect vulnerabilities in your code, but instead makes sure your settings and security features are following the best practices to minimize the risk of vulnerabilities.\r\n\r\n# Pitch\r\n\r\n[Supply-chain attacks][sonatype] are on the rise. Given Python's self-evident importance to the FOSS ecosystem, the OpenSSF has declared CPython one of the most important open-source projects. \r\n\r\nThe OpenSSF has developed the Scorecard system and accompanying GitHub Action to validate a project's security posture and suggest actionable suggestions (added to the project's security dashboard). And indeed, Scorecards was how the need for https://github.com/python/cpython/pull/92999 was detected, for instance.\r\n\r\nThe Action runs on every push to main and lets maintainers know if there's a misstep that weakened the project's security.\r\n\r\nWould you be interested in a PR to add this workflow?\r\n\r\nIf you have any questions, check out the Scorecards [FAQ][faq] or just ask me!\r\n\r\n# Disclaimer\r\n\r\nI work for Google (an OpenSSF founding member), working full-time to help open-source maintainers improve their projects' security.\r\n\r\n![Detail of a Token-Permissions alert, indicating the specific file and remediation steps][img-detail]\r\n\r\n[checks]: https://github.com/ossf/scorecard#scorecard-checks\r\n[faq]: https://github.com/ossf/scorecard/blob/main/docs/faq.md#frequently-asked-questions\r\n[ossf]: https://openssf.org/\r\n[sc]: https://github.com/ossf/scorecard\r\n[sonatype]: https://www.sonatype.com/state-of-the-software-supply-chain/introduction\r\n\r\n[img-detail]: https://user-images.githubusercontent.com/15221358/190184600-ee8d3b39-077e-416a-8711-1b5fb01cf0b3.png\r\n\n\n\u003c!-- gh-linked-prs --\u003e\n### Linked PRs\n* gh-130485\n\u003c!-- /gh-linked-prs --\u003e\n","author":{"url":"https://github.com/pnacht","@type":"Person","name":"pnacht"},"datePublished":"2022-11-21T22:26:45.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":1},"url":"https://github.com/99668/cpython/issues/99668"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:91c7889a-dd9b-6a5c-fa67-15e4a1d58870 |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | A9EA:27157C:F30BE7:143DB33:69699185 |
| html-safe-nonce | 920df533bc8455b9a9a72ee602bfb17a5b5396c642e48c1e5c9d9b4926219118 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJBOUVBOjI3MTU3QzpGMzBCRTc6MTQzREIzMzo2OTY5OTE4NSIsInZpc2l0b3JfaWQiOiIyMTc1MDM4OTM1ODczOTgyODUzIiwicmVnaW9uX2VkZ2UiOiJpYWQiLCJyZWdpb25fcmVuZGVyIjoiaWFkIn0= |
| visitor-hmac | a146bcc0d2eb3eff52f435191b3cdd250de0e19c140b9014ee3879b56a340d93 |
| hovercard-subject-tag | issue:1458676362 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/python/cpython/99668/issue_layout |
| twitter:image | https://opengraph.githubassets.com/294a85f1086f2205cc2a5cd85d83bab306b09730552dafbb21f5b30fade52299/python/cpython/issues/99668 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/294a85f1086f2205cc2a5cd85d83bab306b09730552dafbb21f5b30fade52299/python/cpython/issues/99668 |
| og:image:alt | Feature or enhancement Add the OpenSSF Scorecard GitHub Action, which performs dozens of automated checks to ensure the project's security posture is solid. The Scorecard is a form of project "meta... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | pnacht |
| hostname | github.com |
| expected-hostname | github.com |
| None | 3542e147982176a7ebaa23dfb559c8af16f721c03ec560c68c56b64a0f35e751 |
| turbo-cache-control | no-preview |
| go-import | github.com/python/cpython git https://github.com/python/cpython.git |
| octolytics-dimension-user_id | 1525981 |
| octolytics-dimension-user_login | python |
| octolytics-dimension-repository_id | 81598961 |
| octolytics-dimension-repository_nwo | python/cpython |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 81598961 |
| octolytics-dimension-repository_network_root_nwo | python/cpython |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | af80af7cc9e3de9c336f18b208a600950a3c187c |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width