-
Notifications
You must be signed in to change notification settings - Fork 102
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Adopt Secure Software Development Best Practices of OpenSSF Scorecard #659
Comments
Below is a scan result of the current state of the repo: Low hanging fruits seem to be
Results:
|
Thanks @gkunz for the evaluation on CodeCompass! @wbqpk3: I made some remarks on the issues you created, to make a start on them. |
Hi all, thank you for evaluating the findings and recommendations by ScoreCard. As shown above, a three recommendations have been adopted in the meantime:
The overall score increased from 5.5 to 6.2
|
Thanks for the revaluation @gkunz! It is nice to see the increase in the achieved score. |
I'd like to propose to evaluate and (selectively) adopt secure software development best practices recommended by the Open Source Security Foundation (OpenSSF) [1]. The OpenSSF Scorecard project checks various development best practices of open source projects hosted on GitHub and provides guidance on how to improve those practices [2]. The overall goal of this issue is to adopt best practices to further mature CodeCompass.
The proposed steps include:
[1] https://openssf.org/
[2] https://github.com/ossf/scorecard/tree/main#scorecard-checks
The text was updated successfully, but these errors were encountered: