-
Notifications
You must be signed in to change notification settings - Fork 98
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bring CLOMonitor Score to 100% #970
Comments
Hi @hernanpl, thanks a lot for creating this issue for us. As a part of Security Slam, we heavily attacked the Security section of CLO monitor today.
Concerns:
Could you please help with addressing concerns? I believe we made good progress today and it deserves some more monitor scores :) |
This is perfect for the security slam, where the metric is just CLOMonitor's |
So there are two things happening here. The first one is that Secondly... I noticed that a few files don't have any permissions applied. These are also instant failures for the check.
edit: I also just noticed that release.yml has a top-level |
@eddie-knight thanks a lot for the catch, I had an illusion that the secure-workflows tooling automatically fixed all issues for me :) Created additional #1002 |
Just to not here for future reference. The way to locally get detailed token permissions feedback
|
Good progress with overall local result:
|
@eddie-knight #1002 was merged, I also reported ossf/scorecard#2338 (comment) Is there anything more we can do? Really keen to score 100 :) |
@ytsarev I pinged the OpenSSF Scorecard channel discussing the release, need to get that cut before it can be propogated out to CLOMonitor |
Thanks a lot @eddie-knight ! Just to be sure that we are good with the evaluation, I've built the scorecard from the
Thank you so much for the associated PR ossf/scorecard#2367 |
We are all green at https://clomonitor.io/projects/cncf/k8gb ! Closing this one :) |
This repo is signed up as part of the KubeCon Security Slam. I'm bringing to your attention the checklist from the official CLOMonitor page for K8GB -- it refreshes every hour, so it should be up-to-date.
CLOMonitor report
Summary
Repository: k8gb
URL: https://github.com/k8gb-io/k8gb
Checks sets:
COMMUNITY
+CODE
Score: 84
Checks passed per category
Checks
Documentation [93%]
License [100%]
Best Practices [85%]
EXEMPT
EXEMPT
Security [75%]
Legal [0%]
For more information about the checks sets available and how each of the checks work, please see the CLOMonitor's documentation.
The text was updated successfully, but these errors were encountered: