Skip to content

Roll out OSSF scorecard workflow to all repositories #2636

@trask

Description

@trask

For an example of the report that this generates, see https://scorecard.dev/viewer/?uri=github.com/open-telemetry/opentelemetry-java-instrumentation

We are planning to use the scorecard report on Wednesday of this week to help drive a Security Slam event at KubeCon where participants can help to burn down our security backlog.

Note: this is using an automation mechanism similar to #2574 in order to send PRs to add these workflows to all repositories.

Metadata

Metadata

Assignees

No one assigned

    Labels

    triage:acceptedThis issue has been accepted and will be worked.

    Type

    No type

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions