Skip to content

[bug] Improve Scorecard score #547

@melba-lopez

Description

@melba-lopez

Describe the bug
Improve repository's OpenSSF Scorecard score (currently at 7.1)

To Reproduce
docker run -e GITHUB_AUTH_TOKEN gcr.io/openssf/scorecard:stable --show-details --repo=https://github.com/slsa-framework/slsa-github-generator --format=json > scorecard_slsa-framework_slsa-github-generator.json

Expected behavior

  • Branch Protections could be improved
  • CII-Best-Practices Badge could be obtained
  • Project should be Fuzzed
  • Security Policy should be created
  • Token Permissions should follow principle of least priveledge

Screenshots
image
image
image
image
image

Additional context
Attempted to upload the JSON file, but github does not allow me to. Related to recommendation of securing our repos: slsa-framework/slsa#424

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions