-
Notifications
You must be signed in to change notification settings - Fork 177
Closed
Labels
status:help wantedExtra attention is neededExtra attention is neededtype:bugSomething isn't workingSomething isn't working
Description
Describe the bug
Improve repository's OpenSSF Scorecard score (currently at 7.1)
To Reproduce
docker run -e GITHUB_AUTH_TOKEN gcr.io/openssf/scorecard:stable --show-details --repo=https://github.com/slsa-framework/slsa-github-generator --format=json > scorecard_slsa-framework_slsa-github-generator.json
Expected behavior
- Branch Protections could be improved
- CII-Best-Practices Badge could be obtained
- Project should be Fuzzed
- Security Policy should be created
- Token Permissions should follow principle of least priveledge
Additional context
Attempted to upload the JSON file, but github does not allow me to. Related to recommendation of securing our repos: slsa-framework/slsa#424
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
status:help wantedExtra attention is neededExtra attention is neededtype:bugSomething isn't workingSomething isn't working




