Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

start discussion with ossf/scorecard team to build an initial prototype #1160

Open
zachariahcox opened this issue Sep 30, 2024 · 4 comments
Open

Comments

@zachariahcox
Copy link
Contributor

zachariahcox commented Sep 30, 2024

Goals:

  • new functionality added to scorecard app in a topic branch
  • demonstrate reading from rulesets and repositories APIs to validate at least one best practice
  • demonstrate summarization of those findings into a check that can fail the merge of non-compliant code.
@zachariahcox zachariahcox converted this from a draft issue Sep 30, 2024
@github-project-automation github-project-automation bot moved this to 🆕 New in Issue triage Sep 30, 2024
@zachariahcox zachariahcox moved this to Ready for work! in SLSA Source Track Sep 30, 2024
@TomHennen
Copy link
Contributor

We should file a FR here: https://github.com/ossf/scorecard/issues

And join a community meeting to discuss. Apparently the next one is Oct 17th.

@zachariahcox do you have time to pursue this?

@adityasaky
Copy link
Member

Possibly a starting point: ossf/scorecard#3352

@TomHennen
Copy link
Contributor

Possibly a starting point: ossf/scorecard#3352

Commented there!

@TomHennen
Copy link
Contributor

FYI I attended the Scorecards meeting today to discuss. Folks are open to it. Notes here https://docs.google.com/document/d/1b6d3CVJLsl7YnTE7ZaZQHdkdYIvuOQ8rzAmvVdypOWM/edit?tab=t.0#heading=h.5r8j0smn6u10

Still TBD is who would do this work. (and actually getting a concrete proposal in place to be agreed on more formally)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: 🆕 New
Status: Ready for work!
Development

No branches or pull requests

3 participants