Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Feature] Improvement of OpenSSF Scorecard Score #10908

Open
3 of 6 tasks
harshitasao opened this issue Aug 22, 2024 · 2 comments
Open
3 of 6 tasks

[Feature] Improvement of OpenSSF Scorecard Score #10908

harshitasao opened this issue Aug 22, 2024 · 2 comments
Labels
dependencies Pull requests that update a dependency file enhancement New feature or request

Comments

@harshitasao
Copy link
Contributor

harshitasao commented Aug 22, 2024

Problem Statement

Hi, I'm Harshita. I’m working with CNCF and the Google Open Source Security Team for the GSoC 2024 term. We are collaborating to enhance security practices across various CNCF projects. The goal is to improve security for all CNCF projects by both using OpenSSF Scorecards and implementing its security improvements.

Solution Description

As this project already has scorecard action, I'm here to increase the final score by going over each check. I've listed all of the checks where work needs to be done, in order of its criticality. I plan to submit each PR for each fix. Please let me know what you think and for which ones a PR is welcome that I will submit it ASAP.

Current Score: 8.0

Scorecard report: https://scorecard.dev/viewer/?uri=github.com/kyverno/kyverno

Here's a few checks we can work on to improve the project's security posture:

/cc @joycebrum @diogoteles08 @pnacht @nate-double-u

Alternatives

N/A

Additional Context

reference: #2617

Slack discussion

None

Research

  • I have read and followed the documentation AND the troubleshooting guide.
  • I have searched other issues in this repository and mine is not recorded.
@harshitasao harshitasao added enhancement New feature or request triage Default label assigned to all new issues indicating label curation is needed to fully organize. labels Aug 22, 2024
Copy link

welcome bot commented Aug 22, 2024

Thanks for opening your first issue here! Be sure to follow the issue template!

@realshuting realshuting added dependencies Pull requests that update a dependency file and removed triage Default label assigned to all new issues indicating label curation is needed to fully organize. labels Aug 26, 2024
@realshuting
Copy link
Member

Hi @harshitasao - thanks for taking the time to review and help improve Kyverno!

I can help with branch-protection - currently we require at least one reviewer for approval given the limited availability across all reviewers. I can require review from code owners, would this be enough?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants