Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Show openssf results in for private repos as a github issue #1441

Open
nitrocode opened this issue Sep 4, 2024 · 2 comments
Open

Show openssf results in for private repos as a github issue #1441

nitrocode opened this issue Sep 4, 2024 · 2 comments

Comments

@nitrocode
Copy link

Since advanced security is very expensive, it would be nice to follow something like the renovatebot dashboard as a github issue and create an OpenSSF scorecard dashboard as a github issue. Once the issue is created, it can be edited in place.

SAP/guided-answers-extension#477

If it's decided to not do this, it would be nice to document using an upstream action to do this for us.

E.g. run this action to get the scorecard results, then pass to another action to manage the markdown and dashboard issue

@lelia
Copy link

lelia commented Sep 5, 2024

While I don't believe a Renovate-like dashboard currently exists for Scorecard, you may want to check out Scorecard Monitor, which can file issues/PRs reporting Scorecard results across multiple repositories, and also integrates with StepSecurity to provide potential remediation steps.

Here is a sample report and example of remediation steps provided by StepSecurity (GitHub auth required to view).

@spencerschrock
Copy link
Member

To clarify, you're asking about private repositories (since advanced security is free for public repos) ?

Have you considered Allstar? I believe it has the machinery to create issues on all (?) Scorecard checks? This may be overkill what you want though! Especially since Allstar requires administrative permissions, or self-hosting your own copy.

If it's decided to not do this, it would be nice to document using an upstream action to do this for us.

I think this may be the simplest approach, although I dont think there are any ready out of the box.

you may want to check out Scorecard Monitor,

My understanding is it hits the Scorecard API, which wouldn't be available for private repositories.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants