Skip to content

Presto should strive for an OpenSSF scorecard value of >= 7.0 #26263

@tdcmeehan

Description

@tdcmeehan

Expected Behavior or Use Case

See the scorecard value: https://securityscorecards.dev/viewer/?uri=github.com%2Fprestodb%2Fpresto

Many of these are easy to fix, for example, improvements to our usage of tokens and pinning workflows. OpenSSF recommends a score of 7 or higher for all dependencies.

Presto Component, Service, or Connector

CI

Possible Implementation

We should systematically look through each negative score in the scorecard and work to improve it.

Example Screenshots (if appropriate):

The OpenSSF scorecard is a concise and easy to understand the security robustness of a project. It should have a high score so folks have confidence on depending on Presto.

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    Status

    🆕 Unprioritized

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions