Skip to content

Add the OpenSSF Scorecard Github Action #12564

Open
@wwuck

Description

@wwuck

What's the problem this feature will solve?

https://github.com/ossf/scorecard is a useful tool for analysing the project's security best-practices. It would be nice to see the pip project add the github action to enable this.

I saw an existing MR using some of this tool's output at #11226, so adding the github action would enable better visibility on any future issues.

Describe the solution you'd like

I can submit a PR for this if you think it would be a good addition to the pip CI workflow. I would probably copy an existing PR like docker/compose#9846 to ensure best practice. The associated issue docker/compose#9845 also has some screenshots of the output.

Alternative Solutions

N/A

Additional context

N/A

Code of Conduct

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions