Open
Description
What's the problem this feature will solve?
https://github.com/ossf/scorecard is a useful tool for analysing the project's security best-practices. It would be nice to see the pip project add the github action to enable this.
I saw an existing MR using some of this tool's output at #11226, so adding the github action would enable better visibility on any future issues.
Describe the solution you'd like
I can submit a PR for this if you think it would be a good addition to the pip CI workflow. I would probably copy an existing PR like docker/compose#9846 to ensure best practice. The associated issue docker/compose#9845 also has some screenshots of the output.
Alternative Solutions
N/A
Additional context
N/A
Code of Conduct
- I agree to follow the PSF Code of Conduct.