Skip to content

Conversation

@mhucka
Copy link
Collaborator

@mhucka mhucka commented Sep 1, 2025

This adds a workflow to run the open-source vulnerabilities (OSV) scanner that we run in other Quantumlib repos. It also updates the Scorecard scanner workflow to run on PRs, not just weekly, and also print info about the results to the job summary page. Finally, this renames ossf-scorecard.yaml to scorecard-scanner.yaml in an effort to make the purpose a little more clear.

Add a workflow to run the Open-Source Vulnerabilities (OSV) scanner on
pull requests as well as every week.
This updates the Scorecard workflow to run it on pull requests (instead
of only weekly). It also adds a step to print a link on the job summary
page to make it easier to look up the results. Finally, it renames the
file scorecard-scanner.yaml in an effort to be a little more clear.
@mhucka mhucka changed the title Add OSV scanner workflow Fix #406: add missing security scan workflow Sep 1, 2025
@mhucka mhucka added the area/health Issues and PRs related to code, repository, or project health label Sep 1, 2025
Copy link
Collaborator

@pavoljuhas pavoljuhas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, but please see minor comment.

Simplify the URL for the scorecard page per suggestion by @pavoljuhas.

Co-authored-by: Pavol Juhas <[email protected]>
@mhucka mhucka enabled auto-merge (squash) September 3, 2025 03:46
@mhucka mhucka merged commit cbda8e5 into quantumlib:master Sep 3, 2025
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/health Issues and PRs related to code, repository, or project health

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants