Skip to content

TSC: Integrate Scorecard Workflow #3758

@balhar-jakub

Description

@balhar-jakub

The TSC agreed that all of the squads needs to integrate the TSC Scorecard into the Workflows.

The details about the topic from Mark Ackert:

Per the recommendation in the linked PR, I created a modified scorecard workflow we can use to narrow the scan results to our preferred checks. The workflow is in the zowe-install-packaging repo here. A list of available checks are here, but the ID you need to supply to the workflow's SCORECARD_ENABLED_CHECKS differs slightly. I couldn't find a list of IDs, but you can look at the unfiltered results.sar if uploaded after each scorecard run to map a given check to it's ruleId.

There is also a question of efficient deployments of scorecards for large organizations which is in discussion ossf/scorecard#4339. If the scorecard community comes up with a more elegant solution than duplicating a scorecard workflow across many repositories, we can look into adopting it.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestpriority-mediumNot functioning - next quarter if capacity permits

    Projects

    Status

    Medium Priority

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions