-
Notifications
You must be signed in to change notification settings - Fork 106
Description
The TSC agreed that all of the squads needs to integrate the TSC Scorecard into the Workflows.
The details about the topic from Mark Ackert:
Per the recommendation in the linked PR, I created a modified scorecard workflow we can use to narrow the scan results to our preferred checks. The workflow is in the zowe-install-packaging repo here. A list of available checks are here, but the ID you need to supply to the workflow's SCORECARD_ENABLED_CHECKS differs slightly. I couldn't find a list of IDs, but you can look at the unfiltered results.sar if uploaded after each scorecard run to map a given check to it's ruleId.
There is also a question of efficient deployments of scorecards for large organizations which is in discussion ossf/scorecard#4339. If the scorecard community comes up with a more elegant solution than duplicating a scorecard workflow across many repositories, we can look into adopting it.
Metadata
Metadata
Assignees
Labels
Type
Projects
Status