Skip to content

Add OpenSSF Scorecards workflow#358

Merged
kpumuk merged 1 commit intomainfrom
scorecards
Mar 21, 2026
Merged

Add OpenSSF Scorecards workflow#358
kpumuk merged 1 commit intomainfrom
scorecards

Conversation

@kpumuk
Copy link
Copy Markdown
Owner

@kpumuk kpumuk commented Mar 21, 2026

Why?

https://scorecard.dev/ tracks a solid set of security best practices that we want to follow. This is the first step in hardening the repository and CI around that baseline.

How?

Add the official OpenSSF Scorecards GitHub Actions workflow on the default branch with a weekly scheduled run and SARIF upload to GitHub code scanning.

@kpumuk kpumuk merged commit 2eafb12 into main Mar 21, 2026
35 checks passed
@kpumuk kpumuk deleted the scorecards branch March 21, 2026 22:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant