-
Notifications
You must be signed in to change notification settings - Fork 13
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Introduce OpenSSF Best Practices Badge rule #238
Conversation
Add a rule that ensures that the project has an OpenSSF Best Practices badge at the specified level (defaulting to: "passing"). This is driven by the OpenSSF Best Practices data source, which queries bestpractices.dev. Add the new rule type to the OpenSSF Scorecard profile.
47e7266
to
ef21e81
Compare
# Defines the configuration for alerting on the rule | ||
alert: | ||
type: security_advisory | ||
security_advisory: {} |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
nit: Should we stop adding the security_advisory
alert? we probably want to deprecate this anyway.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes but I think that it makes sense to burn it down so that the rules are consistent with each other, instead of having a few that are one way and a few that are another.
version: v1 | ||
release_phase: alpha | ||
type: rule-type | ||
name: openssf_bestpractices |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This must match the file name.
guidance: | | ||
The [OpenSSF Best Practices Badge](https://www.bestpractices.dev/en) | ||
program allows open source projects to show that they follow best | ||
security practices. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This guidance looks a little off. The intent is to tell people what to do if they fail this check.
Updated in #243 |
Add a rule that ensures that the project has an OpenSSF Best Practices badge at the specified level (defaulting to: "passing"). This is driven by the OpenSSF Best Practices data source, which queries bestpractices.dev.
Add the new rule type to the OpenSSF Scorecard profile.