Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: Removed OpenSSF Scorecard #54

Merged
merged 1 commit into from
Dec 28, 2024
Merged

fix: Removed OpenSSF Scorecard #54

merged 1 commit into from
Dec 28, 2024

Conversation

eddie-knight
Copy link
Contributor

Integrating Scorecard as we have in the past is now resulting in a number of false positives on the Security page, due to changes in how GitHub operates. Foremost is (1) the lack of Scorecard support for rulesets and (2) the new immutable version numbering system for GitHub Actions which nullifies the need for pinned versions.

@eddie-knight eddie-knight requested a review from a team as a code owner December 28, 2024 20:16
@eddie-knight eddie-knight changed the title Fix: Removed OpenSSF Scorecard fix: Removed OpenSSF Scorecard Dec 28, 2024
@jmeridth
Copy link
Member

@eddie-knight we need to make sure we've removed the github action from the ruleset as required.

@jmeridth jmeridth merged commit 3a79b8b into main Dec 28, 2024
3 of 4 checks passed
@jmeridth jmeridth deleted the fix/rm-scorecard branch December 28, 2024 20:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants