Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adopt the Scorecard Action to monitor the project's security posture #7625

Closed
pnacht opened this issue Dec 21, 2023 · 0 comments · Fixed by #7626
Closed

Adopt the Scorecard Action to monitor the project's security posture #7625

pnacht opened this issue Dec 21, 2023 · 0 comments · Fixed by #7626

Comments

@pnacht
Copy link
Contributor

pnacht commented Dec 21, 2023

Hey, it's Pedro and I'm back (see #7594 and my colleague Joyce's #7541 and #7546) with another security suggestion.

Joyce and I detected these issues by using the OpenSSF Scorecard, which scans a repository looking for code or settings that can be changed to improve a project's supply-chain security. It is available as a GitHub Action which routinely runs on the repo and adds actionable suggestions directly to the project's Security Dashboard. It can therefore warn you if any change unintentionally weakens the project's security posture.

For the record, RxJava's current score is 8.5/10, which is awesome! In fact, it's in the top 0.1% of popular projects!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant