[{"data":1,"prerenderedAt":1345},["ShallowReactive",2],{"home":3},{"id":4,"title":5,"body":6,"description":1336,"extension":1337,"meta":1338,"navigation":81,"path":1342,"seo":1343,"stem":1340,"__hash__":1344},"content\u002Fhome.md","Home",{"type":7,"value":8,"toc":1308},"minimark",[9,26,1304],[10,11,12,13],"div",{},"\n  ",[14,15],"sidebar",{"ref":16,"className":17},"sideBar",[18,19,20,21,22,23,24,25],"sticky","top-60","h-400","min-w-max","w-1\u002F3","hidden","md:block","mr-80",[27,28,34,41,45,62,67,135,139,474,479,492,504,508,511,514,522,531,533,537,542,545,548,551,608,610,612,617,627,629,633,654,673,680,686,688,692,696,699,707,718,722,765,873,960,964,1054,1058,1147,1149,1159,1170,1174,1178,1182,1185,1189,1192,1196,1199,1201,1205,1208,1212,1255,1264,1273,1276,1278,1282,1288,1296],"section",{"className":29},[30,31,32,33],"bg-orange","prose","md:prose-lg","w-full",[35,36,40],"h2",{"className":37,"id":39},[38],"h1","run-the-checks","Run the checks",[42,43,44],"p",{},"OpenSSF Scorecard can be used in a couple of different ways:",[46,47,48,56],"ol",{},[49,50,51,52],"li",{},"Run automatically on code you own ",[53,54,55],"strong",{},"using the GitHub Action",[49,57,58,59],{},"Run manually on your (or somebody else’s) project ",[53,60,61],{},"via the Command Line",[63,64,66],"h3",{"id":65},"using-the-github-action","Using the GitHub Action",[27,68,71,75,78,95,99,126],{"className":69},[70],"highlight-section",[63,72,74],{"id":73},"install-time-10-mins","Install time: \u003C10 mins",[42,76,77],{},"Use the action to automatically scan any code updates for security vulnerabilities. Any time someone commits a change, the action will automatically check the repo and alert you (and other maintainers) if there are problems.",[79,80,82,86],"details",{"open":81},true,[83,84,85],"summary",{},"See it in action",[87,88,12],"iframe",{"title":89,"width":90,"height":91,"allow":92,"loop":93,"src":94},"action video","100%",393,"autoplay","true","assets\u002Fgithub-action.mp4?autoplay=1&controls=0&loop=1&mute=1",[63,96,98],{"id":97},"installation-instructions","Installation instructions",[46,100,101,104,114],{},[49,102,103],{},"You need to own the repository you are installing the action to, or have admin rights to it.",[49,105,106,113],{},[107,108,112],"a",{"href":109,"rel":110},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard-action#authentication",[111],"nofollow","Authenticate"," your access to the repository with a Personal Access Token",[49,115,116,117,122,123],{},"Add Scorecard to your ",[107,118,121],{"href":119,"rel":120},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard-action#workflow-setup",[111],"codescanning suite"," inside GitHub using the link below:\n",[124,125],"br",{},[42,127,128],{},[107,129,134],{"href":130,"className":131},"https:\u002F\u002Fgithub.com\u002Fmarketplace\u002Factions\u002Fossf-scorecard-action",[132,133],"btn","cta-icon","Install the action",[63,136,138],{"id":137},"using-the-cli","Using the CLI",[27,140,142,146,149,161,170,174,193,463,466,468],{"className":141},[70],[63,143,145],{"id":144},"install-time-10mins","Install time: \u003C10mins",[42,147,148],{},"You can use Scorecard on the Command Line. This enables you to:",[150,151,152,155,158],"ul",{},[49,153,154],{},"Check someone else’s repository",[49,156,157],{},"Select which checks you want to run",[49,159,160],{},"Control how detailed your results are",[79,162,163,165],{"open":81},[83,164,85],{},[87,166,12],{"title":167,"width":90,"height":168,"allow":92,"loop":93,"src":169},"CLI video",477,"assets\u002Fcli.mp4?autoplay=1&controls=0&loop=1&mute=1",[63,171,173],{"id":172},"install-and-run","Install and run",[46,175,176,185],{},[49,177,178,179,184],{},"Create a ",[107,180,183],{"href":181,"rel":182},"https:\u002F\u002Fdocs.github.com\u002Fen\u002Fauthentication\u002Fkeeping-your-account-and-data-secure\u002Fcreating-a-personal-access-token",[111],"GitHub personal access token"," with 'public_repo' scope. Store the token somewhere safe.",[49,186,187,188],{},"Choose a language-specific quick start below, or refer to our ",[107,189,192],{"href":190,"rel":191},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard#scorecard-command-line-interface",[111],"detailed instructions",[194,195,12,196,12,339,12,396],"code-group",{},[197,198,201,12],"code-block",{"title":199,"active":200},"Homebrew","",[202,203,207],"pre",{"className":204,"code":205,"language":206,"meta":200,"style":200},"language-bash shiki shiki-themes nord","# For posix platforms, e.g. linux, mac:\nexport GITHUB_AUTH_TOKEN=\u003Cyour access token>\n\n# For windows:\nset GITHUB_AUTH_TOKEN=\u003Cyour access token>\n\nbrew install scorecard\n\nscorecard --repo=\u003Cyour choice of repo e.g. github.com\u002Fossf-tests\u002Fscorecard-check-branch-protection-e2e>\n","bash",[208,209,210,219,245,251,257,284,289,301,306],"code",{"__ignoreMap":200},[211,212,215],"span",{"class":213,"line":214},"line",1,[211,216,218],{"class":217},"s8hdm","# For posix platforms, e.g. linux, mac:\n",[211,220,222,226,230,233,236,239,242],{"class":213,"line":221},2,[211,223,225],{"class":224},"sGPm4","export",[211,227,229],{"class":228},"sIPZU"," GITHUB_AUTH_TOKEN",[211,231,232],{"class":224},"=\u003C",[211,234,235],{"class":228},"your",[211,237,238],{"class":228}," access",[211,240,241],{"class":228}," token",[211,243,244],{"class":224},">\n",[211,246,248],{"class":213,"line":247},3,[211,249,250],{"emptyLinePlaceholder":81},"\n",[211,252,254],{"class":213,"line":253},4,[211,255,256],{"class":217},"# For windows:\n",[211,258,260,264,268,271,273,275,278,282],{"class":213,"line":259},5,[211,261,263],{"class":262},"st_Lx","set",[211,265,267],{"class":266},"sUFv7"," GITHUB_AUTH_TOKEN=",[211,269,270],{"class":224},"\u003C",[211,272,235],{"class":266},[211,274,238],{"class":266},[211,276,277],{"class":266}," toke",[211,279,281],{"class":280},"s0_w5","n",[211,283,244],{"class":224},[211,285,287],{"class":213,"line":286},6,[211,288,250],{"emptyLinePlaceholder":81},[211,290,292,295,298],{"class":213,"line":291},7,[211,293,294],{"class":262},"brew",[211,296,297],{"class":266}," install",[211,299,300],{"class":266}," scorecard\n",[211,302,304],{"class":213,"line":303},8,[211,305,250],{"emptyLinePlaceholder":81},[211,307,309,312,315,317,319,322,325,328,331,334,337],{"class":213,"line":308},9,[211,310,311],{"class":262},"scorecard",[211,313,314],{"class":266}," --repo=",[211,316,270],{"class":224},[211,318,235],{"class":266},[211,320,321],{"class":266}," choice",[211,323,324],{"class":266}," of",[211,326,327],{"class":266}," repo",[211,329,330],{"class":266}," e.g.",[211,332,333],{"class":266}," github.com\u002Fossf-tests\u002Fscorecard-check-branch-protection-e2",[211,335,336],{"class":280},"e",[211,338,244],{"class":224},[197,340,342,12],{"title":341},"Docker",[202,343,345],{"className":204,"code":344,"language":206,"meta":200,"style":200},"docker run -e GITHUB_AUTH_TOKEN=\u003Cyour access token> gcr.io\u002Fopenssf\u002Fscorecard:stable --repo=\u003Cyour choice of repo e.g. github.com\u002Fossf-tests\u002Fscorecard-check-branch-protection-e2e>\n",[208,346,347],{"__ignoreMap":200},[211,348,349,352,355,358,360,362,364,366,368,370,373,376,378,380,382,384,386,388,390,392,394],{"class":213,"line":214},[211,350,351],{"class":262},"docker",[211,353,354],{"class":266}," run",[211,356,357],{"class":266}," -e",[211,359,267],{"class":266},[211,361,270],{"class":224},[211,363,235],{"class":266},[211,365,238],{"class":266},[211,367,277],{"class":266},[211,369,281],{"class":280},[211,371,372],{"class":224},">",[211,374,375],{"class":266}," gcr.io\u002Fopenssf\u002Fscorecard:stable",[211,377,314],{"class":266},[211,379,270],{"class":224},[211,381,235],{"class":266},[211,383,321],{"class":266},[211,385,324],{"class":266},[211,387,327],{"class":266},[211,389,330],{"class":266},[211,391,333],{"class":266},[211,393,336],{"class":280},[211,395,244],{"class":224},[197,397,399,12],{"title":398},"Nix",[202,400,402],{"className":204,"code":401,"language":206,"meta":200,"style":200},"export GITHUB_AUTH_TOKEN=\u003Cyour access token>\n\nnix-shell -p nixpkgs.scorecard\n\nscorecard --repo=\u003Cyour choice of repo e.g. github.com\u002Fossf-tests\u002Fscorecard-check-branch-protection-e2e>\n",[208,403,404,420,424,435,439],{"__ignoreMap":200},[211,405,406,408,410,412,414,416,418],{"class":213,"line":214},[211,407,225],{"class":224},[211,409,229],{"class":228},[211,411,232],{"class":224},[211,413,235],{"class":228},[211,415,238],{"class":228},[211,417,241],{"class":228},[211,419,244],{"class":224},[211,421,422],{"class":213,"line":221},[211,423,250],{"emptyLinePlaceholder":81},[211,425,426,429,432],{"class":213,"line":247},[211,427,428],{"class":262},"nix-shell",[211,430,431],{"class":266}," -p",[211,433,434],{"class":266}," nixpkgs.scorecard\n",[211,436,437],{"class":213,"line":253},[211,438,250],{"emptyLinePlaceholder":81},[211,440,441,443,445,447,449,451,453,455,457,459,461],{"class":213,"line":259},[211,442,311],{"class":262},[211,444,314],{"class":266},[211,446,270],{"class":224},[211,448,235],{"class":266},[211,450,321],{"class":266},[211,452,324],{"class":266},[211,454,327],{"class":266},[211,456,330],{"class":266},[211,458,333],{"class":266},[211,460,336],{"class":280},[211,462,244],{"class":224},[42,464,465],{},"Scorecard also has standalone binaries and other platforms troubleshooting and custom configuration available. Learn more here:",[124,467],{},[42,469,470],{},[107,471,473],{"href":190,"className":472},[132,133],"Detailed installation instructions",[35,475,478],{"className":476,"id":477},[38],"learn-more","Learn more",[480,481,482],"blockquote",{},[42,483,484,485,491],{},"We rely on Security Scorecards ",[486,487,488],"em",{},[211,489,490],{},"i.e., OpenSSF Scorecard"," to ensure we follow secure development best practices.",[10,493,496],{"className":494},[495],"text-right",[497,498,499,500],"cite",{},"Appu Goundan, ",[107,501,503],{"href":502},"https:\u002F\u002Fgithub.com\u002FGoogleContainerTools\u002Fdistroless","Distroless",[63,505,507],{"id":506},"the-problem","The problem",[42,509,510],{},"By some estimates* 84% of all codebases have at least one vulnerability, with an average of 158 per codebase. The majority have been in the code for more than 2 years and have documented solutions available.",[42,512,513],{},"Even in large tech companies, the tedious process of reviewing code for vulnerabilities falls down the priority list, and there is little insight into known vulnerabilities and solutions that companies can draw on.",[42,515,516,517,521],{},"That’s where Security Scorecards ",[486,518,519],{},[211,520,490],{}," is helping. Its focus is to understand the security posture of a project and assess the risks that dependencies introduce.",[42,523,524,525,530],{},"*",[107,526,529],{"href":527,"rel":528},"https:\u002F\u002Fwww.synopsys.com\u002Fsoftware-integrity\u002Fresources\u002Fanalyst-reports\u002Fopen-source-security-risk-analysis.html?intcmp=sig-blog-ossra1",[111],"Open Source Security and Risk Analysis Report"," (Synopsys, 2021)",[124,532],{},[63,534,536],{"id":535},"what-is-openssf-scorecard","What is OpenSSF Scorecard?",[538,539,541],"h5",{"id":540},"scorecard-assesses-open-source-projects-for-security-risks-through-a-series-of-automated-checks","Scorecard assesses open source projects for security risks through a series of automated checks.",[42,543,544],{},"It was created by OSS developers to help improve the health of critical projects that the community depends on.",[42,546,547],{},"You can use it to proactively assess and make informed decisions about accepting security risks within your codebase. You can also use the tool to evaluate other projects and dependencies, and work with maintainers to improve codebases you might want to integrate.",[42,549,550],{},"Scorecard helps you enforce best practices that can guard against:",[27,552,558,572,584,596],{"className":553},[554,555,556,557,557],"grid","grid-cols-1","grid-rows-1","md:grid-cols-2",[10,559,560,567],{},[42,561,562],{},[563,564],"img",{"alt":565,"src":566},"malicious maintainers","assets\u002Fmalicious-maintainer.svg",[568,569,571],"h4",{"id":570},"malicious-maintainers","Malicious maintainers",[10,573,574,580],{},[42,575,576],{},[563,577],{"alt":578,"src":579},"build system compromises","assets\u002Fcompromised-build.svg",[568,581,583],{"id":582},"build-system-compromises","Build system compromises",[10,585,586,592],{},[42,587,588],{},[563,589],{"alt":590,"src":591},"source code compromises","assets\u002Fcompromised-source.svg",[568,593,595],{"id":594},"source-code-compromises","Source code compromises",[10,597,598,604],{},[42,599,600],{},[563,601],{"alt":602,"src":603},"malicious packages","assets\u002Fmalicious-package.svg",[568,605,607],{"id":606},"malicious-packages","Malicious packages",[124,609],{},[124,611],{},[480,613,614],{},[42,615,616],{},"It took less than 5 minutes to install. It quickly analysed the repo and identified easy ways to make the project more secure.",[10,618,620],{"className":619},[495],[497,621,622,623],{},"Priya Wadhwa, ",[107,624,626],{"href":625},"https:\u002F\u002Fgithub.com\u002FGoogleContainerTools\u002Fkaniko","Kaniko",[124,628],{},[63,630,632],{"id":631},"how-it-works","How it works",[42,634,635,636,639,640,639,643,639,646,649,650,653],{},"Scorecard checks for vulnerabilities affecting different parts of the software supply chain including ",[53,637,638],{},"source code",", ",[53,641,642],{},"build",[53,644,645],{},"dependencies",[53,647,648],{},"testing",", and project ",[53,651,652],{},"maintenance",".",[42,655,656,657,660,661,664,665,668,669,672],{},"Each automated check returns a ",[53,658,659],{},"score out of 10"," and a ",[53,662,663],{},"risk level",". The risk level ",[53,666,667],{},"adds a weighting"," to the score, and this weighting is compiled into a single, ",[53,670,671],{},"aggregate score",". This score helps give a sense of the overall security posture of a project.",[42,674,675,676,679],{},"Alongside the scores, the tool provides remediation prompts to help you ",[53,677,678],{},"fix problems"," and strengthen your development practices.",[42,681,682],{},[563,683],{"alt":684,"src":685},"scale of risk","assets\u002Fdiagram-risks.svg",[124,687],{},[63,689,691],{"id":690},"the-checks","The checks",[538,693,695],{"id":694},"the-checks-collect-together-security-best-practises-and-industry-standards","The checks collect together security best practises and industry standards",[42,697,698],{},"The riskiness of each vulnerability is based on how easy it is to exploit. For example if something can be exploited via a pull request, we consider that a high risk. There are currently 18 checks made across 3 themes: holistic security practises, source code risk assessment and build process risk assessment.",[42,700,701,702,653],{},"You can learn more about the scoring criteria, risks, and remediation suggestions for each check in the ",[107,703,706],{"href":704,"rel":705},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md",[111],"detailed documentation",[10,708,712],{"className":709},[33,710,711],"items-center","justify-center",[42,713,714],{},[563,715],{"alt":716,"src":717},"What Scorecard assesses","assets\u002Fdiagram-flower.svg",[568,719,721],{"id":720},"holistic-security-practises","Holistic security practises",[723,724,725,741],"table",{"className":723},[726,727,728],"thead",{},[729,730,731,735,738],"tr",{},[732,733,734],"th",{},"Code vulnerabilities",[732,736,737],{},"Description",[732,739,740],{},"Risk",[742,743,744],"tbody",{},[729,745,746,754,762],{},[747,748,749],"td",{},[107,750,753],{"href":751,"rel":752},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md#vulnerabilities",[111],"Vulnerabilities",[747,755,756,757,653],{},"Does the project have unfixed vulnerabilities? Uses the ",[107,758,761],{"href":759,"rel":760},"https:\u002F\u002Fosv.dev\u002F",[111],"OSV service",[747,763,764],{},"High",[723,766,767,778],{"className":723},[726,768,769],{},[729,770,771,774,776],{},[732,772,773],{},"Maintenance",[732,775,737],{},[732,777,740],{},[742,779,780,805,819,839,854],{},[729,781,782,789,803],{},[747,783,784],{},[107,785,788],{"href":786,"rel":787},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md#dependency-update-tool",[111],"Dependency Update Tool",[747,790,791,792,639,797,802],{},"Does the project use tools to help update its dependencies e.g. ",[107,793,796],{"href":794,"rel":795},"https:\u002F\u002Fdocs.github.com\u002Fen\u002Fcode-security\u002Fsupply-chain-security\u002Fmanaging-vulnerabilities-in-your-projects-dependencies\u002Fconfiguring-dependabot-security-updates",[111],"Dependabot",[107,798,801],{"href":799,"rel":800},"https:\u002F\u002Fgithub.com\u002Frenovatebot\u002Frenovate",[111],"RenovateBot","?",[747,804,764],{},[729,806,807,814,817],{},[747,808,809],{},[107,810,813],{"href":811,"rel":812},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md#maintained",[111],"Maintained",[747,815,816],{},"Is the project maintained?",[747,818,764],{},[729,820,821,828,836],{},[747,822,823],{},[107,824,827],{"href":825,"rel":826},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md#security-policy",[111],"Security Policy",[747,829,830,831,802],{},"Does the project contain a ",[107,832,835],{"href":833,"rel":834},"https:\u002F\u002Fdocs.github.com\u002Fen\u002Ffree-pro-team@latest\u002Fgithub\u002Fmanaging-security-vulnerabilities\u002Fadding-a-security-policy-to-your-repository",[111],"security policy",[747,837,838],{},"Medium",[729,840,841,848,851],{},[747,842,843],{},[107,844,847],{"href":845,"rel":846},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md#license",[111],"Licence",[747,849,850],{},"Does the project declare a licence?",[747,852,853],{},"Low",[729,855,856,863,871],{},[747,857,858],{},[107,859,862],{"href":860,"rel":861},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md#cii-best-practices",[111],"CII Best Practices",[747,864,865,866,802],{},"Does the project have a ",[107,867,870],{"href":868,"rel":869},"https:\u002F\u002Fbestpractices.coreinfrastructure.org\u002Fen",[111],"CII Best Practices Badge",[747,872,853],{},[723,874,875,886],{"className":723},[726,876,877],{},[729,878,879,882,884],{},[732,880,881],{},"Continuous testing",[732,883,737],{},[732,885,740],{},[742,887,888,912,931],{},[729,889,890,897,910],{},[747,891,892],{},[107,893,896],{"href":894,"rel":895},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md#ci-tests",[111],"CI Tests",[747,898,899,900,639,905,802],{},"Does the project run tests in CI, e.g. ",[107,901,904],{"href":902,"rel":903},"https:\u002F\u002Fdocs.github.com\u002Fen\u002Ffree-pro-team@latest\u002Factions",[111],"GitHub Actions",[107,906,909],{"href":907,"rel":908},"https:\u002F\u002Fgithub.com\u002Fkubernetes\u002Ftest-infra\u002Ftree\u002Fmaster\u002Fprow",[111],"Prow",[747,911,853],{},[729,913,914,921,929],{},[747,915,916],{},[107,917,920],{"href":918,"rel":919},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md#fuzzing",[111],"Fuzzing",[747,922,923,924,802],{},"Does the project use fuzzing tools, e.g. ",[107,925,928],{"href":926,"rel":927},"https:\u002F\u002Fgithub.com\u002Fgoogle\u002Foss-fuzz",[111],"OSS-Fuzz",[747,930,838],{},[729,932,933,940,958],{},[747,934,935],{},[107,936,939],{"href":937,"rel":938},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md#sast",[111],"SAST",[747,941,942,943,639,948,639,953,802],{},"Does the project use static code analysis tools, e.g. ",[107,944,947],{"href":945,"rel":946},"https:\u002F\u002Fdocs.github.com\u002Fen\u002Ffree-pro-team@latest\u002Fgithub\u002Ffinding-security-vulnerabilities-and-errors-in-your-code\u002Fenabling-code-scanning-for-a-repository#enabling-code-scanning-using-actions",[111],"CodeQL",[107,949,952],{"href":950,"rel":951},"https:\u002F\u002Flgtm.com\u002F",[111],"LGTM",[107,954,957],{"href":955,"rel":956},"https:\u002F\u002Fsonarcloud.io\u002F",[111],"SonarCloud",[747,959,838],{},[568,961,963],{"id":962},"source-risk-assessment","Source risk assessment",[723,965,966,977],{"className":723},[726,967,968],{},[729,969,970,973,975],{},[732,971,972],{},"Name",[732,974,737],{},[732,976,740],{},[742,978,979,993,1011,1026,1040],{},[729,980,981,988,991],{},[747,982,983],{},[107,984,987],{"href":985,"rel":986},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md#binary-artifacts",[111],"Binary Artifacts",[747,989,990],{},"Is the project free of checked-in binaries?",[747,992,764],{},[729,994,995,1002,1009],{},[747,996,997],{},[107,998,1001],{"href":999,"rel":1000},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md#branch-protection",[111],"Branch Protection",[747,1003,1004,1005,802],{},"Does the project use ",[107,1006,1001],{"href":1007,"rel":1008},"https:\u002F\u002Fdocs.github.com\u002Fen\u002Ffree-pro-team@latest\u002Fgithub\u002Fadministering-a-repository\u002Fabout-protected-branches",[111],[747,1010,764],{},[729,1012,1013,1020,1023],{},[747,1014,1015],{},[107,1016,1019],{"href":1017,"rel":1018},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md#dangerous-workflow",[111],"Dangerous Workflow",[747,1021,1022],{},"Does the project avoid dangerous coding patterns in GitHub Actions?",[747,1024,1025],{},"Critical",[729,1027,1028,1035,1038],{},[747,1029,1030],{},[107,1031,1034],{"href":1032,"rel":1033},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md#code-review",[111],"Code Review",[747,1036,1037],{},"Does the project require code review before code is merged?",[747,1039,764],{},[729,1041,1042,1049,1052],{},[747,1043,1044],{},[107,1045,1048],{"href":1046,"rel":1047},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md#contributors",[111],"Contributors",[747,1050,1051],{},"Does the project have contributors from multiple organizations?",[747,1053,853],{},[568,1055,1057],{"id":1056},"build-risk-assessment","Build risk assessment",[723,1059,1060,1070],{"className":723},[726,1061,1062],{},[729,1063,1064,1066,1068],{},[732,1065,972],{},[732,1067,737],{},[732,1069,740],{},[742,1071,1072,1090,1109,1128],{},[729,1073,1074,1081,1088],{},[747,1075,1076],{},[107,1077,1080],{"href":1078,"rel":1079},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md#pinned-dependencies",[111],"Pinned Dependencies",[747,1082,1083,1084,802],{},"Does the project declare and pin ",[107,1085,645],{"href":1086,"rel":1087},"https:\u002F\u002Fdocs.github.com\u002Fen\u002Ffree-pro-team@latest\u002Fgithub\u002Fvisualizing-repository-data-with-graphs\u002Fabout-the-dependency-graph#supported-package-ecosystems",[111],[747,1089,838],{},[729,1091,1092,1099,1107],{},[747,1093,1094],{},[107,1095,1098],{"href":1096,"rel":1097},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md#token-permissions",[111],"Token Permissions",[747,1100,1101,1102,802],{},"Does the project declare GitHub workflow tokens as ",[107,1103,1106],{"href":1104,"rel":1105},"https:\u002F\u002Fdocs.github.com\u002Fen\u002Factions\u002Freference\u002Fauthentication-in-a-workflow",[111],"read only",[747,1108,764],{},[729,1110,1111,1118,1126],{},[747,1112,1113],{},[107,1114,1117],{"href":1115,"rel":1116},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md#packaging",[111],"Packaging",[747,1119,1120,1121,802],{},"Does the project build and publish official packages from CI\u002FCD, e.g. ",[107,1122,1125],{"href":1123,"rel":1124},"https:\u002F\u002Fdocs.github.com\u002Fen\u002Ffree-pro-team@latest\u002Factions\u002Fguides\u002Fabout-packaging-with-github-actions#workflows-for-publishing-packages",[111],"GitHub Publishing",[747,1127,838],{},[729,1129,1130,1137,1145],{},[747,1131,1132],{},[107,1133,1136],{"href":1134,"rel":1135},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fblob\u002Fmain\u002Fdocs\u002Fchecks.md#signed-releases",[111],"Signed Releases",[747,1138,1139,1140,802],{},"Does the project ",[107,1141,1144],{"href":1142,"rel":1143},"https:\u002F\u002Fwiki.debian.org\u002FCreating%20signed%20GitHub%20releases",[111],"cryptographically sign releases",[747,1146,764],{},[124,1148],{},[480,1150,1151],{},[42,1152,1153,1154,1158],{},"Machine checkable properties are an essential part of a sound security process. That’s why we have incorporated Security Scorecards ",[486,1155,1156],{},[211,1157,490],{}," into our dependency acceptance criteria.",[10,1160,1163],{"className":1161},[495,1162],"mb-60",[497,1164,1165,1166],{},"Harvey Tuch, ",[107,1167,1169],{"href":1168},"https:\u002F\u002Fwww.envoyproxy.io\u002F","Envoy",[63,1171,1173],{"id":1172},"use-cases","Use cases",[538,1175,1177],{"id":1176},"openssf-scorecard-reduces-the-effort-required-to-continually-evaluate-changing-packages-when-maintaining-a-projects-supply-chain","OpenSSF Scorecard reduces the effort required to continually evaluate changing packages when maintaining a project’s supply chain",[568,1179,1181],{"id":1180},"for-individual-maintainers","For individual maintainers",[42,1183,1184],{},"Scorecard is helpful as a pre-launch security checker for a new OSS project or to help to plan improvements to an existing one. If a project is well maintained, it’s more likely to be used by others instead of an alternative. It can also be used to check a new dependency being added to a project, so a maintainer can make an informed decision about the risk of doing so.",[568,1186,1188],{"id":1187},"for-an-organisation","For an organisation",[42,1190,1191],{},"Scorecard can be included in the continuous integration\u002Fcontinuous deployment processes using the GitHub action and run by default on pull requests.",[568,1193,1195],{"id":1194},"for-consumers","For consumers",[42,1197,1198],{},"Scorecard helps to make informed decisions about security risks and vulnerabilities. Using the public data, it is also possible to evaluate the security posture of over 1 million of the most used OSS projects.",[124,1200],{},[63,1202,1204],{"id":1203},"about-the-project-name","About the project name",[42,1206,1207],{},"This project was initially called \"Security Scorecards\" but that form wasn't used consistently. In particular, the repo was named \"scorecard\" and so was the program. Over time people started referring to either form (singular and plural), with or without \"Security\", and the inconsitency became prevalent. To end this situation the decision was made to consolidate over the use of the singular form in keeping with the repo and program name, drop the \"Security\" part and use \"OpenSSF\" instead to ensure uniqueness. One should therefore refer to this project as \"OpenSSF Scorecard\" or \"Scorecard\" for short.",[63,1209,1211],{"id":1210},"part-of-the-oss-community","Part of the OSS community",[10,1213,1218,1226,1234,1242,1250],{"className":1214},[33,1215,1216,710,1217],"md:w-3\u002F4","inline-flex","gap-x-40",[10,1219,1220],{},[42,1221,1222],{},[563,1223],{"alt":1224,"src":1225},"cisco","assets\u002Flogos\u002Fcisco.svg",[10,1227,1228],{},[42,1229,1230],{},[563,1231],{"alt":1232,"src":1233},"datto","assets\u002Flogos\u002Fdatto.svg",[10,1235,1236],{},[42,1237,1238],{},[563,1239],{"alt":1240,"src":1241},"endor","assets\u002Flogos\u002Fendor.svg",[10,1243,1244],{},[42,1245,1246],{},[563,1247],{"alt":1248,"src":1249},"google","assets\u002Flogos\u002Fgoogle.svg",[10,1251,1252],{},[42,1253,1254],{},"& many others",[42,1256,1257,1258,1263],{},"OpenSSF Scorecard is being ",[107,1259,1262],{"href":1260,"rel":1261},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard\u002Fgraphs\u002Fcontributors",[111],"developed and facilitated by contributors"," from across the OSS ecosystem.",[42,1265,1266,1267,1272],{},"We're part of the ",[107,1268,1271],{"href":1269,"rel":1270},"https:\u002F\u002Fopenssf.org",[111],"Open Source Security Foundation (OpenSSF)",", a cross-industry collaboration that brings together OSS security initiatives under one foundation and seeks to improve the security of OSS by building a broader community, targeted initiatives, and best practises.",[42,1274,1275],{},"OpenSSF launched Scorecard in November 2020 with the intention of auto-generating a “security score” for open source projects to help users as they decide the trust, risk, and security posture for their use case.",[124,1277],{},[63,1279,1281],{"id":1280},"get-involved","Get involved",[42,1283,1284],{},[563,1285],{"alt":1286,"src":1287},"Open Source Security Foundation","assets\u002Flogos\u002Fopenssf.svg",[42,1289,1290,1291,653],{},"Scorecard is part of the ",[107,1292,1295],{"href":1293,"rel":1294},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fwg-best-practices-os-developers",[111],"OpenSSF Best Practices Working Group",[42,1297,1298,1299,653],{},"If you want to get involved in the OpenSSF Scorecard community or have ideas you'd like to chat about, ",[107,1300,1303],{"href":1301,"rel":1302},"https:\u002F\u002Fgithub.com\u002Fossf\u002Fscorecard#connect-with-the-scorecard-community",[111],"we'd love to connect",[1305,1306,1307],"style",{},"html pre.shiki code .s8hdm, html code.shiki .s8hdm{--shiki-default:#616E88}html pre.shiki code .sGPm4, html code.shiki .sGPm4{--shiki-default:#81A1C1}html pre.shiki code .sIPZU, html code.shiki .sIPZU{--shiki-default:#D8DEE9}html pre.shiki code .st_Lx, html code.shiki .st_Lx{--shiki-default:#88C0D0}html pre.shiki code .sUFv7, html code.shiki .sUFv7{--shiki-default:#A3BE8C}html pre.shiki code .s0_w5, html code.shiki .s0_w5{--shiki-default:#D8DEE9FF}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}",{"title":200,"searchDepth":247,"depth":247,"links":1309},[1310,1318],{"id":39,"depth":221,"text":40,"children":1311},[1312,1313,1314,1315,1316,1317],{"id":65,"depth":247,"text":66},{"id":73,"depth":247,"text":74},{"id":97,"depth":247,"text":98},{"id":137,"depth":247,"text":138},{"id":144,"depth":247,"text":145},{"id":172,"depth":247,"text":173},{"id":477,"depth":221,"text":478,"children":1319},[1320,1321,1322,1323,1328,1333,1334,1335],{"id":506,"depth":247,"text":507},{"id":535,"depth":247,"text":536},{"id":631,"depth":247,"text":632},{"id":690,"depth":247,"text":691,"children":1324},[1325,1326,1327],{"id":720,"depth":253,"text":721},{"id":962,"depth":253,"text":963},{"id":1056,"depth":253,"text":1057},{"id":1172,"depth":247,"text":1173,"children":1329},[1330,1331,1332],{"id":1180,"depth":253,"text":1181},{"id":1187,"depth":253,"text":1188},{"id":1194,"depth":253,"text":1195},{"id":1203,"depth":247,"text":1204},{"id":1210,"depth":247,"text":1211},{"id":1280,"depth":247,"text":1281},"Quickly assess open source projects for risky practices","md",{"date":1339,"slug":1340,"thumbnail":1341},"2021-07-12T15:33:03.264Z","home","\u002Fassets\u002Fchecks.png","\u002Fhome",{"title":5,"description":1336},"kczFZ95FYzSgQN_P56t-_YgfDkSc304S_By3lnsrtME",1786274124659]